Privacy Policy
Last updated 3 October 2026
This policy explains what Avisekh Goswami, an individual trading as Shaewoo by DontMisimi, collects when you use Shaewoo, why, how long we keep it, who else handles it, and what you can ask us to do with it. We decide why and how this information is used, so we are the controller of it. Where we handle product data on your behalf (the content of your catalog), you are the controller and we act on your instructions.
What we collect
| Category | What it is | Why |
|---|---|---|
| Account | Email address and authentication identifier, held by our sign-in provider Clerk. | To identify you and secure your account. |
| Content you supply | URLs, PDFs, documents, images, notes and audio (voiceovers and soundtracks) you upload, a transcript of the words in uploaded audio, used only to screen it, and the videos generated from them. | To produce and store your videos. |
| Billing | Plan, subscription status and customer identifier from Creem. | To give you what you paid for. |
| Shopify store data | If you install the Shopify app: your shop domain, and the product names, descriptions, prices, images and links it reads (permission read_products), plus the product media it adds back when auto-publish is on (write_products). We keep the access token Shopify issues for your shop so the app keeps working, and discard it when you uninstall. We do not ask for your orders, customers or takings. | To make and, if you choose, publish your videos. |
| Usage | Counts of videos generated each month; error reports with the page and browser involved; and, only if you accept cookies on our website, page-view and click statistics. Our servers also keep ordinary technical logs (time, address, request) for security and fixing faults. | To enforce plan allowances, keep the service secure and working, and improve the product. |
| Feedback | What you write in the feedback box and any rating you choose, the page it was sent from (never the web address after the page name), and, if you were signed in or using the Shopify app, which account or shop sent it. Feedback sent while signed out is not linked to you. | To find out what is missing or confusing, and improve the product. |
| Moderation | The outcome of automated content screening, and a short excerpt where something was refused. | To enforce our content policies and investigate reports. |
We never see your card details. Payments are handled by Creem as merchant of record. We receive only the subscription status and a customer reference.
Who we share it with
We use a small number of providers, each for one purpose:
- Clerk — sign-in and account email.
- Neon — the database holding your projects and settings.
- Cloudflare — hosting, R2 storage for your files, and Workers AI, which transcribes audio you upload so its words can be screened, and runs some text features.
- Railway — runs the render service that turns catalog products into video files.
- Creem — merchant of record for web subscriptions: payments, invoices, and automated screening of the words your videos will say (product titles and descriptions, and anything you type) on the website and from the WooCommerce plugin and Odoo module.
- Shopify — if you use the Shopify app: sign-in, billing, and the product data you let it read.
- BigCommerce, Etsy and other shop platforms — if you import from one by typing its API credentials, those are used for that request only and are not stored. Pasting a product link makes our server fetch that public page for you; the address you paste is looked up through Cloudflare DNS to check it is a public one.
- Anthropic and Google Cloud Text-to-Speech — only if you use a feature that drafts text or reads it aloud: the text you send for that feature goes to the provider to produce the result. Videos rendered from a catalog do not use them.
- Resend — sends service emails, such as a low-stock alert, once email sending is switched on for the service.
- Google Analytics and PostHog — website and product analytics, only if you accept cookies. Sentry — error monitoring.
We also disclose information when the law requires it, to protect people from harm, or to deal with a sale or reorganisation of the service (we would tell you first). We do not sell personal information, we do not use your content to train anyone's models, and we do not use it for advertising.
Where it is processed
We operate from 162 GNB Road, Chandmari, Assam 781007, India. The providers above run their own data centres, many of them outside India (including in the United States and the European Union), so your information can be processed in other countries. We choose providers that publish their own data-protection commitments; where the law of your country requires a safeguard for sending data abroad, we rely on the one our provider offers.
Cookies and similar storage
- Needed to run the site: your sign-in session (Clerk), and small notes in your browser such as your cookie choice and whether you closed the feedback button. These do not need consent.
- Analytics (only if you accept): Google Analytics and PostHog set identifiers that let them count visits and see which pages are used. PostHog also records how the page is used — clicks, scrolling, which videos are played and how far — as a session replay we watch to find what is confusing. Everything you type is hidden in those recordings, and store connection keys are blanked out. PostHog deletes replays automatically after a fixed period. Until you choose, nothing from either is loaded. Choose "No thanks" and neither runs. You can change your mind at any time with "Cookie choices" in the page footer. We never load analytics inside Shopify admin.
- We use no advertising cookies and do not build advertising profiles.
How long we keep it
One retention window governs your content: 400 days from last activity. Activity means opening, editing or sharing a project — so an account in regular use never expires. After that window a project is archived, and it is deleted 30 days after that. The clean-up runs periodically rather than at a published hour, so content can stay a little longer than the window until the next run. We do not currently send an automatic email before deletion, so if you want to keep something, download it or keep using the project. Authentication records are kept separately for 90 days.
Feedback you send signed in is deleted with your account, and with a shop if it is uninstalled and erased. Feedback sent while signed out holds nothing that identifies you and is kept for as long as it is useful. Technical logs and error reports are kept by the providers above for the short periods they set. If you uninstall the Shopify app, Shopify tells us, and we erase the shop's data when it asks us to, about two days later. If you have installed the app again by then, your videos and settings are kept.
Deletion is never silent. If we hold no email address for an account, its content is reported as skipped rather than removed without notice. Moderation records are kept without an account identifier after deletion, so we can investigate abuse reports.
Deleting your data
- Delete a single project from the studio — this removes the project and every file attached to it.
- Delete your entire account from account settings — this removes your projects, uploaded files, consent records, usage counters, unlocks and the feedback you sent while signed in.
- Or email privacy@shaewoo.com and we will do it for you.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, to withdraw a consent you gave (withdrawing does not undo what happened before), and to complain to a data protection authority. Write to privacy@shaewoo.com and we will respond within 30 days. We may need to confirm it is you first. If you are a customer of one of our merchants and want your own information removed from a merchant's catalog or video, ask the merchant; we hold that content only on their behalf.
Why we are allowed to use it
Where the law asks for a reason: to run the service you asked for (contract); to keep it secure, prevent abuse and fix faults, and to count usage against your plan (our legitimate interests); to meet legal duties such as tax and responding to lawful requests; and, for analytics cookies, your consent. Screening of text before a video is made is automatic and can refuse a request; if you think it was wrong, write to support@shaewoo.com and a person will look.
People in product photographs
Shaewoo makes product videos, not videos about people. If a product photograph you supply shows a model or any other identifiable person, you are responsible for having the right to use it in advertising, and we process it on your instructions. If you appear in a video made with Shaewoo and want it removed, email abuse@shaewoo.com or use the report link on the share page; we will act on valid requests.
Security
Traffic is encrypted in transit. Uploaded files are stored in a private bucket and are served only to you, or to people holding the link to a video you chose to publish. Share pages are excluded from search engine indexing. No system is perfectly secure, so we cannot promise that information will never be accessed without permission. If a breach affects your information in a way the law requires us to report, we will tell you and the authority concerned.
Children
The service is not for anyone under 18, and videos may not be made about minors. If we learn we hold a child's information we will delete it.
Changes to this policy
If we change this policy in a way that matters, we will say so in the product or by email before it takes effect. The date at the top shows the latest version.
Contact
privacy@shaewoo.com · 162 GNB Road, Chandmari, Assam 781007, India