Privacy Policy — Beyonders
Summary
Beyonders is a profit dashboard and autopilot for e-commerce advertisers. We only collect what is needed to provide the service: your account details, the integrations you authorize yourself, and the advertising/order data that flows from them. We do not sell data and we do not use advertising tracking of any kind.
What data do we process?
- Account: username, email address and an encrypted password hash (scrypt). We never store your password in readable form.
- Integrations you authorize: Facebook (Meta) access token, Shopify access token and optionally an Anthropic API key. These are used exclusively to fetch your advertising and store data and to perform the actions you configure.
- Derived data: ad statistics, orders, profit calculations, your automation rules and the autopilot's action history.
- Payments: handled by Stripe. We never see or store your card details; we only keep your Stripe customer reference and subscription status.
In the iOS app, locally on your device
- Your session token (and optionally a custom server URL) — encrypted in the iOS Keychain.
- Photo library: an image is only uploaded after you explicitly select it (for ads via Facebook Ads). The app never reads your photos on its own.
- Push notifications: only if you enable them; used for autopilot alerts (rules, fatigue alerts, daily reports). Logging out unregisters your device.
What we don't do
- No analytics SDKs, no advertising identifiers, no tracking of you as a person.
- No selling or renting of data to third parties.
- No access to location, contacts or other personal data on your device.
Processors (third parties)
To provide the service, our servers communicate with: Meta (Graph API, your advertising data), Shopify (your store data), Stripe (payments), Anthropic (the "Beyond" AI features — only the product info/metrics needed for your request) and optionally Google (image generation). Each of these parties processes data under their own privacy terms.
Retention and deletion
- You can delete your account completely at any time via Settings → Delete account (in the app and on the web). This immediately erases your account details, API tokens, rules, logs and push registrations from our servers. This is permanent.
- Logging out removes the session token from your device and unregisters push notifications; deleting the app erases all Keychain items.
Security
All traffic runs over HTTPS. Passwords are hashed with scrypt. API tokens are used only for the purposes above and are never visible to other users.
Legal basis for processing
We process your personal data on the basis of performance of a contract (GDPR Art. 6(1)(b)): the data described above is necessary to deliver the Service you sign up for — connecting the advertising and store accounts you authorize, calculating your profit, and running the automation you configure.
Your rights (GDPR)
If you are in the EU/EEA, you have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — have inaccurate or incomplete data corrected.
- Erasure — have your data deleted (you can also do this yourself at any time via Settings → Delete account).
- Objection — object to our processing of your personal data.
You can exercise any of these rights by emailing privacy@beyonders.store.
Contact
Questions or requests (access, rectification, erasure, objection)? Email privacy@beyonders.store.