Privacy Policy

Effective Date: 1 January 2026

1. Introduction

Crovax Capital Ltd ("SuperLocale", "we", "us", or "our"), a Swiss company registered under CHE-309.490.623, operates the website https://www.superlocale.com and the SuperLocale AI-powered Shopify translation platform (the "Service"). We are committed to protecting your privacy in accordance with the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR). This Privacy Policy outlines how we collect, use, and protect your personal data when you use our Service. By using our Service, you accept the practices described herein.

2. Purpose

This Privacy Policy explains:

  • What personal data we collect and why.
  • How we use, store, and share your data.
  • Your rights regarding your personal data.
  • Our commitment to compliance with FADP and GDPR.

We will not use or share your data except as described in this policy or with your explicit consent.

3. What is Personal Data?

Personal data includes any information that can identify you, directly or indirectly, such as your name, email address, IP address, or device identifiers. Under FADP and GDPR, this also includes usage data or encrypted data linked to an individual.

4. What is Processing?

Processing refers to any action performed on personal data, including collection, storage, use, sharing, or deletion.

5. Scope of This Policy

This policy applies to personal data for which SuperLocale is the data controller, meaning we determine the purpose and means of processing. It covers data collected via our website, platform, and support channels.

6. Who's Data Do We Process?

We process personal data from:

  • Platform Users: Shopify merchants and their team members using our translation platform.
  • Organisation Representatives: Contacts provided during account registration.
  • Website Visitors: Individuals browsing our website.
  • Support Inquirers: Individuals contacting us via email or support channels.

7. Types of Data, Purposes, and Legal Basis

7.1 Platform Users (Shopify Merchants)

Data: Contact details (name, email, Shopify store URL), usage data (translation requests, language settings), technical data (IP address, browser, device).

Purposes and Legal Basis:

  • Provide and maintain the Service (contract performance).
  • Process translation requests and store content (contract performance).
  • Improve platform functionality and translation quality (legitimate interest).
  • Ensure security and prevent abuse (legal obligation, legitimate interest).
  • Offer support (contract performance).

7.2 Store Content Data

When merchants connect their Shopify store, our platform processes store content — including product descriptions, collection names, and page text — solely for the purpose of providing translations. This content may include data about the merchant's end customers (e.g. product names, descriptions). We process such content only as a data processor on behalf of the merchant, not as a data controller.

7.3 Website Visitors

Data: Technical data (IP address, browser, device), usage data (pages visited, time spent), cookie data (per our Cookie Policy).

Purposes and Legal Basis:

  • Optimise website performance (legitimate interest).
  • Analyse user behaviour to improve content (legitimate interest, consent for non-essential cookies).

8. How We Do Not Use Your Data

We will never:

  • Sell your personal data.
  • Share your data for third-party marketing.
  • Use your store content to train AI models without your explicit consent.
  • Process your data for purposes not specified here without your consent.

9. AI and Automated Processing

Our platform uses AI to translate store content automatically. Translations are generated without manual human review of individual outputs, but our systems are subject to ongoing quality monitoring. We do not use fully automated decision-making that produces legal or significant effects on individuals.

10. Data Sharing with Third Parties

10.1 Infrastructure Providers

  • Amazon Web Services (AWS): Data storage in the EU.
  • Cloudflare: Content delivery and security.

10.2 Service Providers

We share data with trusted providers for IT and analytics. All providers are bound by Data Processing Agreements ensuring data security and compliance.

10.3 Shopify

Our Service integrates with Shopify's API. Data exchanged with Shopify is subject to Shopify's own Privacy Policy and Terms of Service. We are not responsible for Shopify's data practices.

11. International Data Transfers

Our primary data storage is in the EU (AWS). For transfers outside Switzerland or the EEA, we use Standard Contractual Clauses (SCCs) and vendor assessments to ensure adequate data protection. Switzerland is recognised as providing adequate data protection under GDPR, but we apply additional safeguards for third-country transfers.

12. Security Measures

We protect your data with:

  • Encryption in transit (TLS) and at rest.
  • Secure access controls and multi-factor authentication.
  • Regular security audits.
  • Incident response plans, including data breach notifications to the Swiss FDPIC and affected users within legal timeframes (72 hours for GDPR).

13. Data Retention

We retain data only as long as necessary:

  • Account Data: 1 year after account closure, unless required for legal compliance (e.g. Swiss tax law, up to 10 years).
  • Usage Data: 1 year from collection.
  • Technical Logs: 90 days.
  • Store Content (translation inputs/outputs): deleted within 30 days of account closure.
  • Support Communications: 1 year after resolution.

14. Your Rights

Under FADP and GDPR, you have the right to:

  • Access your personal data.
  • Correct inaccurate data.
  • Request deletion ("right to be forgotten").
  • Restrict or object to processing.
  • Data portability.
  • Be informed about data processing.

15. Exercising Your Rights

Contact us at:

  • Email: [email protected]
  • Address: Crovax Capital Ltd, Chapfstrasse 102, 8126 Zumikon, Switzerland

We respond within 30 days (extendable to 90 days for complex requests). If unsatisfied, contact the Swiss Federal Data Protection and Information Commissioner (FDPIC) at www.edoeb.admin.ch, Feldeggweg 1, 3003 Bern, Switzerland. For EU users, you may also contact your local data protection authority.

16. Cookies

We use:

  • Essential Cookies: For website and platform functionality.
  • Analytics Cookies: To analyse usage (consent required).
  • Preference Cookies: To save settings (consent required).

We obtain explicit consent for non-essential cookies via a cookie banner.

17. Third-Party Websites

Our Service may link to third-party sites (e.g. Shopify, translation engine providers). We are not responsible for their privacy practices. Review their policies before sharing data.

18. Children's Data

Our Service is not intended for users under 16. We do not knowingly collect data from children. Contact us if you believe we have such data.

19. Amendments

We reserve the right to modify this Privacy Policy at any time. We will notify users of material changes via email or a prominent notice on our website. Continued use of the Service following notification constitutes acceptance of the amended policy.