Global
One core standard
COOUP keeps one privacy core worldwide: collect only what the service needs, keep attribution first-party, avoid advertising trackers, protect sensitive access, and respond to privacy requests through privacy@cooup.co.
Privacy
Last updated · July 2026
Canonical version · English
COOUP connects creators with merchants to promote products and earn commission. This page explains what we collect, what we don't, how attribution works, and the rights you have over your information.
Account and role details; creator-link, click, and conversion records; payout and settlement amounts and status; and connected Shopify store, product, market, and subscription information. For attributed orders, COOUP keeps only the identifiers and commercial values needed to operate the service and does not store buyer personal data.
Shopify provides app-plan and subscription status. Stripe provides merchant settlement and creator payout status. Shopify and Stripe collect payment details on their own surfaces; COOUP does not store full card numbers or bank credentials.
We do not read merchant customer records beyond what's required to confirm an order is real and attributable. We don't sell personal data, we don't use it for third-party advertising, and we don't track you across the open web with advertising cookies or cross-site pixels.
To attribute sales to creators, calculate commission, manage merchant subscription lifecycles, surface analytics to merchants, process payouts, send transactional emails, and operate the service. Nothing more.
We process personal data where necessary to provide the service, comply with legal obligations, protect against fraud, and pursue legitimate business interests related to operating the platform.
When a creator shares a product, we attach a lightweight reference so we can credit them when a sale happens. No third-party cookies, no surveillance pixels — just the minimum needed to pay the right person. Analytics are first-party, scoped to the COOUP ecosystem, and used to operate attribution rather than profile users.
We use a small number of first-party cookies and secure session technologies for authentication, fraud prevention, analytics, and maintaining account sessions. No advertising cookies, no third-party trackers, no cross-site profiling.
Data is processed by our infrastructure providers (hosting, database, email delivery) under data-processing agreements. We share aggregate, non-identifying analytics with merchants about their own attributed activity. We disclose data only when legally required.
When a merchant installs the COOUP Shopify app, we receive the store, product, market, installation, subscription, and order information needed to connect the shop and attribute eligible creator-driven sales. We limit access to what the service needs and honour Shopify-required privacy requests.
Data is encrypted in transit. Access to account, provider-connection, and production information is limited by role and operational need, and sensitive access is reviewed.
Depending on your jurisdiction you may have rights to access, correct, port, or delete your personal data, and to object to or restrict processing. EU/UK users have the rights described under the GDPR; California users have the rights described under the CCPA. Email privacy@cooup.co and we'll respond within a week.
Global
COOUP keeps one privacy core worldwide: collect only what the service needs, keep attribution first-party, avoid advertising trackers, protect sensitive access, and respond to privacy requests through privacy@cooup.co.
UK
Depending on the context, UK users may ask for access, correction, deletion, portability, objection, restriction, and safeguards around automated decisions. COOUP handles requests through the same privacy mailbox and keeps its notices clear, specific, and accurate while current ICO guidance is updated for the Data (Use and Access) Act 2026.
EU
EU users receive the same core GDPR transparency: purpose, lawful basis, retention, safeguards for transfers, and practical access to applicable privacy rights. COOUP does not claim certification or a special regulatory status.
US
US users can contact COOUP about access, deletion, correction, and opt-out questions where applicable. COOUP does not sell personal data and does not use third-party advertising cookies for attribution.
Canada
Canadian users can ask how personal information is collected, used, disclosed, accessed, corrected, retained, and safeguarded. COOUP keeps consent and purpose tied to operating the creator-commerce service.
Brands can disconnect COOUP from Shopify at any time. On uninstall, we revoke Shopify access promptly and delete associated credentials within 30 days. Shopify-required data-deletion requests are handled in accordance with Shopify platform requirements. Historical attribution, earnings, settlement, and audit records may be retained only for the purposes and periods described in this policy. You can request full deletion of your account and personal data via privacy@cooup.co.
We retain operational and financial records only for as long as necessary to operate the service, settle earnings correctly, comply with legal obligations, resolve disputes, and enforce agreements. Once that purpose ends, data is deleted or anonymized.
Data may be processed outside your country of residence. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.
We will update this policy as the platform evolves and notify users of material changes via email or in-app notice.
Privacy, data, or general questions? Reach us via the Support page.