Privacy Policy

Last updated: August 9, 2026

SonarID Inc. (“SonarID,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our customer intelligence platform.

1. Roles: Who Controls the Data

SonarID plays two different roles depending on the data:

  • For our own account holders (merchants): we are the data controller of your account information and how you use SonarID.
  • For your store’s customer data: when you connect a Shopify (or other commerce) store, we act as a service provider / data processoron your behalf. We process your customers’ personal data only to provide the SonarID service to you, under your instructions, and in accordance with our agreement with you and this policy.

2. Information We Collect

Account Information

When you create an account, we collect your name, email address, and password (or authentication credentials via Google OAuth).

Store Data

When you connect your store, we access your customers’ names, email addresses, order history, and shipping addresses via read-only API access. We never request or access payment card data. We request only the data required to identify and score notable customers.

Enrichment Data

To identify professional and public profiles, we submit a customer’s email addressto a third-party enrichment provider (EnrichLayer) and receive back publicly available professional data such as job title, company, and social profiles. See the data minimization note in Section 4: only the email address is shared with the enrichment provider. A customer’s name, shipping address, and order details are never sent to the enrichment provider.

Usage Data

We collect analytics about how you use SonarID, including pages visited, features used, and interactions, via PostHog. This is used to improve our product and is not customer personal data from your store.

3. How We Use Information

  • Provide and maintain the SonarID service
  • Enrich and score customer profiles to identify notable (VIP) customers
  • Send notifications via Slack and email about detected VIPs
  • Process subscription and usage payments through Stripe
  • Improve and secure our platform
  • Send transactional emails (welcome, onboarding, alerts)

We do not sell personal data, and we do not use your store’s customer data to train models or for any purpose other than providing SonarID to you.

4. Data Minimization & Sub-Processors

Data minimization.The only customer field transmitted to our enrichment provider is the email address. Names, shipping addresses, and order data remain within SonarID’s own systems and are used solely to score and display results to you.

We rely on the following sub-processors to operate SonarID:

  • EnrichLayer — email-based profile enrichment (receives customer email addresses only).
  • Stripe — subscription and usage payment processing. We never store payment card data.
  • Slack — delivering VIP alert notifications to your workspace.
  • Neon — managed database hosting (encrypted at rest).
  • Vercel — application hosting and serverless compute.
  • Inngest — background job processing.
  • Upstash — rate limiting and ephemeral caching.
  • Resend — transactional email delivery.
  • PostHog — product analytics (SonarID usage, not your store’s customer data).
  • Sentry — error monitoring.

5. Customer Data Rights & Opt-Out

Because we process your store’s customer data on your behalf, we honor deletion and data requests that come to us directly and through the platform’s compliance channels. For Shopify, we process the mandatory customers/data_request,customers/redact, and shop/redact requests and redact the corresponding customer records.

  • Merchants can request that we stop enriching specific customers, suppress a customer from processing, or delete stored customer data by contacting us.
  • A customer whose data was processed can request access to or deletion of their data; we will fulfill or route the request to the relevant merchant.

6. Cookies

We use essential cookies for authentication and session management, and analytics cookies (PostHog) to understand product usage. You can control cookie preferences through your browser settings.

7. Data Retention

We retain your account data for as long as your account is active. Enrichment results are cached for up to 90 days to reduce redundant lookups. When you delete your account, or when a redaction request is received, we delete or redact the corresponding data within 30 days.

8. Data Security

We encrypt data in transit (TLS) and at rest. Shopify access tokens and webhook secrets are additionally encrypted at the application layer (AES-256-GCM) before storage. Store data and API credentials are held in an access-restricted database and are never exposed to your browser. We use read-only API scopes wherever possible, keep production and non-production data separate, restrict staff access to personal data to those who need it, and maintain an access log for reads of customer data.

9. Your Rights

CCPA (California Residents)

  • Know what personal information we collect
  • Request deletion of your personal information
  • Opt out of the sale of personal information (we do not sell personal data)

GDPR (EU/EEA Residents)

  • Access your personal data
  • Rectify inaccurate data
  • Request erasure of your data
  • Restrict or object to processing
  • Data portability

10. Children's Privacy

SonarID is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through a notice on our platform.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your rights, contact us at privacy@sonarid.com.