Privacy policy
Effective from: 2026-10-15 · Version 2.0 (replaces the version of 2026-04-17)
1. Who we are and what this policy covers
BBOLD online, UAB (BBOLD, we, us) is a Shopify agency that builds, migrates and maintains online stores. This privacy policy explains how we process personal data in four areas:
- A. The bbold.online website and communication with us (section 2);
- B. The AI readiness audit tool at >audit.bbold.online (section 3);
- C. The "BBOLD Connector" Shopify app – >apps.shopify.com/bbold-connector (section 4);
- D. Agency services – our work on clients' Shopify stores (section 5).
In areas A and B, BBOLD is the data controller. In areas C and D, the store owner is the controller of their customers' data, and BBOLD acts as a data processor – we process the data only on the store owner's behalf and according to their instructions.
Data controller: BBOLD online, UAB, company code 305719974, Ateities g. 10, Vilnius, 08345, Lithuania, email hello@bbold.online.
2. The bbold.online website and communication with us
2.1. What data we process
- Enquiries and correspondence: name, email address, phone number (if you provide it), company name, store address and the content of your message – when you contact us via the contact form, by email or through other channels.
- Client and partner data: names, job titles and contact details of contact persons, and contract, invoice and payment data.
- Newsletter: email address and consent details, if you have subscribed to our news.
- Cookies: the website runs on the Shopify platform. Essential cookies are used to operate the website; analytics and marketing cookies are used only if you consent via the cookie banner. You can change your consent at any time.
2.2. Purposes and legal bases
- to answer your enquiries and prepare a proposal at your request (GDPR Art. 6(1)(b));
- to perform contracts with clients and partners (GDPR Art. 6(1)(b));
- to keep accounting records and meet other legal obligations (GDPR Art. 6(1)(c));
- to send newsletters – only with your consent (GDPR Art. 6(1)(a));
- to keep the website running and secure (GDPR Art. 6(1)(f)).
2.3. Retention
We keep enquiry and correspondence data for no longer than 24 months after our last communication, unless you become a client. Contracts and accounting documents are kept for the period required by law (accounting documents – usually 10 years). Newsletter data is kept until you withdraw your consent.
3. AI readiness audit tool (audit.bbold.online)
>audit.bbold.online is a free tool that assesses how ready an online store is for AI search and AI agents.
3.1. Scanning a store
We process the store address (URL) you enter, the scan results, the scan time and the IP address of the device that submitted the request. We use the IP address to limit the number of requests and prevent abuse.
During a scan we visit only publicly available pages and files of the store (for example the home page, a few product and collection pages, robots.txt, sitemap.xml, llms.txt) – the same way any visitor or search crawler sees them. Requests are sent with the identifier "BBOLD-AI-Audit-Bot"; the home page is additionally requested with AI crawler identifiers (GPTBot, ClaudeBot) marked with a link to bbold.online, to check whether such crawlers are blocked. We do not log in to accounts, place orders or collect non-public data.
A short summary of the results may be generated with the Google Gemini API. We send it only the store domain, the score and the technical check results – no names, email addresses or other personal data of yours. Under Google's terms, requests from EU users are not used to improve Google's products.
3.2. Unlocking the full report
To unlock the full report, you provide:
- your email address and name (the name is optional);
- your acceptance of the >terms of service and this policy – as proof of consent we store the date and time, IP address, browser identifier and policy version;
- a separate, optional consent to receive AI readiness tips and news.
When you unlock a report, your contact is created or updated in the customer list of the bbold.online Shopify store together with the audit details: the scanned store address, score, score band, report link and date. Marketing consent is recorded only if you gave it.
The report is available via a unique link – anyone who has the link can open it, so share it with care.
3.3. Purposes and legal bases
- to run the scan and deliver the report at your request (GDPR Art. 6(1)(b));
- to protect the tool against abuse (GDPR Art. 6(1)(f));
- to contact you about your audit results – to explain them or answer your questions; for this we group contacts by audit result (GDPR Art. 6(1)(f));
- to send AI readiness tips and news – only with your consent (GDPR Art. 6(1)(a)). You can withdraw it at any time via the unsubscribe link in any email or by writing to us;
- to keep proof of consent (GDPR Art. 6(1)(c) and (f)).
3.4. Where and how long we store data
Audit tool data is stored in the EU: servers – Render (Frankfurt, Germany); database – MongoDB Atlas (AWS, Frankfurt, Germany). Contacts are also stored in the bbold.online Shopify store (see section 7). We keep scan reports and contact data for 24 months after your last activity, unless you become a client or ask us to delete them sooner.
3.5. Public list of recent scans
The tool's start page shows a list of recently scanned stores: domain, score and rating band. This is only the result of assessing publicly available information; names, email addresses or other personal data are never shown publicly. If you do not want your domain to appear on the list, write to hello@bbold.online and we will remove it.
3.6. Automated assessment
The score is calculated automatically against predefined technical criteria (e.g. robots.txt, structured data, content accessibility). The assessment is for information only and has no legal or similarly significant effects on you.
4. The "BBOLD Connector" Shopify app
>BBOLD Connector automatically transfers Shopify orders and refunds to the RoboLabs accounting system. This section applies to stores that have installed the app (the App) and to their customers.
4.1. Roles
The store owner (the Merchant) is the controller of their customers' data; BBOLD acts as a data processor and transfers the data to RoboLabs on the Merchant's instructions. For the Merchant's account and billing data, BBOLD is the data controller.
4.2. What data we process
- Order data (Shopify → RoboLabs): order number, date, status and currency; line items (names, quantities, prices, taxes, discounts, total); shipping and payment method (without card details); refund information used to create a credit note in RoboLabs; invoice data.
- Customer data (Shopify → RoboLabs): first and last name, email address, phone number (if provided), shipping and billing addresses, company name and VAT number (if the customer is a business).
- Other order record data: technical data contained in the Shopify order record, such as the customer's IP address and browser information. It is stored as part of the sync record.
- Merchant data: store domain; name, email address and language of the person who installs or uses the App (received from Shopify); the selected plan and subscription status. Payments for the App are handled by Shopify – we do not receive payment card details.
- Technical data: API access tokens, RoboLabs integration settings, sync statuses and error logs.
The App does not process payment card numbers, passwords or special categories of personal data. The App does not sync the product catalogue from RoboLabs to Shopify – product information is transferred only as part of order lines.
4.3. Purposes and legal bases
- operating the App and performing the contract with the Merchant (GDPR Art. 6(1)(b));
- meeting the Merchant's tax and accounting obligations in RoboLabs (GDPR Art. 6(1)(c));
- service security, error monitoring, retrying failed transfers and supporting the Merchant (GDPR Art. 6(1)(f)).
4.4. Retention and deletion
Each synced order and refund is saved as a sync record (together with the order and customer data transferred), so that the Merchant can see the transfer history, failed transfers can be retried and duplicate entries in RoboLabs are avoided. These records and technical logs are kept for no longer than 12 months after the sync and are then deleted automatically.
When the App is uninstalled from a store, the related sync records are deleted within 30 days at the latest, and API access tokens are revoked immediately. When we receive Shopify's mandatory privacy requests (customer data request or deletion, shop data deletion), we respond to them and delete the relevant data.
Order and customer data remains stored in Shopify and RoboLabs according to those providers' terms and the retention periods set by the Merchant.
4.5. Recipients and storage location
- RoboLabs – the accounting system that receives order and customer data. On its own platform, RoboLabs acts as a separate controller or as the Merchant's processor.
- Shopify – the platform on which the store runs and through which the App is installed and paid for.
- Infrastructure providers – Render, Amazon Web Services and MongoDB Atlas. The App's servers and database are located in the EU (Frankfurt, Germany). These providers may not use the data for their own purposes.
5. Agency services: working on clients' stores
5.1. Our role
When we build, migrate, improve or maintain a client's Shopify store, we get access to its data – products, orders and the personal data of the store's customers. The client (the store owner) is the controller of this data. BBOLD acts as a data processor and processes the data only according to the client's instructions and only within the scope of the agreed work.
5.2. Access to the store
We usually get access through a Shopify collaborator or staff account. The store owner sets the scope of access and can revoke it at any time. We ask only for the permissions needed for the agreed work. When our cooperation ends, you can revoke access yourself or ask us to give it up.
5.3. What we do with the data
We use the data only for the assigned work: building and configuring the store, data migration and import (e.g. from another platform), integrations, troubleshooting, reports and other work ordered by the client. Access is limited to BBOLD team members who need it for their work, and all of them are bound by confidentiality. We do not use client data for our own purposes.
We install third-party apps in a client's store only after agreeing it with the client. Those app providers process data under their own terms and the agreements the client has with them.
5.4. Data processing terms (DPA)
Data processing terms under Article 28 GDPR are set out in the service agreement or in a separate Data Processing Agreement (DPA). If your agreement does not contain such terms, this section sets out our commitments, and we will provide a DPA on request.
5.5. Artificial intelligence tools
We use artificial intelligence tools (e.g. Anthropic Claude, OpenAI ChatGPT) in our work – to analyse data files, prepare import files and write code. When we do:
- we use only business accounts or APIs (e.g. Claude Team / Enterprise, Anthropic API, ChatGPT Business / Enterprise, OpenAI API) whose terms provide that the data we submit is not used to train AI models;
- we share with AI tools only the data needed for the specific task, and where possible we remove or pseudonymise customers' personal data;
- AI providers act as our sub-processors under their commercial terms and data processing agreements – they may not use the data for their own purposes;
- we do not sell client data or share it with AI providers or other third parties for their own purposes.
If you do not want AI tools, or a specific AI provider, to be used on your project, let us know and we will adjust how we work.
5.6. Retention and deletion
We keep working copies of data (e.g. export or import files) only as long as they are needed for the work. When the work or the contract ends, we delete copies of the client's store data or return them to the client, unless the law requires us to keep them longer.
6. Who we share data with
We do not sell or rent personal data, and we do not share it with third parties for their own marketing. Data may be processed by the following recipients, only to the extent needed for the purposes described in this policy:
- Shopify – the platform for the bbold.online website, our clients' stores and BBOLD Connector (>Shopify privacy policy);
- RoboLabs – the accounting system to which BBOLD Connector transfers order data;
- infrastructure providers – Render, Amazon Web Services, MongoDB Atlas;
- AI service providers – Anthropic, OpenAI, Google (Gemini API);
- work and communication tools – e.g. Google Workspace (email, documents), Slack, Productive (project management and invoicing);
- subcontractors (e.g. developers), where engaged on a project – only within the project scope and bound by confidentiality;
- accounting, legal and other professional service providers – when needed;
- public authorities – only when required by law.
Clients can request a full list of our sub-processors at any time.
7. Transfers outside the EEA
Our own servers (for the audit tool and BBOLD Connector) are located in the EU. Some providers (e.g. Shopify, Anthropic, OpenAI, Google, Slack) may process data outside the European Economic Area (EEA), for example in Canada or the United States. Such transfers rely on European Commission adequacy decisions (including the EU-U.S. Data Privacy Framework) or on Standard Contractual Clauses.
8. Security
We apply technical and organisational security measures: encrypted data transfer (HTTPS/TLS), access control (access for authorised persons only, two-factor authentication), restricted access to API keys, monitoring of technical logs, backup management and regular reviews of access rights. If we become aware of a security incident affecting a client's data, we notify the client without undue delay.
9. Your rights
You have the right to:
- access your data and receive a copy of it;
- have inaccurate data corrected;
- have your data erased;
- restrict the processing of your data;
- object to processing based on legitimate interest;
- receive your data in a portable format;
- withdraw your consent at any time – this does not affect the lawfulness of processing before the withdrawal;
- lodge a complaint with the State Data Protection Inspectorate of Lithuania (L. Sapiegos g. 17, Vilnius, >vdai.lrv.lt).
Send your requests to hello@bbold.online. We respond within 30 days. If the controller of your data is a store owner (sections 4 and 5), we will forward your request to them and help them fulfil it.
10. Changes to this policy
We publish the updated policy on this page. We announce material changes at least 14 days before they take effect – on the website, and by email to BBOLD Connector users and agency clients.
11. Contact
For any questions about personal data, contact:
BBOLD online, UAB
Company code: 305719974
Ateities g. 10, Vilnius, 08345, Lithuania
Email: hello@bbold.online
BBOLD Connector questions: apps@bbold.online