This policy describes what data we process, why, and the rights you have. SHORA acts as data controller for the processing described below, within the meaning of the EU General Data Protection Regulation (GDPR).
a. Google Ads data (clients only). When an advertiser explicitly grants us access through Google's OAuth consent screen, we retrieve, read-only, campaign structure data and per-URL performance reports (landing page URLs, dates, hours, impressions, clicks, cost) from that advertiser's Google Ads account via the Google Ads API. We never create, modify, or delete anything in the advertiser's account, and we never access any account that has not explicitly authorized us. Revoking access in the Google account settings stops all retrieval immediately.
b. Website measurement data. Our service executes purchase journeys on publicly accessible pages of e-commerce websites to verify whether advertised products can actually be purchased. This produces technical records (timestamps, page states, network traces, console logs, performance measurements). This data concerns websites, not individuals, and is collected without cookies, forms, or any interaction with personal accounts.
c. Contact and contract data. Names, professional email addresses, phone numbers, and billing details of prospects and clients, used to communicate, deliver the service, and invoice.
Client data is isolated per client. It is never shared across clients, never aggregated into cross-client products, never sold, and never transferred to third parties, except technical processors strictly necessary to operate the service (hosting provider) bound by confidentiality and located in the European Union. No data is transferred outside the European Union.
Google Ads data and measurement data are retained for the duration of the service and applicable legal obligations, then deleted. Any client may request earlier deletion at any time by writing to jl@shora.ai; deletion is confirmed in writing. Contact and contract data are retained for the duration of the commercial relationship plus statutory limitation periods.
Credentials and tokens are stored encrypted. Access to client data is restricted to the founder. All transport uses TLS.
Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection regarding your personal data. To exercise them, write to jl@shora.ai. You also have the right to lodge a complaint with the CNIL (cnil.fr).
This website does not use tracking or advertising cookies.
We may update this policy; the current version is always published at this URL with its version number and effective date.