Harmona AI

Privacy Policy

Last Updated: October 16, 2025

1. Introduction

Harmona AI ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our marketing analytics platform and services.

This policy applies to all users of our Service, whether accessed directly through our website or through our Shopify app integration. By using our Service, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide

  • Account information (name, email, company details)

  • Shopify store connection details

  • Communication data when you contact support

  • Feedback and survey responses

2.2 Shopify Store Data

  • Store information (name, domain, plan, settings)

  • Sales and order data

  • Product catalog and inventory data

  • Marketing campaign performance

  • Geographic sales distribution

Note: Shopify does not share customer's personal information with third-party apps unless explicitly permitted. We only access store data necessary to provide our analytics services, and we do not collect customer personal identifiers data such as names, emails.

2.3 Automatically Collected Information

  • Usage data and analytics

  • Device and browser information

  • IP addresses and location data

  • Cookies and similar tracking technologies

3. How We Use Your Information

We use the collected information for the following purposes:

  • Service Delivery: Generate analytics, insights, and AI-powered recommendations

  • Platform Improvement: Enhance features and develop new functionality

  • Support: Provide customer service and technical assistance

  • Communication: Send service updates, security alerts, and product announcements

  • Security: Detect and prevent fraud, abuse, and security incidents

  • Legal Compliance: Comply with applicable laws and regulations

Important: We never sell your personal data or business information to third parties. Your data is used exclusively to provide and improve our analytics services.

4. Data Sharing and Disclosure

We may share your information in the following limited circumstances:

4.1 Service Providers

We work with trusted third-party service providers for hosting, analytics, payment processing, and customer support. These providers are contractually bound to protect your information and use it only for authorized purposes.

4.2 Legal Requirements

We may disclose information if required by law, court order, or government regulation, or to protect our rights, property, or safety, or that of our users or others.

4.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, user information may be transferred as part of that transaction, subject to equivalent privacy protections.

5. Data Security

We implement industry-standard security measures to protect your information:

  • Encryption in transit and at rest

  • Regular security assessments and monitoring

  • Access controls and employee training

  • Secure cloud infrastructure with reputable providers

  • Regular backups and disaster recovery procedures

We employ commercially reasonable security measures designed to protect your information. However, please be aware that no security system is impenetrable. In the event of a data breach affecting your personal information, we will notify you and relevant authorities as required by applicable law.

6. Data Retention

We retain your information for as long as necessary to provide our services and fulfill the purposes outlined in this policy:

  • Account Data: Retained while your account is active

  • Analytics Data: Retained while your account is active

  • Support Communications: Retained for 3 years for quality and training purposes

  • Legal Requirements: Some data may be retained longer if required by law

After account deletion, we will delete your data within 30 days unless legally required to retain it longer.

7. Your Rights and Choices

You have several rights regarding your personal information:

  • Access: Request a copy of your personal data

  • Correction: Update or correct inaccurate information

  • Deletion: Request deletion of your personal data

  • Portability: Export your data in a structured format

  • Restriction: Limit how we process your data

  • Objection: Object to certain processing activities

To exercise these rights, contact us at privacy@harmona.ai. We will respond within 30 days of receiving your request.

Account Management: You can update most account information directly through your dashboard settings. For data export or deletion requests, please contact our support team.

8. Cookies and Data Collection Technologies

We and our service providers use anonymous identifiers, pixels, container tags and other technologies in order to provide our platform and ensure that it performs properly, to analyze our performance and marketing activities, for personalization purposes, for product development and improvements, and to personalize your experience.

8.1 About Cookies and Our Approach

Cookies are packets of information sent to your web browser and then sent back by the browser each time it accesses the server that sent the cookie. Some cookies are removed when you close your browser tab or window. These are the "Session Cookies". Some last for longer periods and are called "Persistent Cookies".

We do not use traditional Session Cookies. Instead, we primarily use HTML5 Local Storage for essential platform functionality, which provides better privacy and security for your data.

8.2 HTML5 Local Storage

We use HTML5 Local Storage for storing your authentication data and application state. HTML5 Local Storage differs from browser cookies in the amount and type of data stored, and how it stores data locally in your browser.

  • Authentication Data: HTML5 Local Storage securely stores your session tokens to keep you logged in

  • Application State: Remembers your preferences and settings

  • Shopify Integration: Maintains your Shopify app connection state

8.3 Do Not Track and Managing Your Data

While we do not change our practices in response to a "Do Not Track" signal in the HTTP header from a browser or mobile application, you have full control over your stored data. You can clear HTML5 Local Storage data at any time through your browser settings.

Please note that clearing this data will log you out and reset your application preferences, which may affect your ability to use the platform until you log in again.

Privacy Benefits: By using HTML5 Local Storage instead of traditional cookies for essential authentication data, we ensure your data stays local to your browser and domain, with no cross-site tracking capabilities.

9. International Data Transfers

Our servers and service providers may be located in different countries. We ensure that international transfers of personal data are protected by appropriate safeguards, including:

  • Standard contractual clauses approved by relevant authorities

  • Adequacy decisions by data protection authorities

  • Other legally recognized transfer mechanisms

10. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. We will notify you of material changes by:

  • Email notification to your registered email address

  • Prominent notice in our application

  • Updating the "Last Updated" date at the top of this policy

Continued use of our Service after changes indicates your acceptance of the updated policy.

11. Compliance and Regulations

We are committed to complying with applicable data protection regulations, including:

  • General Data Protection Regulation (GDPR) for EU users

  • California Consumer Privacy Act (CCPA) for California residents

  • Personal Information Protection and Electronic Documents Act (PIPEDA) for Canadian users

  • Other applicable regional privacy laws

California Residents: Under the CCPA, you have additional rights including the right to know what personal information we collect and sell, and the right to opt-out of the sale of personal information. We do not sell personal information.

12. Contact Information

If you have questions about this Privacy Policy or our data practices, please contact us:

Harmona AI - Privacy Team

Email: privacy@harmona.ai

Website: harmona.ai

By using Harmona AI, you acknowledge that you have read, understood, and agree to this Privacy Policy and our data practices.