Privacy

Privacy, simply

Last updated · July 2026

Canonical version · English

COOUP connects creators with merchants to promote products and earn commission. This page explains what we collect, what we don't, how attribution works, and the rights you have over your information.

What we collect

Account and role details; creator-link, click, and conversion records; payout and settlement amounts and status; and connected Shopify store, product, market, and subscription information. For attributed orders, COOUP keeps only the identifiers and commercial values needed to operate the service and does not store buyer personal data.

Shopify provides app-plan and subscription status. Stripe provides merchant settlement and creator payout status. Shopify and Stripe collect payment details on their own surfaces; COOUP does not store full card numbers or bank credentials.

What we don't collect

We do not read merchant customer records beyond what's required to confirm an order is real and attributable. We don't sell personal data, we don't use it for third-party advertising, and we don't track you across the open web with advertising cookies or cross-site pixels.

How we use data

To attribute sales to creators, calculate commission, manage merchant subscription lifecycles, surface analytics to merchants, process payouts, send transactional emails, and operate the service. Nothing more.

Lawful basis

We process personal data where necessary to provide the service, comply with legal obligations, protect against fraud, and pursue legitimate business interests related to operating the platform.

Attribution, transparently

When a creator shares a product, we attach a lightweight reference so we can credit them when a sale happens. No third-party cookies, no surveillance pixels — just the minimum needed to pay the right person. Analytics are first-party, scoped to the COOUP ecosystem, and used to operate attribution rather than profile users.

Cookies & sessions

We use a small number of first-party cookies and secure session technologies for authentication, fraud prevention, analytics, and maintaining account sessions. No advertising cookies, no third-party trackers, no cross-site profiling.

Sharing

Data is processed by our infrastructure providers (hosting, database, email delivery) under data-processing agreements. We share aggregate, non-identifying analytics with merchants about their own attributed activity. We disclose data only when legally required.

Shopify integration

When a merchant installs the COOUP Shopify app, we receive the store, product, market, installation, subscription, and order information needed to connect the shop and attribute eligible creator-driven sales. We limit access to what the service needs and honour Shopify-required privacy requests.

Security

Data is encrypted in transit. Access to account, provider-connection, and production information is limited by role and operational need, and sensitive access is reviewed.

Your rights

Depending on your jurisdiction you may have rights to access, correct, port, or delete your personal data, and to object to or restrict processing. EU/UK users have the rights described under the GDPR; California users have the rights described under the CCPA. Email privacy@cooup.co and we'll respond within a week.

Regional privacy notes

Global

One core standard

COOUP keeps one privacy core worldwide: collect only what the service needs, keep attribution first-party, avoid advertising trackers, protect sensitive access, and respond to privacy requests through privacy@cooup.co.

UK

UK data rights

Depending on the context, UK users may ask for access, correction, deletion, portability, objection, restriction, and safeguards around automated decisions. COOUP handles requests through the same privacy mailbox and keeps its notices clear, specific, and accurate while current ICO guidance is updated for the Data (Use and Access) Act 2026.

EU

EU data rights

EU users receive the same core GDPR transparency: purpose, lawful basis, retention, safeguards for transfers, and practical access to applicable privacy rights. COOUP does not claim certification or a special regulatory status.

US

US privacy and marketing

US users can contact COOUP about access, deletion, correction, and opt-out questions where applicable. COOUP does not sell personal data and does not use third-party advertising cookies for attribution.

Canada

Canadian privacy

Canadian users can ask how personal information is collected, used, disclosed, accessed, corrected, retained, and safeguarded. COOUP keeps consent and purpose tied to operating the creator-commerce service.

Uninstall & data deletion

Brands can disconnect COOUP from Shopify at any time. On uninstall, we revoke Shopify access promptly and delete associated credentials within 30 days. Shopify-required data-deletion requests are handled in accordance with Shopify platform requirements. Historical attribution, earnings, settlement, and audit records may be retained only for the purposes and periods described in this policy. You can request full deletion of your account and personal data via privacy@cooup.co.

Retention

We retain operational and financial records only for as long as necessary to operate the service, settle earnings correctly, comply with legal obligations, resolve disputes, and enforce agreements. Once that purpose ends, data is deleted or anonymized.

International transfers

Data may be processed outside your country of residence. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

Changes

We will update this policy as the platform evolves and notify users of material changes via email or in-app notice.

Contact

Privacy, data, or general questions? Reach us via the Support page.