Privacy Policy
Profitablo s.r.o.
Last updated: September 21, 2026
1. Who we are
Profitablo s.r.o. ("Profitablo", "we", "us") operates the Profitablo profit analytics platform at profitablo.com and app.profitablo.com (the "Service").
- Registered address: Fialová 4023/2, 851 07 Bratislava, Slovakia
- Company ID (IČO): 53549457 · VAT ID (IČ DPH): SK2121421478
- Contact for all privacy matters: rob@profitablo.com
We have not appointed a Data Protection Officer, as it is not legally required. All privacy inquiries go to the address above.
2. Who this policy applies to
- Website visitors of profitablo.com.
- Users: people who register for and use the Service on behalf of a business ("Customer").
- End customers: individuals whose data is processed through a Customer's connected store and advertising accounts (for example, a shopper who buys from a Customer's Shopify store).
Profitablo is a business analytics tool intended for professional use by persons aged 18 or older. It is not directed at children.
3. What the Service does
Profitablo helps e-commerce businesses understand their profit. A User connects their online store and their advertising and analytics accounts. Profitablo reads order, cost and advertising performance data from those platforms, combines it, and shows the User reports such as net revenue, cost of goods, advertising spend, attribution of orders to marketing channels, and profit after advertising cost. Profitablo also delivers automated daily summaries by email, Slack or SMS if the User enables them.
Profitablo's access to third-party platforms is read-only. Profitablo does not create, edit, pause, publish or delete campaigns, ads, audiences, pins, boards, products or orders on any connected platform.
4. Our role under the GDPR
- Data Controller for: User account data, billing data, website analytics, product usage data, and support communications.
- Data Processor on behalf of the Customer for: end-customer data and business data obtained through the Customer's connected integrations. The Customer is the Controller of that data and is responsible for having a lawful basis to process it and for informing their end customers as required. Our processing on behalf of Customers is governed by our Data Processing Agreement.
5. Data we collect and how we use it
5.1 Account and User data (we are Controller)
Name, email address, company name, authentication data, role and team membership, subscription and billing status, support requests.
Used to: create and secure the account, provide the Service, bill for it, communicate about the Service.
Legal basis: performance of a contract; legal obligation (billing records); legitimate interest (security, fraud prevention).
5.2 Website and product usage data (we are Controller)
IP address, device and browser information, log files, session and cookie identifiers, pages viewed, feature usage.
Used to: operate and secure the Service, diagnose problems, understand how the product is used, and — with consent — marketing analytics.
Legal basis: legitimate interest; consent for non-essential cookies. See our Cookie Policy.
5.3 Store and order data obtained through integrations (we are Processor)
When a User connects an e-commerce platform (currently Shopify; other platforms may be offered), Profitablo reads, via the platform's official API and the User's authorization:
- Orders, order line items, refunds, discounts, fulfilment and payment status.
- Products, variants, inventory and cost of goods.
- Customer records associated with orders: name, email address, phone number, shipping and billing address, order history.
- Store settings needed for correct reporting: currency, time zone.
Used to: calculate revenue, refunds, margins and profit; attribute orders to marketing channels; produce the reports and summaries the User has enabled.
5.4 Advertising and analytics platform data obtained through integrations (we are Processor)
When a User connects an advertising or analytics platform, Profitablo accesses only what is needed to report advertising cost and profit, on a read-only basis, through the platform's official API after the User authorizes access via OAuth:
- Google Ads (scope
https://www.googleapis.com/auth/adwords): the list of accessible Google Ads accounts; campaign, ad group and ad structure; and daily performance metrics (cost, impressions, clicks, conversions). We read this data using the Google Ads API reporting service. We do not perform any write ("mutate") operations and do not upload conversions. - Google account identity (
openid,userinfo.email,userinfo.profile): the email address and name of the Google account that authorized access, used only to show which account is connected. - Meta (Facebook and Instagram) Ads (
ads_read): the list of accessible ad accounts and campaign, ad set and ad performance metrics, read via the Marketing API Insights endpoints. - TikTok Ads: advertiser account identity and campaign, ad group and ad performance metrics, read via the TikTok Marketing API reporting endpoints.
- Pinterest Ads (
ads:read,user_accounts:read): the connected user account identity and campaign, ad group and ad performance metrics, read via the Pinterest API. - Microsoft Advertising: advertiser account identity and campaign performance metrics, if offered and connected.
Used to: attribute the Customer's orders and revenue to advertising channels and campaigns and calculate profit after advertising cost. This is the core function of the Service.
Google API Services User Data Policy — Limited Use disclosure. Profitablo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, Google user data is used only to provide and improve the Service's user-facing features, is not used for advertising, is not sold, is not transferred to third parties except as necessary to provide the Service (our subprocessors), for security, or to comply with law, and is not read by humans except with the User's consent, for security purposes, or to comply with law.
5.5 Profitablo tracking pixel (we are Processor)
A Customer may install the Profitablo pixel on their own store (as a Shopify web pixel or a script on their site). The pixel records, for visitors of that store: page views, product and collection views, add-to-cart, checkout started and purchase events; a pseudonymous visitor identifier and session identifier stored in the visitor's browser; the page URL, referrer and UTM parameters; advertising click identifiers present in the URL (such as gclid, fbclid, ttclid, msclkid, epik); browser and device information; and IP address (used for security, rate limiting and, where applicable, coarse matching of a purchase to an earlier visit).
The pixel respects the store's consent settings: on Shopify it runs under Shopify's Customer Privacy controls, and it records the consent state with each event. Where consent for analytics is not given, events are not linked to a persistent visitor identifier.
Used to: attribute the Customer's orders to marketing channels.
5.6 Billing data
Payment processing is performed by Stripe. Profitablo does not store full card numbers. We retain invoices and transaction records as required by Slovak accounting law.
6. How we share data
We do not sell personal data and do not share it with third parties for their own marketing. We share data only with:
- Subprocessors that host or support the Service under contract with us (listed on our Subprocessors page), including: Supabase / Amazon Web Services (database, authentication and application hosting, EU-Frankfurt), Stripe (payments), Slack and email/SMS delivery providers (for summaries the User enables), the Lovable AI Gateway and Google Gemini (AI-generated summaries, see Section 7), and error-monitoring and email providers.
- The Customer's own team: data belonging to a Customer is visible only to Users the Customer has authorized on that account.
- Authorities where required by law.
- A successor in the event of a merger or acquisition, under the same protections.
Data received from Google APIs is shared only with subprocessors as necessary to operate the Service, and never for advertising purposes.
7. AI and automated processing
Profitablo generates written summaries and forecasts using AI models accessed through the Lovable AI Gateway, which routes requests to Google Gemini. The AI receives aggregated business metrics and, where needed for a feature, product or campaign names; it is not used to make decisions about individuals. AI outputs are informational only, are not financial, accounting, tax or investment advice, and do not produce automated decisions with legal or similarly significant effects on any person.
8. Cookies and similar technologies
The website and Service use essential cookies (login, security), analytics cookies and, with consent, marketing cookies. Details and choices are in our Cookie Policy. The Profitablo pixel described in Section 5.5 sets identifiers only on the Customer's store, under the Customer's consent management.
9. Where data is stored and international transfers
Primary storage is in Amazon Web Services data centres in Frankfurt, Germany (EU). Some subprocessors process data outside the EU. Where that happens we rely on EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
10. How long we keep data
- Account data: for the life of the account.
- Store, order and advertising platform data: for as long as the integration is connected and the account is active.
- When a User disconnects an integration, the platform's access token is deleted immediately. Data already obtained from that platform is retained so that reconnecting the same account preserves history, and is deleted or irreversibly anonymized within 30 days of a deletion request to rob@profitablo.com.
- When an account is terminated, all Customer data is deleted within 30 days.
- Backups: up to 90 days, then overwritten.
- Billing records: as required by Slovak law (currently 10 years).
- Pixel event data: retained per the Customer's configured retention period, by default 13 months.
11. Data deletion requests
You can delete data in three ways:
- Disconnect an integration in the Service (Integrations → Disconnect). This immediately deletes our stored access token for that platform, so no further data is collected. To have data already collected deleted, email rob@profitablo.com — we complete deletion within 30 days and confirm by email.
- Delete your account by emailing rob@profitablo.com from your registered address. We complete deletion within 30 days and confirm by email.
- Revoke our access at the platform: Google Account → Security → Third-party access; Facebook → Settings → Business integrations; TikTok Ads Manager → Tools → Authorization management; Pinterest → Settings → Apps; Shopify Admin → Apps → Uninstall. Revocation stops all further access; email us to have already-collected data deleted.
End customers of a Customer's store should direct requests to that Customer, who is the Controller; we assist Customers in fulfilling such requests. For Shopify stores, we honour Shopify's mandatory data request, customer redaction and shop redaction webhooks automatically.
12. Security
Data is encrypted in transit (TLS) and at rest. Access tokens for connected platforms are stored encrypted and are never shown in the interface. Access to Customer data is restricted by tenant-level row-level security, authenticated sessions and role-based permissions. We log access and changes to sensitive data. Passwords are checked against known-breach lists at sign-up.
13. Your rights
If you are in the EU/EEA or UK, you may: access your data; have it corrected or erased; restrict or object to processing; receive it in a portable format; and withdraw consent at any time without affecting prior processing. To exercise these rights, email rob@profitablo.com. You may also complain to the Slovak supervisory authority, Úrad na ochranu osobných údajov SR (dataprotection.gov.sk), or to your local authority.
14. Changes to this policy
We will post any changes on this page and update the date above. Material changes will be notified to Users by email or in the Service.
15. Contact
Profitablo s.r.o., Fialová 4023/2, 851 07 Bratislava, Slovakia · rob@profitablo.com