Schopfer Logo

Schopfer Retail

Privacy Policy

Effective Date: 8 July 2026  |  Version 1.0

This Privacy Policy describes how Schopfer Retail collects, uses, shares, and protects personal data in connection with the Schopfer Retail Platform. It is incorporated into, and should be read together with, our Terms of Use. By using the Platform, you acknowledge the practices described in this Policy.

At a Glance

What we do. Schopfer Retail is a business tool for e-commerce sellers. We collect the information needed to run your account, generate AI content you request, and connect the third-party accounts you authorise (such as Amazon Seller Central). We do not sell your personal data, and we do not share it with third parties for their advertising.

AI processing. Content you submit for AI generation is processed by third-party AI providers (Anthropic, OpenAI, Google) solely to produce your requested output. We do not permit your Amazon data or your customers’ personal data to be used to train generative AI models.

Your choices. You can access, correct, export, or delete your data, withdraw consent, and opt out of marketing at any time. Contact privacy@schopferretail.com.

1. Introduction and Scope

This Privacy Policy applies to the Schopfer Retail platform, including the website at www.schopferretail.com, associated APIs, the Schopfer Retail browser extension, and all related tools and services (collectively, the “Platform”), operated by SCHOPFER RETAIL, a company incorporated under the Companies Act, 2013, with its registered office at 441, 4th Cross Road, Royal Residency Layout, JP Nagar 9th Phase, Bengaluru, Karnataka, India — 560062 (“Schopfer Retail”, “we”, “us”, or “our”). For personal data of users in India, Schopfer Retail is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (“DPDP Act”).

The Platform is designed for business use by e-commerce sellers, agencies, and brands. We treat information about individuals using the Platform as pertaining to people acting in a business capacity; nevertheless, where that information identifies an individual, we protect it as personal data under this Policy. As of the Effective Date, the Platform is offered to users in India and the United States. Capitalised terms not defined here have the meanings given in our Terms of Use.

2. Information We Collect

Account and profile information. Name, email address, phone number, business or brand name, and related details you provide when registering, configuring your profile, or contacting support.

Payment information. Payments are processed by our payment processor, Stripe. Stripe collects and stores your payment-card details; Schopfer Retail does not store full card numbers. We retain billing records such as invoices, transaction amounts, plan and Credit purchases, and billing contact details.

User Content and AI inputs. Product information, text, images, brand assets, knowledge-base documents, and any other material you upload or submit to the Platform, including inputs submitted to generate AI content, and the outputs generated for you.

Connected third-party account data. Where you connect a third-party account — such as Amazon Seller Central via the Amazon Selling Partner API (SP-API) — we retrieve, with your authorisation, data from that account such as listing content, catalogue information, and performance reports, as needed to deliver the features you use (see Section 7).

Google account data. If you sign in with Google, we receive your basic Google profile information: name, email address, and profile picture (see Section 5).

Browser extension data. If you install the Schopfer Retail browser extension, it accesses certain browser data only within supported workflows you initiate (see Section 6).

Usage and device data. Log data, IP address, browser type, device identifiers, pages viewed, features used, and timestamps, collected automatically through cookies and similar technologies (see Section 8).

3. How We Use Information

We use the information described above for the following purposes:

  • Providing the Platform: operating your account, generating the AI content and analytics you request, publishing listings to connected platforms at your direction, and providing customer support;
  • Billing: processing Subscription and Credit purchases, invoicing, and managing renewals, reminders, and refunds;
  • Security and integrity: authenticating users, preventing fraud and abuse, enforcing usage limits, securing our systems, and verifying accounts (including IP-based checks);
  • Improving the Platform: understanding how features are used and improving performance and quality. Any use of User Content to improve our models is limited to de-identified or aggregated data as described in our Terms of Use, and never includes Amazon data or your customers’ personal data;
  • Communications: sending service and transactional messages (which you cannot opt out of while you hold an account) and, separately, product updates and marketing messages, from which you can unsubscribe at any time;
  • Legal compliance: complying with applicable law, tax and accounting obligations, and lawful requests from authorities, and establishing, exercising, or defending legal claims.

We do not sell personal data, and we do not share personal data with third parties for their own advertising or cross-context behavioural advertising.

4. AI Processing and Third-Party AI Providers

The Platform delivers generative features using third-party AI providers, currently Anthropic, OpenAI, and Google. When you request AI-generated content, your inputs (which may include User Content) are transmitted to one or more of these providers solely to produce the requested output. We use these providers under their business or API terms and configure our use so that, to the extent the provider offers such options, your inputs are not used by the provider to train its foundation models.

We do not permit data retrieved from Amazon, or personal data relating to your customers, to be submitted to AI providers for model training, and we impose confidentiality and data-protection obligations on all our sub-processors (see Section 9).

5. Google User Data and Sign-In

Where you use Google Sign-In, we request only the basic profile scopes needed to authenticate you: your name, email address, and profile picture. We use this data solely to create and secure your account and to identify you within the Platform. We do not use Google user data for advertising, and we do not sell it.

Schopfer Retail’s use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is shared with third parties only as necessary to provide or improve user-facing features (for example, our cloud hosting provider), as required by law, or with your consent.

6. Browser Extension Data

The optional Schopfer Retail browser extension assists with Amazon Seller Central workflows. It accesses browser data strictly when activated by you and exclusively within supported workflows. Specifically, the extension:

  • Reads user-opened tabs on supported Amazon Seller Central domains solely to assist with listing optimisation, content population, and SP-API workflows;
  • Uses tab permissions to open and manage Seller Central pages as part of guided workflows you expressly initiate;
  • Injects scripts on supported pages to enable form-filling, visual guidance, and content insertion as requested by you;
  • Uses identity permissions to authenticate you via Google Sign-In and to authorise Amazon Selling Partner API access, where applicable;
  • Uses network-monitoring permissions solely to track the status of API calls to Schopfer Retail backend services and update the extension interface;
  • May retrieve your IP address via a third-party IP lookup service for security verification and fraud prevention.

The extension does not monitor browsing activity outside supported workflows, does not automatically scrape or extract data from public websites, and does not access browser tabs without a direct user-initiated action. Data accessed by the extension is used only to provide the user-facing features described above; it is not sold, is not used for unrelated purposes, and is not shared with third parties except as described in this Policy.

7. Amazon Seller Data (SP-API)

Where you connect your Amazon Seller Central account, we access Amazon data through the official Amazon Selling Partner API, with your authorisation, and handle it in accordance with the Amazon Acceptable Use Policy and the Amazon Data Protection Policy (or their successors). In particular, we:

  • Use Amazon data only as necessary to provide the Services you request;
  • Do not use Amazon data to train generative AI models;
  • Retain Amazon data only for as long as reasonably necessary to provide the Services or as required by law, and delete it on disconnection of your Amazon account or on your request, subject to legal retention obligations;
  • Apply appropriate technical and organisational security safeguards to such data;
  • Do not sell Amazon data, and derive analytics only from de-identified or aggregated data to the extent permitted by Amazon’s policies and applicable law.

8. Cookies and Analytics

We use cookies and similar technologies to keep you signed in, remember preferences, secure the Platform, and understand how the Platform is used. These include essential cookies (required for the Platform to function) and analytics cookies (which help us measure and improve performance). You can control non-essential cookies through your browser settings; disabling essential cookies may prevent parts of the Platform from working. We do not use third-party advertising cookies and do not respond to “Do Not Track” browser signals at this time.

9. How We Share Information; Sub-Processors

We share personal data only in the following circumstances:

  • Service providers and sub-processors: trusted vendors that process data on our behalf to run the Platform, listed below. Each is bound by contractual confidentiality and data-protection obligations and may use the data only to provide services to us;
  • At your direction: when you publish content to a connected platform (such as Amazon), or otherwise ask us to share data;
  • Legal reasons: where disclosure is reasonably necessary to comply with applicable law, regulation, legal process, or an enforceable governmental request, or to protect the rights, safety, or property of Schopfer Retail, our users, or the public;
  • Business transfers: in connection with a merger, acquisition, financing, or sale of assets, subject to the acquirer assuming the obligations of this Policy;
  • With your consent: in any other case, only with your consent.

Current material sub-processors

ProviderRoleData involved
Amazon Web Services (AWS)Cloud hosting, storage, and infrastructureAll Platform data, including account data, User Content, and generated outputs
Stripe, Inc.Payment processing and billingName, email, billing details, and payment-card information (collected and stored by Stripe)
Anthropic, PBCAI model provider (generative content)Inputs you submit for AI generation and the resulting outputs
OpenAI (incl. OpenAI, L.L.C.)AI model provider (generative content and images)Inputs you submit for AI generation and the resulting outputs
Google LLCSign-in authentication (Google OAuth) and AI model providerBasic Google profile data (name, email, profile picture) for sign-in; inputs submitted for AI generation where Google models are used

We will update this list when we add or replace a material sub-processor. The current list is also available on request at privacy@schopferretail.com.

10. International Data Transfers

The Platform is hosted on Amazon Web Services cloud infrastructure, and your data may be stored and processed in India and the United States, including by the sub-processors listed above. Where personal data is transferred from a jurisdiction that restricts cross-border transfers, we make such transfers only under appropriate safeguards — such as the European Commission’s Standard Contractual Clauses or the UK International Data Transfer Agreement/Addendum, where applicable — together with any required supplementary measures. Transfers of personal data of Indian users are made in accordance with the DPDP Act.

11. Data Retention

We retain personal data for as long as your account is active and as needed to provide the Services. After your account is terminated or closed, you may export your User Content for thirty (30) days; following that period, we delete or de-identify your User Content and account data, except where retention is required by law (for example, tax and accounting records), is reasonably necessary to establish, exercise, or defend legal claims, or consists of de-identified or aggregated data. Residual copies in routine backups are purged on our standard backup cycle. Amazon data is retained as described in Section 7.

12. Security

We maintain commercially reasonable administrative, technical, and organisational safeguards designed to protect personal data, including encryption of data in transit (TLS), access controls, and the principle of least privilege for internal access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If a personal-data breach occurs, we will notify affected users and the relevant authorities — including the Data Protection Board of India, where the DPDP Act applies — as required by applicable law.

13. Your Rights and Choices

13.1 Users in India (DPDP Act, 2023)

If you are in India, you have the right to: (a) obtain a summary of the personal data we process about you and the processing activities undertaken; (b) request correction, completion, and updating of your personal data, and erasure of personal data that is no longer necessary; (c) have readily available means of grievance redressal (see Section 16); (d) nominate another individual to exercise your rights in the event of death or incapacity; and (e) withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing before withdrawal. If your grievance is not resolved to your satisfaction, you may complain to the Data Protection Board of India.

13.2 Users in the United States

US state privacy laws (such as the California Consumer Privacy Act) apply to businesses meeting certain thresholds, which Schopfer Retail may not currently meet. Regardless of legal thresholds, we voluntarily extend the following to all US users: the right to know what personal data we hold about you, to request a copy of it, to correct it, and to request its deletion, subject to legal retention obligations. We do not sell personal data or share it for cross-context behavioural advertising, so there is nothing to opt out of in that respect.

13.3 Exercising Your Rights

To exercise any of these rights, email privacy@schopferretail.com from your registered email address, or use the account settings within the Platform where available. We may ask you to verify your identity before acting on a request, and we will respond within the timelines required by applicable law. Authorised agents may submit requests where permitted by law, subject to verification. We will not discriminate against you for exercising your rights.

You may opt out of marketing communications at any time by using the unsubscribe link in any marketing email or by writing to privacy@schopferretail.com. Service and billing communications will continue while you hold an account.

14. Children

The Platform is intended for business use by persons aged 18 or over. We do not knowingly collect personal data from anyone under 18. If we become aware that such data has been collected, we will delete it and suspend the associated account. If you believe a person under 18 has provided us personal data, please contact privacy@schopferretail.com.

15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to your registered address and/or by prominent notice on the Platform at least fourteen (14) days before the changes take effect, unless a shorter period is required by law or the change relates to a new feature or a legal or security requirement. The “Effective Date” above reflects the latest revision. Your continued use of the Platform after the effective date constitutes acknowledgement of the updated Policy; where applicable law requires fresh consent for a change, we will seek it.

16. Grievance Officer and Contact

For questions, requests, or complaints about this Policy or our data practices, contact:

SCHOPFER RETAIL

Platform
Schopfer Retail (www.schopferretail.com)
Data-protection queries
info@schopferretail.com
Grievance Officer & Data Protection Contact
Naveen Kumar, Managing Partner
Grievance Officer email
info@schopferretail.com
Registered office
441, 4th Cross Road, Royal Residency Layout, JP Nagar 9th Phase, Bengaluru, Karnataka, India — 560062

For users in India: In accordance with the Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 and the DPDP Act, 2023, our Grievance Officer will acknowledge your complaint within 24 hours and resolve it within 15 days.