Privacy Policy
This Privacy Policy describes how EffyCorp ("we", "us", or "our") collects, uses, and protects your information when you use the Background Remover — ProductShot Chrome extension ("Service"). We are committed to protecting your privacy and processing your data only to the extent necessary to provide the Service.
Short version: We only collect what we need to run the Service. Your images are processed in memory and not stored permanently. We do not sell your data to anyone.
1. Information We Collect
1.1 Account Information
When you sign in with Google, we receive:
- Your Google account email address;
- A unique Google user identifier (sub) used to link your account;
- A randomly generated device ID created by the extension and stored locally in your browser.
We do not access your Google contacts, Google Drive, calendar, or any other Google services.
1.2 Usage Data
We record the number of background removal operations performed under your account each billing month. This counter is used to enforce free-tier limits and subscription quotas.
1.3 Images
Images you submit for background removal are transmitted to our backend server over HTTPS, forwarded to our AI processing pipeline, and the resulting output is returned to your browser. Images are not stored on our servers after processing is complete. We do not retain, analyze, or use your images for any purpose other than performing the requested operation.
1.4 Technical Logs
Standard server logs may record request timestamps, HTTP status codes, and approximate request size for operational monitoring and error diagnosis. Logs do not contain image content. Logs are retained for up to 30 days.
2. How We Use Your Information
We use the collected information to:
- Authenticate your identity and maintain your session;
- Process your background removal requests;
- Track usage against your plan's quota;
- Manage your subscription and process billing through our payment processor;
- Diagnose technical issues and monitor service health;
- Respond to your support requests.
3. Legal Basis for Processing (GDPR)
If you are located in the European Economic Area or United Kingdom, we process your personal data on the following legal bases:
- Performance of a contract — processing necessary to provide the Service you have requested (authentication, quota tracking, image processing);
- Legitimate interests — server logs for security and reliability monitoring;
- Legal obligation — where applicable law requires us to retain certain records.
4. Data Sharing & Third Parties
4.1 AI Processing
Background removal is powered by Replicate (replicate.com). Images are transmitted to Replicate's API for AI inference. Replicate's privacy practices are governed by their own privacy policy. Images submitted to Replicate are not retained beyond the immediate inference operation.
4.2 Payment Processing
Subscription payments are processed by PayPro Global Inc., our Merchant of Record. PayPro collects and processes payment information (credit card details, billing address) directly. We never receive or store your payment card details. PayPro's privacy practices are governed by their own privacy policy.
4.3 Google OAuth
Authentication is performed via Google's OAuth API. Google's privacy policy governs the data Google collects during the sign-in process.
4.4 No Sale of Data
We do not sell, rent, or trade your personal information to any third party for marketing or advertising purposes.
5. Data Retention
- Account data (email, google_sub, device ID): retained while your account is active. Deleted within 30 days upon account deletion request.
- Usage counters: retained for up to 13 months for billing dispute resolution, then deleted.
- Images: not stored after processing. No retention period applies.
- Server logs: retained for up to 30 days, then automatically purged.
6. Data Security
We implement appropriate technical measures to protect your data:
- All data is transmitted over HTTPS/TLS;
- Session tokens are short-lived (1 hour) JWTs;
- Our servers are access-controlled with key-based SSH authentication only;
- Payment data is handled entirely by PayPro and never passes through our servers.
No method of transmission or storage is 100% secure. We cannot guarantee absolute security, but we take reasonable steps to protect your information.
7. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access — request a copy of the data we hold about you;
- Correction — request correction of inaccurate data;
- Deletion — request deletion of your account and associated data;
- Portability — request your data in a machine-readable format;
- Objection — object to processing based on legitimate interests;
- Restriction — request restriction of processing in certain circumstances.
To exercise any of these rights, contact us at support@effycorp.com. We will respond within 30 days.
8. Children's Privacy
The Service is not directed at children under the age of 13. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will revise the "Last updated" date at the top of this page. For material changes, we will provide notice through the extension or by email. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
10. Contact
For privacy-related questions, requests, or complaints, contact us at:
- Email: support@effycorp.com
- Website: effycorp.com/productshot