Privacy Policy

Effective from: 24 June 2026

Last updated: 19 July 2026

This Privacy Policy explains how SUBVENTUM s.r.o. processes personal data in connection with the ProfitEcom website, the ProfitEcom application and related services.

ProfitEcom is an analytics and reporting platform for e-commerce businesses, companies and entrepreneurs. The service connects data from marketing platforms, e-commerce platforms, ERP, PIM, CRM and other customer systems and helps evaluate business performance, marketing efficiency, orders, products, margins, returns and other business metrics.

This Privacy Policy applies in particular to:

  • visitors of profitecom.com,
  • persons who contact us through a form or by e-mail,
  • users of app.profitecom.com,
  • customers and their representatives,
  • personal data processed as part of customer implementations, if such data is provided, uploaded or connected by the customer.

The ProfitEcom service is intended exclusively for businesses and entrepreneurs. It is not intended for consumers or children.

1. Who controls the data

The operator of the ProfitEcom service is:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771

General contact: hello@profitecom.com

Privacy contact: privacy@profitecom.com

Security contact: security@profitecom.com

In some cases, SUBVENTUM s.r.o. acts as the data controller. This typically applies to data of website visitors, contact form submissions, business communication, user accounts, application login, billing, customer relationship management and service security.

In other cases, SUBVENTUM s.r.o. acts as a data processor. This typically applies to customer data that the customer uploads, connects or makes available to ProfitEcom through its systems and integrations. In such cases, the customer is the data controller and ProfitEcom processes the data according to the customer’s instructions, the applicable contract and the data processing agreement.

2. What data we process

The scope of processed data depends on how you use the website, the application or a specific customer implementation.

2.1 Website visitor data

When you visit our website, we may process in particular:

  • IP address,
  • information about your device, browser and operating system,
  • approximate information about your visit,
  • pages you visit,
  • time of visit,
  • technical logs,
  • cookies and similar technologies according to your consent settings.

Details about cookies are provided in the Cookie Policy.

Based on your consent, we may also use third-party measurement, advertising and business technologies on the website, such as Sklik and Saleskit/Merk. These tools may help with measuring website traffic, evaluating advertising campaigns, measuring conversions, retargeting or identifying corporate visitors to the website.

The Saleskit/Merk tool operated by Imper CZ s.r.o. may, based on available data and the Merk database, help identify the company from which a visitor comes to the website. The result may be stored in the Saleskit/Merk environment and may in the future be forwarded to our Raynet CRM system as a business lead, if this function is enabled and if there is an appropriate legal basis or consent.

2.2 Contact form data

If you contact us through a website form, we process the information you provide to us, in particular:

  • first name,
  • surname,
  • e-mail address,
  • phone number,
  • company name,
  • message content.

We use this data to handle your inquiry, communicate with you and manage the business relationship. The form is technically processed through an integration layer and may subsequently be forwarded to our internal e-mail communication and the Raynet CRM system.

If the contact does not become a customer, we may retain business lead data for up to 24 months from the last relevant communication, unless you request earlier deletion or unless we have another legal reason for further retention.

2.3 Application user data

When you use the ProfitEcom application, we process in particular:

  • e-mail address,
  • first name and surname,
  • phone number,
  • language preference,
  • user role,
  • link to a customer account or tenant,
  • company details,
  • login information,
  • technical and security logs,
  • account settings and permissions.

Login to the application is provided through Auth0. Users may log in using e-mail and password, Google login or Microsoft Enterprise login.

Google and Microsoft login are used only to verify the user’s identity and to log the user into the application. We do not use them to access the user’s e-mail inbox, documents, files or other data in Google Workspace or Microsoft 365.

2.4 Billing and payment data

For contractual, billing and payment purposes, we may process in particular:

  • customer identification and contact details,
  • billing details,
  • VAT ID, Company ID and registered office,
  • information about the purchased plan,
  • subscription status,
  • payment and billing metadata.

Payments and subscriptions may be processed through Stripe. Payment cards and payment methods are processed in the Stripe environment. ProfitEcom does not store payment card numbers.

2.5 Data from connected integrations

ProfitEcom allows the customer to connect external systems and data sources. Depending on the specific implementation, these may include:

  • marketing platforms,
  • e-commerce platforms,
  • ERP systems,
  • PIM systems,
  • CRM systems,
  • logistics and warehouse systems,
  • spreadsheets and auxiliary data files,
  • other customer systems according to the implementation analysis.

The data stored and processed varies depending on the specific customer, its systems and the agreed scope of implementation.

By default, ProfitEcom works mainly with business and economic data, for example:

  • orders,
  • order items,
  • products,
  • categories,
  • brands,
  • suppliers,
  • inventory,
  • returns,
  • costs,
  • margins,
  • marketing campaigns,
  • performance metrics,
  • sales channels,
  • countries,
  • payment and shipping methods.

The standard ProfitEcom data model does not require names, e-mail addresses, postal addresses or phone numbers of end customers of an e-commerce store. If it is necessary to track repeat purchases or customer behaviour in an aggregated form, a pseudonymized customer identifier is used, such as a hash of the original identifier.

For custom reports and individual implementations, the scope of processed data may be broader. Such processing is always based on an implementation analysis, the contract, the data scope approved by the customer and, where applicable, a data processing agreement.

The customer should not provide ProfitEcom with special categories of personal data, health data, political opinions, religious beliefs, criminal offence data, national identification numbers, children’s data or other sensitive data unless this has been expressly agreed in writing.

3. Google login, Google Ads API and Google Analytics API

ProfitEcom uses Google in three different situations.

3.1 Login using a Google account

A user may log in to the ProfitEcom application using a Google account through Auth0. In such case, we process only the data necessary to verify the user’s identity and to create or manage the user account, typically the e-mail address, user identifier and basic profile data provided as part of the login process.

This login is not used to access Gmail, Google Drive, Google Sheets, Google Calendar or any other Google Workspace data.

3.2 Connecting a Google Ads account

A customer may connect its Google Ads account in the application. The connection is performed through Google OAuth authorization. ProfitEcom does not receive or store the customer’s Google account password.

For Google Ads, we use the following permission: https://www.googleapis.com/auth/adwords

We use this permission only to read data from Google Ads accounts authorized by the customer. ProfitEcom does not write any changes to Google Ads accounts, does not create campaigns, does not modify budgets, does not edit ads, does not change account settings and does not perform any campaign management.

From the Google Ads API, we may process in particular:

  • advertising account IDs and names,
  • campaign IDs and names,
  • ad groups,
  • ads and their identifiers,
  • costs,
  • impressions,
  • clicks,
  • conversions,
  • performance metrics,
  • segments and dimensions available in Google Ads reporting,
  • other data necessary for marketing reporting and e-commerce economics calculations.

We use this data exclusively to provide the ProfitEcom service, in particular for reporting, marketing analytics, profitability calculations and connecting marketing costs with the customer’s business data.

Google Ads data:

  • is not sold,
  • is not provided to data brokers,
  • is not used for our own advertising targeting outside the provision of the ProfitEcom service,
  • is not used for retargeting for our own purposes,
  • is not used to train general AI or ML models,
  • is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.

3.3 Connecting a Google Analytics account

A customer may connect its Google Analytics account or Google Analytics property in the application. The connection is performed through Google OAuth authorization. ProfitEcom does not receive or store the customer’s Google account password.

For Google Analytics, we use the following permission: https://www.googleapis.com/auth/analytics.readonly

We use this permission only to read data from Google Analytics accounts and properties authorized by the customer. ProfitEcom does not write any changes to Google Analytics accounts, does not modify property settings, does not create or change data streams, events, conversions, audiences or any other Google Analytics settings.

From the Google Analytics API, we may process in particular:

account IDs and names,

property IDs and names,

basic property settings, such as currency and time zone,

traffic data,

traffic sources,

campaigns,

session sources and media,

device data,

geographic data,

landing pages,

page views,

events,

conversions,

e-commerce metrics,

dimensions and metrics available in Google Analytics reporting,

other aggregated reporting data necessary for website analytics and e-commerce performance evaluation.

We use this data exclusively to provide the ProfitEcom service, in particular for reporting, marketing analytics, website traffic analysis, conversion evaluation and connecting marketing, website and business data of the customer.

Google Analytics data:

is not sold,

is not provided to data brokers,

is not used for our own advertising targeting outside the provision of the ProfitEcom service,

is not used for retargeting for our own purposes,

is not used to train general AI or ML models,

is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.

3.4 Security and disconnection of Google integrations

Authorization tokens obtained through Google OAuth are stored in a secured backend infrastructure. Long-term tokens are stored in encrypted form. Tokens are not displayed to users in the application, are not stored in analytical tables in Fabric and are not used for any purpose other than authorized retrieval of data from connected accounts.

When the Google Ads or Google Analytics integration is disconnected, we remove the stored authorization credentials and also call the Google endpoint to revoke the authorization.

4. Meta Marketing API

A customer may connect its Meta advertising accounts in the application. The connection is performed through authorization in the Meta/Facebook environment.

ProfitEcom uses the Meta Marketing API only to read advertising and performance data from accounts authorized by the customer. ProfitEcom does not create, edit, pause, delete or manage campaigns, ad sets, ads, budgets, audiences or pixels.

From the Meta Marketing API, we may process in particular:

  • advertising account IDs and names,
  • campaigns,
  • ad sets,
  • ads,
  • costs,
  • impressions,
  • clicks,
  • conversions,
  • performance metrics,
  • other aggregated reporting data available in the Meta Marketing API.

The technical configuration of the Meta integration may require permissions related to access to advertising accounts and business assets. We use these permissions only to allow the customer to authorize selected advertising accounts and to enable ProfitEcom to read data required for reporting. We do not use them for active management of advertising accounts.

Meta data:

  • is not sold,
  • is not provided to data brokers,
  • is not used for our own advertising targeting outside the provision of the ProfitEcom service,
  • is not used to train general AI or ML models,
  • is not used for purposes other than those described in this Privacy Policy and in the contract with the customer.

When the Meta integration is disconnected, we remove the stored authorization credentials and call the mechanism for removing the application’s permissions. ProfitEcom also has endpoints prepared for deauthorization and data deletion requests in accordance with Meta requirements.

Details about disconnecting integrations and data deletion requests are provided on the Data Deletion page.

5. Why we process data

We process personal data mainly for the following purposes:

Purpose of processingExamples of dataLegal basis
Website operationtechnical data, essential cookieslegitimate interest
Processing contact form submissionsname, last name, email, phone, company, messagecontract negotiation, legitimate interest
Customer account managementemail, role, company, tenant, language, phonecontract fulfillment
Login and securityauthentication data, logs, roles, permissionscontract performance, legitimate interest
Provision of the ProfitEcom Servicecustomer data, marketing data, business datacontract performance
Processing Customer Data as a Processordata provided or connected by the customerdata processing agreement
Connecting Google Ads, Google Analytics and Meta accountsadvertising accounts, Google Analytics accounts and properties, campaigns, website traffic, conversions, metrics, OAuth tokenscontract performance, customer authorization
Invoicing and Accountingbilling information, payment metadatacontract performance, legal obligation
Website Analytics and Marketing Measurementcookies, online identifiers, traffic, conversionsconsent
Protection of Rights and Securitylogs, audit data, communicationlegitimate interest, legal obligation

Where processing requires consent, for example in the case of marketing cookies, you may change or withdraw your consent at any time through the cookie settings.

6. Cookies and marketing technologies

We use cookies and similar technologies on the website. Some cookies are necessary for the website to function. Others are used only based on your consent, for example for analytics, advertising measurement or marketing pixels.

We use Cookiebot to manage consent.

On the website, we may use in particular:

  • Google Analytics 4,
  • Google Ads measurement,
  • Meta Pixel,
  • Sklik measurement,
  • Microsoft Ads UET,
  • possibly LinkedIn Insight Tag,
  • Saleskit/Merk for identifying corporate visitors to the website,
  • embedded YouTube video,
  • a chat tool, such as Smartsupp,
  • other similar tools listed in the cookie banner or Cookie Policy.

Details about individual cookie categories, purposes and retention periods are provided in the Cookie Policy. You can change your consent at any time through the Cookie Settings link in the website footer.

7. Who we may share data with

We do not share personal data with third parties for the purpose of selling it. We make data available only to the extent necessary for the operation of the website, the application, customer integrations, security, support, billing and legal obligations.

We use in particular the following providers and technologies:

Provider / TechnologyPurpose
Auth0 / OktaUser authentication, login, identity management
Microsoft Azure / Microsoft Fabric / Power BIData platform, analytics, reporting
Microsoft 365Email and internal communication
XanoBackend, API, database, and integration layer
HetznerServer hosting for the self-hosted n8n integration layer
Webflowmarketing website operation
Cookiebot / Usercentricscookie and consent management
Mandrill / Mailchimp Transactional Emailtransactional emails from Auth0, such as security codes and password reset
Stripepayments, subscriptions, and billing processes
RaynetCRM tracking of sales leads from web forms
Googlelogin, Google Ads API, Google Analytics API, web analytics and ad measurement based on consent
MetaMeta Marketing API and ad measurement based on consent
Microsoft Advertisingad measurement based on consent
Sklikwebsite traffic measurement, conversion measurement, advertising campaign measurement and retargeting based on consent
Saleskit / Merk / Imper CZ s.r.o.identification of corporate visitors to the website, B2B marketing, business leads and possible forwarding to CRM according to consent and settings
LinkedInad measurement based on consent, if deployed
Smartsuppwebsite chat communication, if deployed

Some providers act as processors, while others act as independent controllers, especially where they provide their own services such as payment infrastructure, advertising platforms or identity services.

For customers for whom we act as a personal data processor, we enter into or make available a data processing agreement.

8. Where data is processed

ProfitEcom data is primarily processed within the European Union or the European Economic Area.

We use in particular:

  • a dedicated Xano instance in Belgium,
  • Microsoft Fabric in the West Europe region,
  • Auth0 in the EU region,
  • a self-hosted n8n integration layer on a Hetzner server in Nuremberg.

Some providers, such as Webflow, Stripe, Mandrill/Mailchimp, Google, Meta, Microsoft, LinkedIn or other technology providers, may process data outside the EU/EEA as part of their services. Some other providers, such as Sklik or Saleskit/Merk, may process data according to their own terms and infrastructure.

9. How we protect data

We use technical and organizational measures appropriate to the nature of processing and the related risks. These measures include in particular:

  • encrypted data transmission via HTTPS/TLS,
  • encrypted storage of long-term authorization tokens,
  • use of OAuth instead of storing passwords to external platforms,
  • role-based access restrictions,
  • separation of data of individual customers and tenants,
  • access control in Power BI using RLS,
  • restriction of internal access to production data to necessary persons only,
  • MFA for key services and administrator accounts,
  • use of a dedicated Xano instance,
  • operation of the integration layer on a server with restricted access,
  • secure deletion and revocation of tokens when integrations are disconnected,
  • technical logging and monitoring of operational events,
  • limited retention of execution data in the integration layer,
  • limitation or redaction of sensitive data in integration workflows where access tokens may occur,
  • internal procedure for handling security incidents,
  • backups and technical copies according to the capabilities and standards of the providers used.

Long-term tokens for Google Ads, Google Analytics and Meta integrations are stored only in the backend infrastructure. They are not stored in Fabric, Power BI or the WeWeb frontend. Only short-term access tokens necessary to retrieve data from authorized platforms are passed to n8n.

ProfitEcom does not use customer data, Google Ads data, Google Analytics data or Meta data to train general AI or ML models.

10. How long we retain data

We retain personal data only for as long as necessary for the purposes described in this Privacy Policy, for the performance of a contract, compliance with legal obligations or protection of our rights.

In general:

Type of dataRetention period
Contact form dataup to 24 months from the last relevant communication, unless the contact becomes a customer
Customer account datafor the duration of the contractual relationship and a reasonable period after its termination
Customer data in the applicationfor the duration of the service, unless the customer requests earlier deletion
Data from Google Ads, Google Analytics and Meta integrationsfor the duration of service use, or until data is deleted upon customer request
OAuth tokensfor the duration of active integration; upon disconnection, they are removed and, where possible by the platform, revoked
Billing and accounting dataas required by law
Technical logs and integration execution datafor a limited technical period, typically ranging from days to weeks
Backups and technical copiesaccording to backup cycles and provider standards, usually for a limited period; ideally no longer than 90 days, unless a longer period is required by the provider's technical settings or legal obligations

If a customer terminates the use of the ProfitEcom service, we generally delete or anonymize customer data within 30 days of service termination, unless otherwise agreed with the customer or unless we have a legal reason for longer retention.

If an active customer only disconnects Google, Meta or another integration, we remove or revoke the authorization credentials. Historical analytics data may remain available for the customer’s reporting for as long as the customer uses the service or until the customer requests its deletion.

11. Data deletion and disconnecting integrations

A user or customer may request the deletion of personal data, customer data or data from a specific integration.

The detailed procedure is described on the Data Deletion page.

In general:

  • The Google Ads and Google Analytics integrations can be disconnected in the application; when disconnected, we remove the stored authorization credentials and call the Google revoke endpoint.
  • The Meta integration can be disconnected in the application; when disconnected, we remove the stored authorization credentials and call the mechanism for removing the application’s permissions.
  • A data deletion request can be sent to privacy@profitecom.com.
  • For customer data where we act as a processor, the request may need to be confirmed or submitted by the customer as the data controller.
  • If we must retain data for legal reasons, for example due to accounting, contractual claims or statutory obligations, we will not delete it before these reasons cease to apply.

12. Rights of data subjects

Under GDPR, you may have in particular the following rights:

  • the right of access to personal data,
  • the right to rectification of inaccurate data,
  • the right to erasure,
  • the right to restriction of processing,
  • the right to data portability,
  • the right to object to processing,
  • the right to withdraw consent, where processing is based on consent,
  • the right to lodge a complaint with a supervisory authority.

In the Czech Republic, the supervisory authority is:

Office for Personal Data Protection

Pplk. Sochora 27

170 00 Prague 7

Website: www.uoou.cz

Requests concerning personal data can be sent to privacy@profitecom.com.

If we process personal data as a processor for our customer, we may refer you to the relevant customer as the data controller. In such case, we will provide the customer with the necessary cooperation.

13. Automated decision-making and AI

ProfitEcom does not provide decision-making that would have legal effects concerning natural persons or similarly significantly affect them within the meaning of GDPR.

ProfitEcom does not use customer data, Google Ads data, Google Analytics data, Meta data or end customer data to train general AI or ML models.

14. Changes to this Privacy Policy

We may update this Privacy Policy from time to time, especially when the service features, providers, legal requirements or processing methods change.

The current version will always be available on the ProfitEcom website. If a change is material, we may also inform customers by e-mail or in the application.

15. Contact

For questions regarding personal data protection, please contact us at:privacy@profitecom.com

For security notifications, suspected vulnerabilities or security incidents, please contact us at:

security@profitecom.com

General contact: hello@profitecom.com

Operator:

SUBVENTUM s.r.o.

Kaprova 42/14

110 00 Prague 1

Czech Republic

Company ID: 08239771

VAT ID: CZ08239771