Privacy Policy.
Last updated: 19 July 2026
Data controller: Carlos Andrés Rosas Curilén, RUN 17.411.258-4, domiciled in Santiago, Chile. Direct email: contact@sololander.com
Governing law: this policy is governed by Chilean law (Ley 19.628 and, from the date it comes into force, Ley 21.719). If you are in the European Union, you also have the rights granted by the GDPR.
1. Who we are and scope
Sololander is a software as a service (SaaS) that helps dropshipping merchants generate and publish product pages for their Shopify stores.
This Privacy Policy explains how we handle the personal data of our subscriber users (the merchants who create an account and use Sololander) and also of those who leave us their details in the sololander.com forms (for example, to receive the launch notice or news), even if they are not yet customers.
Important: this policy covers the subscriber user's data. It does not cover the data of the end consumers who buy from the user's Shopify store; that data is collected and managed by the merchant themselves as an independent controller (see section 9).
If you have questions about this policy, you can contact us through the means indicated in section 14.
2. What data we collect
We collect only the data necessary to provide the service:
- Account data. When you sign up (with email and password or through Google), we process your email address and the identifiers associated with your account. Authentication is handled through Supabase (see section 5).
- Usage data. Contracted plan and usage counters (for example, number of generations or "runs" and images used), to apply your plan's limits and show you your consumption.
- Shopify connection data. When you connect your store via OAuth, we store your store's domain and an access token that lets us generate and publish pages on your behalf (read and write products, theme and metafields of your store).
- Product links you provide to us. To generate content, you give us the link to a product page (for example, from a competitor or supplier). We extract product data from that page (title, description, images, features). This is product data, not personal data.
- Payment data (through Dodo Payments). Payments are processed through Dodo Payments, which acts as Merchant of Record. Sololander does not store card data. We receive webhooks from Dodo with the status of your subscription (for example, active, paused, cancelled) and minimal billing data necessary to manage your account.
- Technical data and logs. Like any online service, our servers log technical data (for example, IP address, date and time, request type, errors) for security, diagnostic and operational purposes.
- Data you leave us on the landing page. If you complete the access form on sololander.com, we process your email and, if you provide it, your store's URL, in order to notify you of the launch and send you information about the service. You can unsubscribe at any time from the email itself.
We do not request or process special categories of data (sensitive data) to provide the service.
3. How we use the data
We use the above data to:
- Provide the service: create and maintain your account and authenticate you.
- Generate and publish pages: process the links you give us, generate the content with AI providers and publish it to your connected Shopify store.
- Billing: manage your subscription, plan and usage limits through Dodo Payments.
- Support: answer your queries and resolve incidents.
- Service improvement: understand aggregate usage in order to fix errors and improve features.
- Security: prevent fraud, abuse and unauthorised access, and maintain the integrity of the system.
We do not sell your personal data or use it for third-party advertising.
4. Basis for processing
Where applicable (for example, under the GDPR or other equivalent rules), we process your data on the following legal bases:
- Performance of the contract: to register you, provide you with the service, generate and publish pages and manage your subscription.
- Legitimate interest: for the security of the service, fraud prevention, technical diagnostics and product improvement, always in a proportionate manner and respecting your rights.
- Consent: where the law requires it, for example, when you leave your email on the landing page to receive notices, or for behavioural analytics (Microsoft Clarity; see section 10). You can withdraw your consent at any time.
- Compliance with legal obligations: when we must retain or disclose data due to legal, accounting or tax requirements.
5. Who we share data with (sub-processors and third parties)
To provide the service we use external providers that process data on our behalf or as independent controllers depending on their role. We share with them only the data necessary for their function:
| Provider | What we use it for | What data it receives |
|---|---|---|
| Supabase | Authentication and account management (USA) | Email, login credentials, account identifiers |
| Shopify | Connection with your store and publication of pages (Canada / USA) | Your store's domain and access token, generated content |
| Dodo Payments (Merchant of Record) | Payment processing and billing (USA) | Payment and billing data (card data is handled by Dodo; we do not store it) |
| Anthropic | Text/copy generation using AI (USA) | Product data extracted from the link you give us |
| Kie / GPT Image | On-demand image generation using AI (USA) | Instructions and product data necessary to generate the image |
| Cloudflare | Delivery and protection of the dashboard and the landing page (global network, headquartered in the USA) | Technical connection data (for example, IP, requests) |
| Hostinger | Hosting of the control plane and the database (EU). The same server hosts our automation engine (self-hosted n8n), through which internal service notices and lead data pass | Account, usage, connection and log data stored on the server |
| Brevo | Sending of transactional emails and service notices (EU) | Email address and message content |
| Microsoft Clarity | Behavioural analytics (heatmaps and session recording) on the landing page and the dashboard, only if you accept analytics cookies (USA) | Browsing interactions and technical device data |
In brackets we indicate the main country or region where each provider processes the data (see also section 6 on international transfers).
These providers have their own privacy policies. We may update this list as our providers change; in that case we will reflect the changes in this policy (see section 13).
We may also disclose data when required by law or a competent authority, or to protect our rights, safety or those of third parties.
6. International transfers
Some of our providers are located in or process data outside your country of residence (for example, in the United States). This means that your data may be transferred and processed in jurisdictions with data protection rules different from those of your country.
Our providers process data in the United States and the European Union (see the table in section 5). These transfers are covered by each provider's data processing agreements (DPA), which incorporate standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework. Chile does not have an adequacy decision from the European Union; as controller, we apply those same contractual safeguards.
7. Retention and deletion
We retain your data while your account is active and for as long as necessary to provide the service.
- If you delete your account or uninstall the app from your Shopify store, we delete or anonymise your personal data within a maximum of 30 days, except for what we must retain by legal or accounting obligation or in order to resolve disputes.
- When you disconnect your store, we stop using the Shopify access token and proceed to delete it.
- We may retain technical logs and billing data for the periods required by applicable regulations.
You can request the deletion of your account through the contact means in section 14.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access: obtain a copy of the personal data we process about you.
- Rectification: correct inaccurate or incomplete data.
- Deletion: request the erasure of your data ("right to be forgotten").
- Portability: receive your data in a structured and commonly used format.
- Objection and restriction: object to certain processing or ask that it be restricted.
- Withdraw consent: where the processing is based on your consent.
To exercise these rights, contact us through the means in section 14. We may ask you to verify your identity before handling the request. If you believe we have not respected your rights, you can complain: if you are in Chile, to the Agencia de Protección de Datos Personales; if you are in the European Union, to the supervisory authority of your Member State.
9. Data of your own end customers
Sololander helps you create product pages, but it does not manage the data of the consumers who buy from your store. That data (orders, addresses, payments of your customers) is collected and processed by your Shopify store, and you are the controller of its processing towards those consumers.
As a merchant, you are responsible for having your own privacy policy and for complying with the applicable regulations regarding your end customers.
10. Cookies and local storage
We use cookies and browser local storage for the operation of the service and, only if you accept it, for usage analytics. In particular:
- Authentication session: to keep you identified while you use the dashboard.
- Dashboard preferences: some local key necessary for the operation of the interface (including the key where we store your choice about analytics cookies).
- Behavioural analytics (Microsoft Clarity): we use Microsoft Clarity, an analytics tool that uses cookies and scripts to generate heatmaps and session recordings that help us improve the service. Clarity is only activated if you accept it in the cookie notice, and you can withdraw your consent at any time from the "Cookies" link in the footer.
We do not use third-party advertising cookies. You can manage or delete cookies from your browser settings, although disabling them may affect the operation of the service.
11. Security
We apply reasonable technical and organisational measures to protect your data, among them: access through authentication, use of tokens instead of credentials where possible, and separation of responsibilities (for example, card data is processed by Dodo Payments and is not stored in Sololander).
No system is completely secure, so we cannot guarantee absolute security. If we detect a security incident that affects you, we will act in accordance with the applicable regulations.
12. Minors
Sololander is a service aimed at people who operate a business and is not aimed at people under 18 years of age. We do not knowingly collect data from minors. If you believe a minor has provided us with data, contact us so we can delete it.
13. Changes to this policy
We may update this policy to reflect changes in the service, in our providers or in the applicable regulations. We will publish the updated version with a new "last updated" date. If the changes are significant, we will endeavour to notify you by a reasonable means.
14. Contact
For privacy queries or to exercise your rights, contact us:
- Email: contact@sololander.com
- Form: sololander.com/en/help
15. Language of this document
This document exists in Spanish and in English. The Spanish version is the original and, in the event of any discrepancy between the two versions, the Spanish version prevails.