Privacy policy
Camel builds Shopify stores. This policy explains what personal data we collect, why, where it goes and what rights you have over it. We have written it to be read, not just published. Section 11 explains why there is no contact address yet.
1. Who we are
Camel is a pre-launch project run by its founders in the United Kingdom. It has not yet been incorporated, so there is no company name to give you; the founders are the data controllers, and this policy will be updated with the legal entity, its registered address and its ICO registration once they exist. UK data protection law (the UK GDPR and the Data Protection Act 2018) applies to what we do now, exactly as it will then.
2. This website (trycamel.app)
What we collect
The website has two forms, the launch waitlist and the affiliate interest list. When you submit one, we store:
- Your email address.
- Which form you used ("site" or "affiliates") and, if your browser sends it, the page that referred you to us.
- The date and time you signed up.
To stop abuse, our server briefly looks at the IP address each request comes from and limits how many submissions one address can make in a minute. The address is held in memory for that minute and is not written to our database.
We do not use analytics, advertising pixels or tracking cookies on this website. We set no cookies of our own.
Why, and on what legal basis
- To tell you when Camel launches and to send you the invitation you asked for. Legal basis: your consent, given when you submit the form. You can withdraw it at any time (section 8).
- To contact prospective affiliates about the programme when it exists. Legal basis: consent, as above.
- To keep the forms working and free of abuse (the rate limit above). Legal basis: our legitimate interest in running a functioning website.
We will not add you to any other mailing list, and we will not sell or rent your address to anyone.
Third parties who load when you visit
The page loads its typefaces from Google Fonts. When it does, your browser sends your IP address to Google, as it does for any resource fetched from Google's servers. Google's handling of that request is covered by Google's privacy policy. We are working to self-host the fonts so this stops.
3. The Camel app for Shopify
This section applies once you install the Camel app on your Shopify store. It is written for merchants; shoppers on a merchant's store are covered by that merchant's own privacy policy.
What we collect
- Your store's identity and an access token. Shopify gives us your store's domain and a token that lets Camel read and write the parts of your store you authorised (for example products and themes). Without it Camel cannot publish anything to your store.
- The product you build from. The product page URL you paste, and what we extract from it: titles, descriptions, prices, images and reviews. If it is your own product on Shopify, we read it through Shopify instead.
- What Camel generates for you. The store's copy, images, design choices and page layouts, and the record of what was published to your store, so you can come back to it and edit it.
- Your answers in the questionnaire (target customer, store shape, design preferences).
- Feature requests and votes. If you use the "Request a feature" board, we store your suggestion, the votes you cast and any feedback you type, linked to your store's domain.
- Support messages. If you contact support from inside the app, the message and your store's domain are included so we can find your account.
Why, and on what legal basis
- To provide the service you installed: generating, editing and publishing your store. Legal basis: performance of a contract with you.
- To improve Camel using feature requests, votes and the patterns in what gets generated. Legal basis: our legitimate interest in building a better product. We do not use your generated store's content to train AI models.
- To meet Shopify's requirements for apps, including responding to their data requests. Legal basis: legal obligation and legitimate interest.
AI providers
Camel writes copy and creates images using third-party AI services (currently Anthropic and Google). The product information you give us, and the brief Camel derives from it, is sent to those services to produce the result. Under the terms we use them on, they do not train their models on this data. We do not send them your store's access token or your customers' data.
4. Where your data is stored and who processes it
We use a small number of service providers, each bound by a data processing agreement:
| Provider | What for | Where |
|---|---|---|
| Supabase | Our database, including the waitlist and app data | See section 5 |
| Render | Hosting this website and our servers; keeps standard access logs (IP address, time, page requested) for a short period | United States and Germany |
| Shopify | The platform the app runs on; authentication and billing | Canada, with global infrastructure |
| Anthropic, Google | AI generation of copy and images (app only) | United States |
| Resend | Sending the emails you asked for, once we start sending them | United States |
5. International transfers
Some of the providers above are outside the UK. Where they are, we rely on the UK's adequacy regulations where they exist, and otherwise on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, so that your data keeps the protection it has here.
6. How long we keep it
- Waitlist and affiliate emails: until Camel has launched and you have received the invitation you asked for, and then for up to 12 months in case you want to come back, unless you unsubscribe earlier.
- App data: for as long as the app is installed. If you uninstall, Shopify tells us and we delete your store's access token immediately. Generated stores and settings are kept for 90 days so a reinstall picks up where you left off, then deleted.
- Feature requests and votes: for as long as the board exists, with your store's domain removed 90 days after you uninstall.
- Server logs: 30 days.
7. Security
Data is encrypted in transit and at rest. Access tokens are stored only in our database, never in code or logs, and production credentials are held only in our hosting provider's secret store. Access to production data is limited to the people who run Camel.
8. Your rights
Under UK data protection law you can ask us to:
- Tell you what we hold about you and give you a copy (access).
- Correct anything that is wrong.
- Delete your data. For the waitlist, this is the same as unsubscribing.
- Stop or restrict what we do with it, or object to processing based on legitimate interests.
- Withdraw consent at any time, without affecting what was done before.
- Receive your data in a portable format.
Once a contact address exists (section 11), we will respond to any of these requests within one month. You do not have to pay, and you do not have to give a reason. If you are unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk, though we would rather you told us first.
9. Children
Camel is a business tool. We do not knowingly collect data from anyone under 18, and the website and app are not directed at them.
10. Changes to this policy
When we change this policy we will update the date at the top. If a change is significant, for example a new purpose for the data we already hold, we will email the people it affects before it takes effect.
11. Contact
There is no contact address yet. Camel will not email anyone on the waitlist or the affiliate list, and will not use those addresses for anything, until it has incorporated and has a real contact address. When that happens, the address will be published here, the people on the list will be told in the first email they receive, and requests about your data will be handled within the one-month window in section 8. Until then the only thing that happens to your email address is that it is stored.