Last updated: 23 July 2026
Privacy Policy
Overview
Sectionheroes Martins Alves, Julian & Lücking, Joel GbR (“Sectionheroes”, “we”, “us”) takes the protection of your personal data seriously. This Privacy Policy explains what personal data we process, for what purposes, on what legal basis, and what rights you have. It applies to:
- our website sectionheroes.com (the “Website”),
- the Sectionheroes app distributed through the Shopify App Store and embedded in the Shopify admin (the “App”), and
- the storefront elements the App renders in the online stores of merchants who install the App (custom sections and blocks, bundles, upsells, quantity upsells, price blocks/badges, and related features).
1. Controller
Sectionheroes Martins Alves, Julian & Lücking, Joel GbR
Höltkebruchstr. 81
32602 Vlotho, Germany
Represented by: Joel Lücking and Julian Martins-Alves
Email: support@sectionheroes.com
We have not appointed a data protection officer, as we are not legally required to do so. For all data protection matters, please contact us at support@sectionheroes.com.
2. Our two roles: controller and processor
Depending on whose data is involved, we act in different roles under the GDPR:
- For merchants (Shopify store owners and their staff who install and use the App) and for Website visitors, we are the controller.
- For end customers (visitors and buyers of a merchant’s online store), we are a processor acting on behalf of the merchant, who is the controller. Our processing of end-customer data is governed by the Data Processing Annex in our Terms of Service. End customers who have questions about how their data is handled should contact the store they purchased from; we support merchants in fulfilling such requests.
3. Data we process as controller
3.1 Website visitors
When you visit sectionheroes.com, our hosting provider (Render Services, Inc., data hosted in the EU) processes technical connection data (IP address, browser type, requested pages, timestamps) in server logs to deliver the site and ensure its security. We do not use any web analytics, advertising, or tracking tools on the Website (no Google Analytics, no Meta Pixel, no cookies for tracking). Legal basis: Art. 6(1)(f) GDPR (legitimate interest in operating a secure website).
3.2 Merchant account data
When you install the App, we receive and store via the Shopify API:
- your store’s
.myshopify.comdomain and store name, - the store owner’s email address,
- the name and email address of the staff member using the App,
- API access tokens and granted permission scopes,
- installation date, trial status, and subscription plan.
We use this data to provide the App, manage your subscription and trial, authenticate API requests, and contact you about your account. Legal basis: Art. 6(1)(b) GDPR (performance of contract).
3.3 App usage, subscription and billing insights
Billing for the App is handled through Shopify’s billing system. We use Mantle (Heymantle Inc., USA) to manage subscriptions and to obtain usage and billing insights (e.g. plan, subscription status, trial state) that help us operate the App and improve the product. We also process your store’s subscription and revenue data through the Shopify Partner API for our own accounting and product analytics. Legal basis: Art. 6(1)(b) GDPR (billing) and Art. 6(1)(f) GDPR (legitimate interest in operating and improving our product).
3.4 Support and communication
- In-app and help-center support chat is provided by us directly (self-hosted). When you contact support, your name, email address, store domain, and message content are processed so we can help you. Support requests may be forwarded to internal tools for handling: Slack (Salesforce, USA) for team notifications and ClickUp (Mango Technologies, Inc., USA) where a request is turned into a bug report.
- Support email is sent and received via Postmark (ActiveCampaign, LLC, USA).
- To help us triage support requests faster, incoming messages may be processed by Anthropic PBC (USA) for automated spam classification and to draft or summarize replies. The message content and contact details are transmitted for this purpose only and are not used to train Anthropic’s models.
- Product and lifecycle emails (onboarding tips, feature announcements, trial reminders) are sent via Klaviyo, Inc. (USA). You can unsubscribe from marketing emails at any time via the link in each email.
Legal basis: Art. 6(1)(b) GDPR for support and service messages; Art. 6(1)(f) GDPR for product communication to existing customers.
3.5 AI-assisted features (“AI Hub”)
When you use AI-assisted analysis or content suggestions in the App, we transmit the relevant product and store configuration data you submit to Anthropic PBC (USA) solely to generate the requested analysis or suggestion. This feature runs only upon your request. No end-customer data is transmitted as part of this feature. Data submitted through this feature is not used by Anthropic to train its models. Legal basis: Art. 6(1)(b) GDPR (you request the analysis). AI output is generated automatically and may be incomplete or incorrect; you are responsible for reviewing it before use (see our Terms of Service).
3.6 Affiliate / referral program
If you participate in our affiliate or referral program, we process your name, email address, and the payout details you provide (e.g. PayPal address or IBAN) in order to administer the program and pay commissions. Legal basis: Art. 6(1)(b) GDPR (performance of the affiliate arrangement) and Art. 6(1)(c) GDPR (statutory bookkeeping duties for payouts).
4. Data we process on behalf of merchants (end customers)
When a merchant uses the App, we process limited data about that store’s visitors and customers as processor, strictly to provide the App’s features. The merchant remains the controller for this data.
- Bundle, upsell and quantity-upsell analytics: after an order is placed, we receive from Shopify (via the
orders/createwebhook) pseudonymous order data — order number, currency, order and discount totals, item count, and the product variant IDs involved in a bundle or upsell. We do not receive or store customer names, email addresses, IP addresses, or shipping/billing addresses through this feature. This data cannot be linked to an individual customer and is used to produce aggregated performance reporting for the merchant. - Customer email timeline (only if the merchant connects Klaviyo): for merchants who connect their Klaviyo account, we retrieve “received email” events (the customer’s email address and the subject/name of the campaign or flow they received) from the merchant’s own Klaviyo account, to display a customer timeline in the App. This is the only feature through which we store an end customer’s email address.
- Personalized storefront rendering: our storefront widgets (bundles, upsells, price blocks/badges, sections) render personalized elements in the visitor’s browser. These widgets do not set cookies or local storage, and do not run a visitor-tracking pixel.
Deletion and access requests by end customers are fulfilled through the merchant, including via Shopify’s GDPR webhooks (customers/data_request, customers/redact, shop/redact), which we implement:
- On
customers/redact, we delete the end customer’s email-timeline data for that store. - On
shop/redactand on uninstallation, we delete the store’s end-customer data (order analytics and email-timeline data). - On
customers/data_request, we compile the data we hold about the requesting customer and provide it to the merchant so the merchant can respond.
5. Cookies and local storage in merchant storefronts
Our storefront widgets do not set any cookies or local storage in the visitor’s browser and do not include a tracking pixel. Any cookies present in a merchant’s storefront (including Shopify’s own cart cookies) are set by Shopify or by the merchant’s theme and other apps; the merchant’s own cookie/consent solution governs their storefront.
6. Recipients and sub-processors
We share personal data only with the service providers listed below, under data processing agreements, and never sell it. Current sub-processors:
| Provider | Purpose | Location / Region |
|---|---|---|
| Render Services, Inc. | Application & website hosting, PostgreSQL database | Database hosted in Frankfurt (EU); provider USA |
| Anthropic PBC | AI-assisted features and support automation | USA |
| Mantle (Heymantle Inc.) | Subscription management, billing and app usage insights | USA |
| Klaviyo, Inc. | Merchant lifecycle & marketing emails; customer email-timeline sync | USA |
| Postmark (ActiveCampaign, LLC) | Transactional and support email | USA |
| Slack (Salesforce, Inc.) | Internal support notifications | USA |
| ClickUp (Mango Technologies, Inc.) | Bug tracking from support requests | USA |
| Shopify International Ltd. | Platform, billing, APIs | Ireland / Canada |
Where providers are located outside the EU/EEA, transfers are safeguarded by adequacy decisions (including the EU–US Data Privacy Framework where the provider is certified) or by the EU Standard Contractual Clauses (Art. 46(2)(c) GDPR).
7. Retention
- Merchant account data is stored for the duration of the contract. After uninstallation we retain limited records (store domain, trial history, subscription and revenue records) as needed for fraud and trial-abuse prevention and to meet statutory retention duties (§ 147 AO, § 257 HGB — up to 10 years for billing records).
- End-customer order analytics is deleted upon uninstallation of the App or upon a
shop/redactrequest. - End-customer email-timeline data is deleted upon a
customers/redactrequest (for the individual customer) and upon uninstallation orshop/redact(for the whole store). - Support data is retained for as long as necessary to handle and document the support relationship.
- Server log data (including IP addresses) is retained for up to 30 days and then deleted.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21 GDPR). Where processing is based on consent, you may withdraw it at any time with future effect. To exercise your rights, contact us at support@sectionheroes.com.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia (Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, LDI NRW), Düsseldorf, Germany.
9. Changes to this policy
We may update this Privacy Policy to reflect changes in our services or legal requirements. The current version is always available on this page. Material changes affecting merchants will be announced in the App or by email.

