Privacy notice
How Korzaro processes data about website visitors, account users and shop contacts. We process a shop’s customer data on behalf of its operator under separate data processing terms. Version dated 28 September 2026.
This is a translation for convenience. The controller is a Czech company and the Czech version of this notice is the binding one; if the two ever differ, the Czech wording prevails.
Who processes the data
The controller is Shingen s.r.o., company ID 192 48 334, registered at Na Hřebenkách 3340/122, Smíchov, 150 00 Prague 5, Czech Republic, entered in the commercial register kept by the Municipal Court in Prague, section C, file 383648. Contact info@korzaro.com, telephone +420 603 402 154.
What data we process
For the signup form, this is the e-mail address, submission time, the form’s location and where the visit came from: the campaign tags in the page address and the name of the site that sent you to us, never its full address. When choosing a password you can optionally say where you heard about us. In the contact form, we process the name, email address and message you provide so we can respond to you. When you order a paid plan, we also process billing details (name, company ID, VAT ID, address and e-mail) and subscription and payment records to perform the contract, and keep receipts for as long as accounting and tax law requires. You enter your card directly with the Stripe payment gateway; we neither store nor see its number. Once an account is activated, we also process the name, sign-in details, language, project membership and role, security and audit records, and support communication. For connected services, we record their settings and technical identifiers; access secrets are stored encrypted. In the application, we measure approved screen names, product milestones, aggregate time spent and last activity. Product analytics runs without cookies or session recording, but its provider may receive technical data in transit, such as an IP address and device information.
Why we use it and on what basis
The address is how we let you in: we create an account and a fourteen-day trial project from it, let you straight in and send you an e-mail with a link that confirms the address and sets your password. The project reads data only from the services you connect yourself; it starts walking the website derived from the address only once you confirm it through that link or a verified Google or Apple sign-in. We also use the address to tell you when the trial is about to end.
We process the account, trial, support and service messages to enter into and perform the service agreement. Security, abuse prevention, essential operating records and limited usage measurement rely on our legitimate interests in operating a secure service and improving the product. We send news about our own similar services to existing users on the basis of legitimate interests where the law permits; in other cases we rely on consent. You may object to marketing or withdraw consent at any time. We do not sell data or provide it to others for their own advertising.
An e-mail address is required to create an account, verify access and send service communications; without it we cannot provide the trial or account. Other profile information is optional unless a feature marks it as required.
How we protect your data
We protect personal information and data obtained through Google APIs, including Google Analytics, Search Console, Google Ads, Merchant Center, YouTube Analytics and Business Profile, using the following measures:
- Encrypted transfer: connections between your browser and Korzaro, and between Korzaro and Google APIs, use HTTPS/TLS.
- Encrypted access credentials: stored Google OAuth refresh tokens and other integration credentials are encrypted in the database. The encryption key is kept separately in protected server configuration.
- Restricted access: access to a shop’s data in the application is checked against project membership and user roles. Operational access is restricted to authorized administrators. The production database and cache are not directly accessible from the public internet.
- Protected backups: database backups are encrypted before upload to private backup storage. The backup decryption key is kept outside the production server.
- Account and operational safeguards: passwords are stored as hashes, sign-in attempts are rate-limited, and session cookies use Secure and HttpOnly protections. We record security and administrative actions and filter sensitive data from error reports.
How long we keep it
An unused trial project is suspended after fourteen days. A standalone registration whose account was never activated, whose sources were never given credentials and which never started collecting data is automatically removed from Korzaro’s operational database during the first daily cleanup at least 30 days after suspension and at least 30 days after the trial ends. We delete the project and the account created solely for it. Used or shared accounts and projects are not removed by this automatic cleanup; after the service ends, we delete or return them as required by the agreement and your request. Uncertain cases are kept for individual review, including older registrations without a complete history. To request earlier deletion, write to info@korzaro.com.
This deletion covers the operational database. Older copies may remain in encrypted backups and records of e-mails already sent; the same daily cleanup does not remove them; encrypted daily backups expire within 90 days. For other newsletter addresses, you can unsubscribe at any time and we keep them for at most three years from the last contact.
We keep security, audit and accounting records for as long as needed to protect the service, evidence actions and meet legal duties, and review their continued need regularly. Data needed for legal claims may be kept while a claim can be brought or defended.
Who can access it
Korzaro’s primary database runs at Hetzner in the European Union. Cloudflare protects network traffic and stores backups encrypted before upload in its European jurisdiction. We send e-mail through Resend and diagnose errors through Sentry with default collection of personal data and request bodies disabled. PostHog product analytics receives only approved screen names, milestones and technical data, without a shop name, address or content. Anthropic’s commercial API words some outputs only after the input passes a personal-data check. Stripe Payments Europe, Ltd. (Ireland) handles subscription payments and receipts. We contractually bind our providers. Some are established in the United States or may process data outside the EEA; such transfers are protected by an adequacy decision or Standard Contractual Clauses. On request, we explain the mechanism used and how to obtain a copy.
AI assistant connections
If a project owner connects Korzaro to an external AI assistant such as Claude or ChatGPT, they choose the project and the areas the assistant may read. Korzaro sends the aggregate answer requested in that conversation to the chosen assistant provider. The provider processes that answer under the user’s account and its own terms and privacy settings. The assistant’s sign-in to Korzaro is verified by WorkOS, which processes the e-mail address and account identifier for that. The owner can change or revoke the connection in Korzaro. Korzaro records access metadata for security and support but does not store the answer text in its MCP access log. The connection guide explains the controls.
Mobile app
The Korzaro app for iPhone and Android shows the same account as the web and processes the same data. In addition, we count how many people opened the app per day and per month, separately for iOS and Android, without linking the count to any account. Download numbers come from the aggregate reports of the App Store and Google Play. You can delete your account right in the app under My account → Delete account, or on the account deletion page.
What you can do about it
You can unsubscribe at any time using the link in every e-mail, or write to info@korzaro.com and we will delete the address. You also have the right to access, correct or erase data, restrict processing, receive portable data where applicable, and object to processing based on legitimate interests. You may withdraw consent at any time without affecting earlier lawful processing. Requests are free and we normally answer within one month. You may lodge a complaint with the Czech Office for Personal Data Protection. If you represent a shop and the request concerns its customer data, contact the shop operator first; Korzaro acts as its processor for that data.
Where the data comes from and automated decisions
We receive data from you, from the project operator who invited you, and from connected services under the permissions you approve. Where data does not come directly from you, we make this information available by the first communication at the latest, unless you already have it or a statutory exception applies. We do not make automated decisions about account users that have legal or similarly significant effects.
Shop customer data
The shop operator decides the purpose and scope of processing for this data. Details are set out in the Czech data processing terms and the security annex.
Cookies and website analytics
We measure traffic on korzaro.com and the results of our advertising based on our legitimate interest in improving and promoting the website. Cloudflare Web Analytics uses no cookies or other browser storage and does not identify visitors. Google Analytics 4, provided by Google Ireland Limited, sets the analytics cookies _ga and _ga_* for up to two years to recognise a returning visit. Google processes a pseudonymous browser identifier, pages viewed, the referring website, approximate location derived from the IP address and device details; data may be transferred to the USA under the EU-US Data Privacy Framework. The Meta pixel, provided by Meta Platforms Ireland Limited, sets the _fbp cookie for three months and passes Meta the pages viewed and trial signups so we can measure and target advertising on Facebook and Instagram; this data may also be transferred to the USA. If you go on to pay for a subscription, we also send Google and Meta your first payment (the invoice number and the amount excluding VAT) against the same identifiers and your browser type, so we know which advertising brought a paying customer; we never pass on your e-mail or name. We only see aggregate figures in the reports. You can refuse or delete cookies in your browser settings.