
Privacy Policy
Last Updated: October 16, 2025
1. Introduction
Harmona AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketing analytics platform and services.
This policy applies to all users of our Service, whether accessed directly through our website or through our Shopify app integration. By using our Service, you consent to the practices described in this Privacy Policy.
2. Information We Collect
2.1 Information You Provide
Account information (name, email, company details)
Shopify store connection details
Communication data when you contact support
Feedback and survey responses
2.2 Shopify Store Data
Store information (name, domain, plan, settings)
Sales and order data
Product catalog and inventory data
Marketing campaign performance
Geographic sales distribution
Note: Shopify does not share customer's personal information with third-party apps unless explicitly permitted. We only access store data necessary to provide our analytics services, and we do not collect customer personal identifiers data such as names, emails.
2.3 Automatically Collected Information
Usage data and analytics
Device and browser information
IP addresses and location data
Cookies and similar tracking technologies
3. How We Use Your Information
We use the collected information for the following purposes:
Service Delivery: Generate analytics, insights, and AI-powered recommendations
Platform Improvement: Enhance features and develop new functionality
Support: Provide customer service and technical assistance
Communication: Send service updates, security alerts, and product announcements
Security: Detect and prevent fraud, abuse, and security incidents
Legal Compliance: Comply with applicable laws and regulations
Important: We never sell your personal data or business information to third parties. Your data is used exclusively to provide and improve our analytics services.
4. Data Sharing and Disclosure
We may share your information in the following limited circumstances:
4.1 Service Providers
We work with trusted third-party service providers for hosting, analytics, payment processing, and customer support. These providers are contractually bound to protect your information and use it only for authorized purposes.
4.2 Legal Requirements
We may disclose information if required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users or others.
4.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to equivalent privacy protections.
5. Data Security
We implement industry-standard security measures to protect your information:
Encryption in transit and at rest
Regular security assessments and monitoring
Access controls and employee training
Secure cloud infrastructure with reputable providers
Regular backups and disaster recovery procedures
We employ commercially reasonable security measures designed to protect your information. However, please be aware that no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.
6. Data Retention
We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this policy:
Account Data: Retained while your account is active
Analytics Data: Retained while your account is active
Support Communications: Retained for 3 years for quality and training purposes
Legal Requirements: Some data may be retained longer if required by law
After account deletion, we will delete your data within 30 days unless legally required to retain it longer.
7. Your Rights and Choices
You have several rights regarding your personal information:
Access: Request a copy of your personal data
Correction: Update or correct inaccurate information
Deletion: Request deletion of your personal data
Portability: Export your data in a structured format
Restriction: Limit how we process your data
Objection: Object to certain processing activities
To exercise these rights, contact us at privacy@harmona.ai. We will respond within 30 days of receiving your request.
Account Management: You can update most account information directly through your dashboard settings. For data export or deletion requests, please contact our support team.
8. Cookies and Data Collection Technologies
We and our service providers use anonymous identifiers, pixels, container tags and other technologies in order to provide our platform and ensure that it performs properly, to analyze our performance and marketing activities, for personalization purposes, for product development and improvements, and to personalize your experience.
8.1 About Cookies and Our Approach
Cookies are packets of information sent to your web browser and then sent back by the browser each time it accesses the server that sent the cookie. Some cookies are removed when you close your browser tab or window. These are the "Session Cookies". Some last for longer periods and are called "Persistent Cookies".
We do not use traditional Session Cookies. Instead, we primarily use HTML5 Local Storage for essential platform functionality, which provides better privacy and security for your data.
8.2 HTML5 Local Storage
We use HTML5 Local Storage for storing your authentication data and application state. HTML5 Local Storage differs from browser cookies in the amount and type of data stored, and how it stores data locally in your browser.
Authentication Data: HTML5 Local Storage securely stores your session tokens to keep you logged in
Application State: Remembers your preferences and settings
Shopify Integration: Maintains your Shopify app connection state
8.3 Do Not Track and Managing Your Data
While we do not change our practices in response to a "Do Not Track" signal in the HTTP header from a browser or mobile application, you have full control over your stored data. You can clear HTML5 Local Storage data at any time through your browser settings.
Please note that clearing this data will log you out and reset your application preferences, which may affect your ability to use the platform until you log in again.
Privacy Benefits: By using HTML5 Local Storage instead of traditional cookies for essential authentication data, we ensure your data stays local to your browser and domain, with no cross-site tracking capabilities.
9. International Data Transfers
Our servers and service providers may be located in different countries. We ensure that international transfers of personal data are protected by appropriate safeguards, including:
Standard contractual clauses approved by relevant authorities
Adequacy decisions by data protection authorities
Other legally recognized transfer mechanisms
10. Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:
Email notification to your registered email address
Prominent notice in our application
Updating the "Last Updated" date at the top of this policy
Continued use of our Service after changes indicates your acceptance of the updated policy.
11. Compliance and Regulations
We are committed to complying with applicable data protection regulations, including:
General Data Protection Regulation (GDPR) for EU users
California Consumer Privacy Act (CCPA) for California residents
Personal Information Protection and Electronic Documents Act (PIPEDA) for Canadian users
Other applicable regional privacy laws
California Residents: Under the CCPA, you have additional rights including the right to know what personal information we collect and sell, and the right to opt-out of the sale of personal information. We do not sell personal information.
12. Contact Information
If you have questions about this Privacy Policy or our data practices, please contact us:
By using Harmona AI, you acknowledge that you have read, understood, and agree to this Privacy Policy and our data practices.