Legal

Privacy Policy

Last updated: October 3, 2026. This policy explains what personal data we process when you use SpotPeaks, why, and the rights you have under the GDPR.

Who is responsible

The data controller is SpotPeaks v/Nicolas van Arkens, a sole proprietorship registered in Denmark (CVR 40494537), Ringstedgade 7, st. th, 2100 København Ø, Denmark. Contact: hello@spotpeaks.com. For anything in this policy, including exercising your rights, that address is the way to reach us.

What we collect and why

Account data. When you create an account we process your email address, a hashed password, and the name you optionally provide. Legal basis: performance of our contract with you. Without this we cannot provide the service.

Product data you create. Your launches, saved products, settings, and store connection details (for example a Shopify token you add) are processed to provide the features you use. Legal basis: contract. Store credentials are used only to perform the actions you trigger, such as pushing a product you created.

Billing data. Payments are processed by Stripe. We receive your subscription status and invoice-level information, but we never see or store your full card number. Legal basis: contract and our legal obligations (bookkeeping and tax rules require us to keep transaction records). Stripe acts as its own controller for parts of payment processing; see Stripe’s privacy policy.

Usage analytics. We use first-party, cookieless page analytics (an anonymous events table we run ourselves) and Vercel Web Analytics, which is also cookieless and does not track you across sites. We use this to understand which pages are used and to improve the product. Legal basis: legitimate interest in understanding and improving our own service.

Your activity while signed in. When you are signed in we keep a record of your own use of SpotPeaks: the pages you open, the products you look at and save, the launches you build, the verdicts and diagnostics you run, and the messages you exchange with the built-in AI copilot along with our replies. We use this to support you, to see where the product is confusing or wrong, and to fix it. It is never used for advertising and it is never shared or sold. It is deleted when you delete your account. Legal basis: legitimate interest in supporting and improving a service you are signed in to.

Session replay. If enabled, we use Microsoft Clarity to record anonymised replays of site sessions so we can see where the interface causes trouble. Clarity masks text input by default and sets its own first-party cookies. It never runs on our internal admin pages. You can opt out of Clarity in your browser’s settings, and it is disabled entirely when we are not actively running a usability review.

Newsletter. If you subscribe to the weekly email, we process your email address to send it. Legal basis: consent, which you can withdraw at any time with the unsubscribe link in every email or by writing to us.

Feedback and support. If you send feedback through the in-app widget or email us, we process what you write, the page it was sent from, and your email if you include it, in order to respond and improve the product. Legal basis: legitimate interest.

AI features. When you use AI features (for example the validation verdict or launch kit), the inputs needed for that feature are sent to our AI provider, Anthropic, to generate the result. We do not send more than the feature needs. Legal basis: contract.

Local storage on your device

SpotPeaks stores functional data in your browser’s local storage: your theme choice, recently viewed products and drafts of your launches. While you are signed in, the authentication session that keeps you logged in is stored in a first-party cookie on this domain, which is strictly necessary for the site to work at all. This stays on your device, is not used for advertising, and is not shared with third parties. We do not use advertising cookies or cross-site tracking, and we do no cross-site profiling of any kind.

Who processes data for us

We use a small set of processors to run SpotPeaks: Supabase (database and authentication), Vercel (hosting and cookieless analytics), Stripe (payments), Anthropic (AI features), Cloudflare (DNS and media storage), and Zoho (email). Some of these providers are based in or process data in the United States; where that happens, transfers are covered by the EU-US Data Privacy Framework or EU standard contractual clauses. We do not sell personal data, and we do not share it with anyone for advertising.

How long we keep data

Account data is kept while your account exists and deleted or anonymized when you delete your account, except where the law requires longer retention (Danish bookkeeping rules require keeping transaction records for 5 years). Newsletter addresses are kept until you unsubscribe. Your signed-in activity record, including copilot conversations, is deleted with your account. Anonymous analytics events carry no identity to delete. Feedback is kept as long as it is useful for improving the product.

Your rights

Under the GDPR you can ask us for access to your data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interest. Where processing is based on consent, you can withdraw it at any time without affecting past processing. Write to hello@spotpeaks.com and we will respond within a month. You also have the right to complain to a supervisory authority; in Denmark that is Datatilsynet (datatilsynet.dk), or the authority in your own EU country.

Data about businesses from public sources

The product research features of SpotPeaks are built on information collected from public sources: public ad libraries, public storefronts, and public marketplace listings. This is overwhelmingly data about companies and products, but it can include personal data where a business trades under a personal name (for example an advertiser page named after its owner). We process it on the basis of legitimate interest, in a business context, exactly as it was already published. If you are identifiable in this data and want it removed, email hello@spotpeaks.com and we will handle it.

Writers and editors we contact

We sometimes email writers, editors and creators whose published articles or videos cover dropshipping, to offer our published statistics as a source. For this we process your name, your work email address, the publication and article we wrote to you about, and our messages to each other. We find these on the public pages where you publish or list your contact details. The legal basis is legitimate interest: offering a free, sourced figure to someone who writes about the subject.

We write to each person at most three times (one email and two short follow-ups) and do not add you to any mailing list. If you reply that you would rather not hear from us, we stop at once and keep only your email address on a do-not-contact list, so it does not happen again. Otherwise we delete these details within 12 months of our last message. You have the rights described above, including the right to object, and can use them by writing to hello@spotpeaks.com.

The Store X-Ray browser extension

The SpotPeaks Store X-Ray extension reads the page you are already viewing. When you open its panel on a store, it sends that store’s domain and its public product list (product titles and prices only) to SpotPeaks, so we can price that catalogue against published advertising benchmarks and show you the result. On a product page it also sends the title and price of the product you are looking at. This is the same public storefront data described above under “Data about businesses from public sources”.

Nothing is sent to SpotPeaks from a page where you do not open the panel. Signing in is optional: if you connect the extension to your SpotPeaks account (from the extension’s menu or our Connect Store X-Ray page), it keeps a sign-in token in its own storage and sends it with each lookup, so we can show what your plan includes. We keep only a scrambled copy of that token, tied to your account, and when it was last used; Disconnect in the extension’s menu retires it, and deleting your account removes it. Without signing in, the extension has no account and no identifier of any kind. There is one thing it does before you press anything: on a page carrying the markers of an online shop, it asks that site once for a single product from the shop’s own public feed, to work out whether the page is a shop at all and whether to offer you the button. That request goes to the site you are already on, never to us, carries no cookies, and its answer is not sent anywhere. It does not send or store your browsing history. Requests are rate limited by IP address for abuse protection and the store lookups are cached briefly; neither is used to build any profile of you. Your preferences, your imported supplier costs, the board of products you pin, and the snapshot the panel uses to tell you what changed on a store since your last visit are all kept in your own browser’s storage and never leave it. Removing the extension deletes them.

Three buttons in the panel send something further, and only when you press them. Share this X-ray saves the figures already on screen (the store’s hostname, the counts, the price range, the verdict) and gives you a link to a page on spotpeaks.com that anyone with the link can read. It carries no product names and nothing about you, so a shared X-ray cannot be traced back to whoever made it, but the store’s name is public on that page, so do not share one you would rather keep private. Tell us something is wrong opens a review page showing the address of the page you were on, the panel’s diagnostic and anything you type; nothing is transmitted until you press send on that page, and you can edit or delete any of it first. We keep those reports to fix the extension. Suggest this store sends the store’s domain so we can consider adding it to our index.

The SpotPeaks Shopify app

If you connect your Shopify store through the SpotPeaks app, we keep an access token for that store, encrypted, so SpotPeaks can add the products you choose as drafts and read your store’s orders. From those orders we keep only the order lines of products tied to one of your launches: which product, how many, the amount paid, refunds, whether the order was cancelled or a test, and when it was placed. We never read or keep a customer’s name, email address, phone number or address, and we use these lines only to show you what your launches really sold.

Order lines are deleted 18 months after the order was placed, when Shopify passes on a customer’s request to erase their data, and when Shopify asks us to erase your store’s data, which it does 48 hours after you uninstall the app. Requests from your store’s customers to see their data reach us through Shopify, and we answer each one within 30 days.

How we protect data

All traffic is encrypted in transit (TLS). Data is stored with our processors under access controls, and per-user data in our database is protected by row-level security, so one account can never read another’s rows. Card data is handled entirely by Stripe and never reaches our systems. We make no automated decisions with legal or similarly significant effects about you. If a personal data breach occurs that risks your rights, we will notify the supervisory authority and, where required, you, within the GDPR’s deadlines.

Children

SpotPeaks is a business tool and is not directed at children. You must be at least 18 to create an account, and we do not knowingly process children’s data.

Changes to this policy

If we change this policy in a material way, we will give notice in the app or by email before the change takes effect. The date at the top always shows the current version.

Contact

Privacy questions and rights requests: hello@spotpeaks.com. See also our Terms of Service.