Privacy Policy
Last updated: 20 July 2026
1. Who we are
CuanCo ("we", "us", "our") provides an ecommerce finance workspace at cuanco.ie. This policy explains how we handle information when merchants use CuanCo and when they connect third-party services such as Shopify, Xero, Meta, and Google Analytics.
Contact: support@cuanco.ie
2. Scope
This policy covers:
- Account and authentication data for CuanCo users
- Company and configuration data stored in CuanCo
- Operational data synced from connected platforms (for example Shopify orders and inventory, Xero accounting data, Meta ads spend, Google Analytics channel metrics)
- Technical logs needed to run and secure the service
3. Information we collect
3.1 Account information
When you create or are invited to a CuanCo account we process email address, name (if provided), authentication credentials or OAuth identifiers, role, and which companies you can access.
3.2 Merchant business data
For each company workspace we store settings you configure (for example assumptions, Coupler URLs where still used, and integration connection status).
3.3 Connected platform data
When you connect a platform, we receive and store the data needed for finance reporting. Depending on which integrations you enable, this may include:
- Shopify: orders, line items, refunds, inventory levels, and related identifiers. We request the minimum access required for reporting. We do not use Shopify data for customer marketing or advertising.
- Xero: bank transactions, chart of accounts, and accounting reports you authorise.
- Meta: advertising performance metrics such as spend and conversions for connected ad accounts.
- Google Analytics (GA4): aggregated channel and session metrics for connected properties.
3.4 Technical data
We may process IP address, browser/user-agent, timestamps, and application logs for security, debugging, and reliability.
4. How we use information
We use information to:
- Provide and operate the CuanCo product for authorised users
- Sync and display finance, inventory, and marketing performance reporting
- Authenticate users and enforce company access controls
- Maintain security, prevent abuse, and troubleshoot issues
- Communicate about the service (for example support and important notices)
- Comply with legal obligations
We process personal data only as needed to deliver these purposes. We do not sell personal data. We do not use connected Shopify customer data for marketing or advertising on our own behalf.
5. Legal bases (EEA/UK)
Where GDPR/UK GDPR applies, we typically rely on:
- Contract: to provide the service you signed up for
- Legitimate interests: to secure, improve, and support the service in ways that do not override your rights
- Legal obligation: where we must retain or disclose information by law
- Consent: where required (for example certain optional cookies or marketing communications)
When we process store customer data on behalf of a merchant through a connected app (for example Shopify), we act as a processor/service provider for that merchant, and the merchant is the controller of their customer data.
6. Sharing
We share information only with:
- Infrastructure providers that host or power the service (for example database, hosting, and email delivery providers)
- Connected platforms you authorise (Shopify, Xero, Meta, Google) to complete OAuth and API syncs
- Professional advisers or authorities when required by law or to protect rights and safety
We do not sell or rent personal data to third parties.
7. Retention
We retain account and synced operational data for as long as the company workspace remains active and as needed to provide the service. When an integration is disconnected, we stop new syncs for that source. When a company or account is deleted, we delete or anonymise associated data within a reasonable period, except where we must keep records for legal, security, or dispute-resolution purposes. Application logs are kept for a limited operational window.
8. Security
We use industry-standard measures including encryption in transit (HTTPS), access controls, and encrypted storage provided by our infrastructure partners. No method of transmission or storage is completely secure; please use strong passwords and limit access to authorised staff.
9. International transfers
Our providers may process data in the EU, UK, US, or other countries. Where required, we use appropriate safeguards such as standard contractual clauses or equivalent mechanisms offered by those providers.
10. Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data, and to object or request portability. Merchants' end-customers should normally contact the merchant (the store) for requests about store customer data. CuanCo users can contact us at support@cuanco.ie. You may also lodge a complaint with your local data protection authority.
11. Children
CuanCo is a business service and is not directed at children. We do not knowingly collect personal data from children.
12. Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top will change when we do. Material changes may also be communicated in-product or by email where appropriate.
13. Contact
Questions about this policy: support@cuanco.ie
This page is provided for transparency. It is not legal advice. Consider having counsel review it before relying on it for App Store or regulatory submissions.