Who we are
BasketFathom is operated by Fleeta Limited (company number 16675897), registered in England and Wales. Our registered office is 50 Princes Street, Ipswich, IP1 1RJ, United Kingdom. Contact us at vytautas@fleeta.co.uk.
Information we process
- Shopify shop identity, installation status, authorized scopes, locale, timezone, and the authenticated staff context supplied by Shopify.
- Product, variant, collection, supported metafield, inventory, media metadata, and merchant-provided catalog content needed for readiness analysis.
- Merchant settings, goals, markets, personas, approvals, audit events, plan entitlements, credit usage, and support diagnostics.
- Minimized post-install order evidence and consented storefront events needed to report assisted outcomes. BasketFathom does not require customer names, email addresses, phone numbers, postal addresses, checkout tokens, or raw search text.
- Model and operational metadata such as schema version, token usage, cost, latency, status, and safe error class. Secrets and raw access tokens are never written to logs.
Shopify processes app subscription and payment information. We receive subscription state and billing-event status, not card details.
Why we use information
We use information to authenticate the shop, synchronize its catalog, provide readiness audits and bounded simulations, prepare merchant-approved product changes, operate the guided finder, estimate delivery windows, measure assisted outcomes, administer USD plans and credits, secure the service, provide support, meet legal obligations, and respond to Shopify privacy requests.
Where applicable, our legal bases are performance of the merchant service contract, legitimate interests in operating and securing the service, compliance with legal obligations, and consent managed through Shopify for storefront analytics.
AI processing and service providers
BasketFathom may send minimized catalog or merchant task content to OpenAI to produce schema-validated analysis. Requests use provider-side storage disabled where BasketFathom manages state. Merchant content is treated as data, not as executable instruction, and model output cannot publish product facts without merchant approval.
We use Shopify for commerce-platform services, OpenAI for approved AI workloads, and OVHcloud infrastructure for the dedicated application server and encrypted off-host backups. Providers may process data in other countries under their contractual safeguards and applicable transfer mechanisms. We do not sell personal information.
Retention and security
Active-shop records are kept while needed to provide the service. Consented storefront event and journey-attribution records are scheduled to expire within 30 days. Minimized order and refund evidence is scheduled to expire after 13 months. Local encrypted backup sets are retained for 35 days and whole-system off-host backups for 14 days. Uninstall, export, deletion, and Shopify-mandated redaction requests are processed through auditable, idempotent workflows; backup copies expire through the stated retention cycle.
We use TLS, isolated production and staging environments, least-privilege access, forced database row-level security, encrypted Shopify credentials, durable job records, monitoring, encrypted backups, and tested restoration procedures.
Your choices and rights
A merchant can review permissions in Shopify, leave optional product write access disabled, disable storefront components, keep usage overage off, request an export or deletion in BasketFathom, or uninstall the app. Depending on location, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information and to complain to a data-protection authority.
Send privacy requests to vytautas@fleeta.co.uk. We may need to verify the request through the associated Shopify account.
Changes
We will update the effective date and notify merchants through the app or Shopify when a material change requires notice.