Privacy Policy & GDPR
Last updated: 20 August 2026
This policy explains how Clepie processes personal data in the AI Shopify theme builder. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR) and the equivalent UK GDPR.
Who is responsible
Christos Demetriou, a sole trader in the Republic of Cyprus trading as "Clepie" ("we", "us"), operates clepie.com and is the data controller for account data, billing data and usage data. You can reach us for any privacy matter through the contact page.
What we collect and why
- Account data — email address and authentication identifiers, so you can sign in and access your projects. Legal basis: performance of a contract.
- Prompts and generated output — the descriptions you submit and the themes created for you. Legal basis: performance of a contract.
- Billing data — handled by Paddle.com, our Merchant of Record; we store only the subscription state, never card numbers. Legal basis: contract and legal obligation.
- Usage data — page views, generation counts, error logs and, for anti-abuse, a short-lived hashed IP. Legal basis: legitimate interest in operating and securing the service.
AI processing
Prompts and any inspiration images you upload are sent to our AI providers solely to generate the requested output. We do not permit those providers to use your content to train their models, and generated results are returned to your account only.
Who we share data with (processors)
- Cloud hosting and database providers, for running the application.
- AI model providers, to generate themes and copy.
- Paddle.com, our Merchant of Record, for the sale of our products, subscription management, payments, tax compliance and invoicing (Paddle is an independent controller for that processing).
- Professional advisers (legal, accounting) and authorities where required by law.
- Privacy-respecting product analytics, to understand aggregate usage.
All processors act under written agreements. We do not sell personal data and we do not share it with advertisers.
International transfers
Some processors are located outside the European Economic Area. Where that is the case, transfers rely on the European Commission's Standard Contractual Clauses or an adequacy decision, together with appropriate technical safeguards such as encryption in transit and at rest.
How long we keep data
- Account and project data: while your account is active, then deleted within 30 days of closure.
- Security and abuse logs: up to 90 days.
- Invoices: retained as required by tax law (typically 6–10 years).
Your rights under the GDPR
You have the right to access, rectify, erase, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time where processing is based on consent. You can delete projects from inside the app at any time; for an account deletion or a full export, contact us and we will respond within 30 days. You also have the right to lodge a complaint with your national data protection authority.
Cookies
We use strictly necessary cookies for authentication and security, and — only with your consent — a minimal set of analytics cookies. Details are on our cookie page.
Security
Data is encrypted in transit (TLS) and at rest. Database access is protected by row-level security so users can only read their own records. In the event of a personal data breach affecting your rights, we will notify the relevant supervisory authority within 72 hours and inform affected users without undue delay.
Children
Clepie is not intended for children under 16.
Changes and contact
We may update this policy; material changes will be announced in the app. Questions, requests or complaints: use the contact page.