Fischer & Habel App

Privacy Policy

Last updated: 7 June 2026

Fischer & Habel App is an internal e-commerce operations platform operated by Fischer & Habel GmbH ("we", "us"), an e-commerce agency. This policy explains what data the platform processes, why, and how it is protected. It covers data accessed through connected third-party platforms (Amazon, Shopify, Google Ads, Meta, Klaviyo) on behalf of our clients.

Data controller

Fischer & Habel GmbH. Privacy contact: privacy@fischer-habel.com.

For client business data accessed via connected accounts, our clients are the controllers and Fischer & Habel GmbH acts as a processor under a data processing agreement; we process that data only on their documented instructions.

What we process

  • Account & user data: names, email addresses, and authentication identifiers of our staff who use the platform.
  • Connected-platform business data: product catalogs, listings, orders and aggregated sales metrics, advertising performance (spend, impressions, clicks, conversions), and email/SMS campaign performance — retrieved via the official APIs of Amazon, Shopify, Google Ads, Meta, and Klaviyo after a client authorizes the connection.
  • Operational metadata: logs, audit events, and approval decisions generated while operating the platform.

We retrieve only the fields needed for analytics and operations. Where advertising or order data may include limited personal data, we minimize it and aggregate wherever possible.

Why we process it (legal bases under the GDPR)

  • Performance of a contract with our clients (operating their stores and advertising).
  • Legitimate interests in providing, securing, and improving the platform.
  • Consent, where required, granted by the client when connecting a third-party account via OAuth.

How connections work

Connections are authorized by the client through each platform's official OAuth/authorization flow. We never ask for or store platform passwords. Access tokens are stored encrypted and are used only to perform the operations the client has approved. A client can revoke access at any time from the connected platform or by asking us to disconnect.

Sub-processors

We use a limited set of vetted providers:

  • Supabase (database, authentication, encrypted secret storage) — EU region.
  • Vercel (application hosting).
  • AI model providers (e.g. Anthropic, and other models via the Vercel AI Gateway) — used to generate drafts (listing copy, creative, recommendations) that a human reviews and approves. We do not use customer data to train third-party models.
  • The connected platforms themselves (Amazon, Shopify, Google, Meta, Klaviyo) as data sources.

Security

Data is hosted in the EU. Access tokens and API credentials are stored encrypted in a dedicated secret vault, never in plain application tables. Access is role-based and scoped per organization. Material changes that affect a live store or account are gated behind explicit human approval.

Data retention

We retain connected-platform data only as long as needed for the agreed services, and operational logs for a limited period for security and audit purposes. On disconnection or account closure we delete stored tokens and purge associated data — see our Data Deletion page.

International transfers

Where a provider processes data outside the EU/EEA, we rely on appropriate safeguards (e.g. EU Standard Contractual Clauses).

Your rights

Subject to applicable law, individuals may request access, rectification, erasure, restriction, portability, or object to processing. Requests: privacy@fischer-habel.com. You may also lodge a complaint with a supervisory authority.

Changes

We may update this policy; the "last updated" date reflects the latest version.

This document is provided for transparency and platform-review purposes and does not constitute legal advice.