Privacy Policy
Effective from: 24 June 2026
Last updated: 19 July 2026
This Privacy Policy explains how SUBVENTUM s.r.o. processes personal data in connection with the ProfitEcom website, the ProfitEcom application and related services.
ProfitEcom is an analytics and reporting platform for e-commerce businesses, companies and entrepreneurs. The service connects data from marketing platforms, e-commerce platforms, ERP, PIM, CRM and other customer systems and helps evaluate business performance, marketing efficiency, orders, products, margins, returns and other business metrics.
This Privacy Policy applies in particular to:
- visitors of profitecom.com,
- persons who contact us through a form or by e-mail,
- users of app.profitecom.com,
- customers and their representatives,
- personal data processed as part of customer implementations, if such data is provided, uploaded or connected by the customer.
The ProfitEcom service is intended exclusively for businesses and entrepreneurs. It is not intended for consumers or children.
1. Who controls the data
The operator of the ProfitEcom service is:
SUBVENTUM s.r.o.
Kaprova 42/14
110 00 Prague 1
Czech Republic
Company ID: 08239771
VAT ID: CZ08239771
General contact: hello@profitecom.com
Privacy contact: privacy@profitecom.com
Security contact: security@profitecom.com
In some cases, SUBVENTUM s.r.o. acts as the data controller. This typically applies to data of website visitors, contact form submissions, business communication, user accounts, application login, billing, customer relationship management and service security.
In other cases, SUBVENTUM s.r.o. acts as a data processor. This typically applies to customer data that the customer uploads, connects or makes available to ProfitEcom through its systems and integrations. In such cases, the customer is the data controller and ProfitEcom processes the data according to the customer’s instructions, the applicable contract and the data processing agreement.
2. What data we process
The scope of processed data depends on how you use the website, the application or a specific customer implementation.
2.1 Website visitor data
When you visit our website, we may process in particular:
- IP address,
- information about your device, browser and operating system,
- approximate information about your visit,
- pages you visit,
- time of visit,
- technical logs,
- cookies and similar technologies according to your consent settings.
Details about cookies are provided in the Cookie Policy.
Based on your consent, we may also use third-party measurement, advertising and business technologies on the website, such as Sklik and Saleskit/Merk. These tools may help with measuring website traffic, evaluating advertising campaigns, measuring conversions, retargeting or identifying corporate visitors to the website.
The Saleskit/Merk tool operated by Imper CZ s.r.o. may, based on available data and the Merk database, help identify the company from which a visitor comes to the website. The result may be stored in the Saleskit/Merk environment and may in the future be forwarded to our Raynet CRM system as a business lead, if this function is enabled and if there is an appropriate legal basis or consent.
2.2 Contact form data
If you contact us through a website form, we process the information you provide to us, in particular:
- first name,
- surname,
- e-mail address,
- phone number,
- company name,
- message content.
We use this data to handle your inquiry, communicate with you and manage the business relationship. The form is technically processed through an integration layer and may subsequently be forwarded to our internal e-mail communication and the Raynet CRM system.
If the contact does not become a customer, we may retain business lead data for up to 24 months from the last relevant communication, unless you request earlier deletion or unless we have another legal reason for further retention.
2.3 Application user data
When you use the ProfitEcom application, we process in particular:
- e-mail address,
- first name and surname,
- phone number,
- language preference,
- user role,
- link to a customer account or tenant,
- company details,
- login information,
- technical and security logs,
- account settings and permissions.
Login to the application is provided through Auth0. Users may log in using e-mail and password, Google login or Microsoft Enterprise login.
Google and Microsoft login are used only to verify the user’s identity and to log the user into the application. We do not use them to access the user’s e-mail inbox, documents, files or other data in Google Workspace or Microsoft 365.
2.4 Billing and payment data
For contractual, billing and payment purposes, we may process in particular:
- customer identification and contact details,
- billing details,
- VAT ID, Company ID and registered office,
- information about the purchased plan,
- subscription status,
- payment and billing metadata.
Payments and subscriptions may be processed through Stripe. Payment cards and payment methods are processed in the Stripe environment. ProfitEcom does not store payment card numbers.
2.5 Data from connected integrations
ProfitEcom allows the customer to connect external systems and data sources. Depending on the specific implementation, these may include:
- marketing platforms,
- e-commerce platforms,
- ERP systems,
- PIM systems,
- CRM systems,
- logistics and warehouse systems,
- spreadsheets and auxiliary data files,
- other customer systems according to the implementation analysis.
The data stored and processed varies depending on the specific customer, its systems and the agreed scope of implementation.
By default, ProfitEcom works mainly with business and economic data, for example:
- orders,
- order items,
- products,
- categories,
- brands,
- suppliers,
- inventory,
- returns,
- costs,
- margins,
- marketing campaigns,
- performance metrics,
- sales channels,
- countries,
- payment and shipping methods.
The standard ProfitEcom data model does not require names, e-mail addresses, postal addresses or phone numbers of end customers of an e-commerce store. If it is necessary to track repeat purchases or customer behaviour in an aggregated form, a pseudonymized customer identifier is used, such as a hash of the original identifier.
For custom reports and individual implementations, the scope of processed data may be broader. Such processing is always based on an implementation analysis, the contract, the data scope approved by the customer and, where applicable, a data processing agreement.
The customer should not provide ProfitEcom with special categories of personal data, health data, political opinions, religious beliefs, criminal offence data, national identification numbers, children’s data or other sensitive data unless this has been expressly agreed in writing.
3. Google login, Google Ads API and Google Analytics API
ProfitEcom uses Google in three different situations.
3.1 Login using a Google account
A user may log in to the ProfitEcom application using a Google account through Auth0. In such case, we process only the data necessary to verify the user’s identity and to create or manage the user account, typically the e-mail address, user identifier and basic profile data provided as part of the login process.
This login is not used to access Gmail, Google Drive, Google Sheets, Google Calendar or any other Google Workspace data.
3.2 Connecting a Google Ads account
A customer may connect its Google Ads account in the application. The connection is performed through Google OAuth authorization. ProfitEcom does not receive or store the customer’s Google account password.
For Google Ads, we use the following permission: https://www.googleapis.com/auth/adwords
We use this permission only to read data from Google Ads accounts authorized by the customer. ProfitEcom does not write any changes to Google Ads accounts, does not create campaigns, does not modify budgets, does not edit ads, does not change account settings and does not perform any campaign management.
From the Google Ads API, we may process in particular:
- advertising account IDs and names,
- campaign IDs and names,
- ad groups,
- ads and their identifiers,
- costs,
- impressions,
- clicks,
- conversions,
- performance metrics,
- segments and dimensions available in Google Ads reporting,
- other data necessary for marketing reporting and e-commerce economics calculations.
We use this data exclusively to provide the ProfitEcom service, in particular for reporting, marketing analytics, profitability calculations and connecting marketing costs with the customer’s business data.
Google Ads data:
- is not sold,
- is not provided to data brokers,
- is not used for our own advertising targeting outside the provision of the ProfitEcom service,
- is not used for retargeting for our own purposes,
- is not used to train general AI or ML models,
- is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.
3.3 Connecting a Google Analytics account
A customer may connect its Google Analytics account or Google Analytics property in the application. The connection is performed through Google OAuth authorization. ProfitEcom does not receive or store the customer’s Google account password.
For Google Analytics, we use the following permission: https://www.googleapis.com/auth/analytics.readonly
We use this permission only to read data from Google Analytics accounts and properties authorized by the customer. ProfitEcom does not write any changes to Google Analytics accounts, does not modify property settings, does not create or change data streams, events, conversions, audiences or any other Google Analytics settings.
From the Google Analytics API, we may process in particular:
account IDs and names,
property IDs and names,
basic property settings, such as currency and time zone,
traffic data,
traffic sources,
campaigns,
session sources and media,
device data,
geographic data,
landing pages,
page views,
events,
conversions,
e-commerce metrics,
dimensions and metrics available in Google Analytics reporting,
other aggregated reporting data necessary for website analytics and e-commerce performance evaluation.
We use this data exclusively to provide the ProfitEcom service, in particular for reporting, marketing analytics, website traffic analysis, conversion evaluation and connecting marketing, website and business data of the customer.
Google Analytics data:
is not sold,
is not provided to data brokers,
is not used for our own advertising targeting outside the provision of the ProfitEcom service,
is not used for retargeting for our own purposes,
is not used to train general AI or ML models,
is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.
3.4 Security and disconnection of Google integrations
Authorization tokens obtained through Google OAuth are stored in a secured backend infrastructure. Long-term tokens are stored in encrypted form. Tokens are not displayed to users in the application, are not stored in analytical tables in Fabric and are not used for any purpose other than authorized retrieval of data from connected accounts.
When the Google Ads or Google Analytics integration is disconnected, we remove the stored authorization credentials and also call the Google endpoint to revoke the authorization.
4. Meta Marketing API
A customer may connect its Meta advertising accounts in the application. The connection is performed through authorization in the Meta/Facebook environment.
ProfitEcom uses the Meta Marketing API only to read advertising and performance data from accounts authorized by the customer. ProfitEcom does not create, edit, pause, delete or manage campaigns, ad sets, ads, budgets, audiences or pixels.
From the Meta Marketing API, we may process in particular:
- advertising account IDs and names,
- campaigns,
- ad sets,
- ads,
- costs,
- impressions,
- clicks,
- conversions,
- performance metrics,
- other aggregated reporting data available in the Meta Marketing API.
The technical configuration of the Meta integration may require permissions related to access to advertising accounts and business assets. We use these permissions only to allow the customer to authorize selected advertising accounts and to enable ProfitEcom to read data required for reporting. We do not use them for active management of advertising accounts.
Meta data:
- is not sold,
- is not provided to data brokers,
- is not used for our own advertising targeting outside the provision of the ProfitEcom service,
- is not used to train general AI or ML models,
- is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.
When the Meta integration is disconnected, we remove the stored authorization credentials and call the mechanism for removing the application’s permissions. ProfitEcom also has endpoints prepared for deauthorization and data deletion requests in accordance with Meta requirements.
Details about disconnecting integrations and data deletion requests are provided on the Data Deletion page.
5. Why we process data
We process personal data mainly for the following purposes:
| Purpose of processing | Examples of data | Legal basis |
|---|---|---|
| Website operation | technical data, essential cookies | legitimate interest |
| Processing contact form submissions | name, last name, email, phone, company, message | contract negotiation, legitimate interest |
| Customer account management | email, role, company, tenant, language, phone | contract fulfillment |
| Login and security | authentication data, logs, roles, permissions | contract performance, legitimate interest |
| Provision of the ProfitEcom Service | customer data, marketing data, business data | contract performance |
| Processing Customer Data as a Processor | data provided or connected by the customer | data processing agreement |
| Connecting Google Ads, Google Analytics and Meta accounts | advertising accounts, Google Analytics accounts and properties, campaigns, website traffic, conversions, metrics, OAuth tokens | contract performance, customer authorization |
| Invoicing and Accounting | billing information, payment metadata | contract performance, legal obligation |
| Website Analytics and Marketing Measurement | cookies, online identifiers, traffic, conversions | consent |
| Protection of Rights and Security | logs, audit data, communication | legitimate interest, legal obligation |
| Provider / Technology | Purpose |
|---|---|
| Auth0 / Okta | User authentication, login, identity management |
| Microsoft Azure / Microsoft Fabric / Power BI | Data platform, analytics, reporting |
| Microsoft 365 | Email and internal communication |
| Xano | Backend, API, database, and integration layer |
| Hetzner | Server hosting for the self-hosted n8n integration layer |
| Webflow | marketing website operation |
| Cookiebot / Usercentrics | cookie and consent management |
| Mandrill / Mailchimp Transactional Email | transactional emails from Auth0, such as security codes and password reset |
| Stripe | payments, subscriptions, and billing processes |
| Raynet | CRM tracking of sales leads from web forms |
| login, Google Ads API, Google Analytics API, web analytics and ad measurement based on consent | |
| Meta | Meta Marketing API and ad measurement based on consent |
| Microsoft Advertising | ad measurement based on consent |
| Sklik | website traffic measurement, conversion measurement, advertising campaign measurement and retargeting based on consent |
| Saleskit / Merk / Imper CZ s.r.o. | identification of corporate visitors to the website, B2B marketing, business leads and possible forwarding to CRM according to consent and settings |
| ad measurement based on consent, if deployed | |
| Smartsupp | website chat communication, if deployed |
| Type of data | Retention period |
|---|---|
| Contact form data | up to 24 months from the last relevant communication, unless the contact becomes a customer |
| Customer account data | for the duration of the contractual relationship and a reasonable period after its termination |
| Customer data in the application | for the duration of the service, unless the customer requests earlier deletion |
| Data from Google Ads, Google Analytics and Meta integrations | for the duration of service use, or until data is deleted upon customer request |
| OAuth tokens | for the duration of active integration; upon disconnection, they are removed and, where possible by the platform, revoked |
| Billing and accounting data | as required by law |
| Technical logs and integration execution data | for a limited technical period, typically ranging from days to weeks |
| Backups and technical copies | according to backup cycles and provider standards, usually for a limited period; ideally no longer than 90 days, unless a longer period is required by the provider's technical settings or legal obligations |