This policy explains how Noaya (the "Service") collects, uses, protects and shares the personal and business data of its users (the "Merchants") and connected integrations (Shopify, Google Ads, Meta Ads, Google Analytics, etc.). It complies with the GDPR and the Google API Services User Data Policy.
1. Data controller
The data controller is NILA, a French simplified joint-stock company (SASU) with a share capital of €25,000, registered with the Nantes Trade Register under SIREN 953 774 569, headquartered at 49 rue de Racapé, 44300 Nantes, France, represented by its president Nadya Jahan, operating the service under the Noaya brand.
General contact: hello@noaya.app. Dedicated data protection contact: privacy@noaya.app.
To exercise your rights or report a security incident, write to privacy@noaya.app. Response within 30 days.
2. Data collected
Account data
- Email, first name, last name (account creation)
- Organization name, business sector
- Hashed password (never stored in plain text)
Data from connected integrations
When you connect an external service via OAuth, Noaya imports and stores only the data necessary for its AI agents to work. Each scope is tied to a single purpose.
- Shopify (read-only). Scopes
read_orders,read_products,read_inventory,read_locations,read_customers. Purpose: sales dashboards, product analysis, stock tracking, customer segmentation for the Track, Plan, Build and Convert agents. Shopify Protected Customer Data compliance applied: at-rest and in-transit encryption, Postgres RLS, access logging, retention limited to the contract term plus 30 days. Noread_all_orders: Noaya is limited to the last 60 days of orders, enough for daily briefs and 90% of Track analyses. - Meta Ads (read-only). Scope
ads_read. Purpose: campaign insights for the Attract agent. Data transferred to the United States (Meta Platforms) under the EU-US Data Privacy Framework and Standard Contractual Clauses. Deletion instructions: privacy@noaya.app or by disconnecting the integration from your dashboard. - Google Ads (read-only). Scope
https://www.googleapis.com/auth/adwordsused exclusively for reading via GAQL queries. Purpose: campaign reporting for Attract. - Google Analytics 4 (read-only). Scope
https://www.googleapis.com/auth/analytics.readonly. Purpose: sessions, conversions and attribution for Track and Convert. - Google Calendar (read-only). Scope
https://www.googleapis.com/auth/calendar.readonly. Purpose: contextualize Noaya's briefs with your work calendar. - Notion (read-only). Scopes
read:database,read:page. Purpose: read product pages and internal documentation you connect to give context to the agents. - Klaviyo (read-only, API key). Purpose: email performance for Keep. The key is stored encrypted, never logged.
- Triple Whale (read-only, API key). Purpose: consolidated attribution for Track. The key is stored encrypted, never logged.
No personal data of the Merchant's end customers (buyers, prospects) is used for marketing, remarketing or training of shared AI.
Technical data
- Server logs (IP, user-agent, timestamps) - retained 30 days for security
- Strictly necessary cookies: authentication session only
3. Purposes & legal bases
- Performance of the contract - providing the Service (accounts, integrations, analyses, AI agents).
- Consent - for each external integration connection via OAuth, the Merchant explicitly consents to data access in the third-party provider's permissions screen.
- Legitimate interest - security, fraud prevention, Service improvement.
- Legal obligation - invoicing and retention of accounting records (10 years).
4. Subprocessors & transfers
Noaya relies on the following subprocessors. Every transfer outside the EU is governed by Standard Contractual Clauses (SCC) from the European Commission and, where applicable, the EU-US Data Privacy Framework (DPF).
- Vercel Inc. (web hosting), United States, DPF + SCC.
- Supabase (Postgres database + Storage), European Union (eu-west-1, Ireland).
- Anthropic (Claude LLM for the agents), United States, DPA + SCC. 30-day retention on Anthropic's side. No data is used to train the models.
- OpenAI (Voice image generation via gpt-image-1), United States, DPA + SCC. No persistent storage on OpenAI's side, no training.
- Resend (transactional emails), European Union, DPA in place.
- Stripe Payments Europe (payments), European Union (Ireland).
Noaya never sells, rents or shares any data for advertising purposes. A Merchant's data is never aggregated, cross-referenced or exposed to another Merchant.
5. Retention
- Account data: as long as your account is active. Deletion within 30 days of cancellation.
- Integration data: as long as the connection is active. Disconnection or cancellation triggers cascading deletion within 30 days.
- Logs: 30 days.
- Free audit: the email left to receive a landing-page audit is kept for 12 months at most, then automatically deleted.
- Accounting records: 10 years (French legal requirement).
6. Your rights (GDPR)
You have the following rights over your personal data:
- Access, rectification, erasure
- Restriction, objection to processing
- Portability (export of your data in a structured format)
- Withdrawal of consent at any time (disconnection of an integration)
- Complaint to the CNIL (French data protection authority)
To exercise these rights: hello@noaya.app. Response within 30 days.
7. Security
- HTTPS on all communications
- Integration tokens encrypted at rest
- Row-Level Security (RLS) on the Postgres database: strict isolation per organization
- Authentication: hashed passwords (bcrypt), httpOnly sessions
- No human read access to Merchant data without an explicit request (support)
8. Cookies
Noaya uses no third-party advertising or analytics tracking cookies. Only strictly necessary cookies are set:
session- authentication (duration: 30 days)- Temporary OAuth cookies during connection flows (duration: 10 minutes)
9. Google API Services compliance (Limited Use)
Noaya's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. This applies to the scopes https://www.googleapis.com/auth/adwords, https://www.googleapis.com/auth/analytics.readonly and https://www.googleapis.com/auth/calendar.readonly. Concretely:
- Google Ads, GA4 and Calendar data are used only to provide or improve features visible to the Merchant.
- No personalized advertising is derived from this data.
- No transfer to a third party, except technical subprocessors listed in §4.
- No human reading, except with explicit consent, for security, or legal obligation.
- Data is never used to train general-purpose AI models.
9 bis. Meta Platform compliance (Data Use)
Noaya uses the Meta Marketing API (scope ads_read) only to aggregate the Merchant's advertising insights in the Attract agent. No re-identification, no ad targeting, no cross-referencing between Merchants. Meta data deletion instructions: privacy@noaya.app (response within 30 days) or by disconnecting the integration in your dashboard, which triggers cascading deletion within 30 days.
9 ter. Shopify Protected Customer Data compliance
For Shopify scopes read_orders and read_customers, Noaya applies Level 1 Protected Customer Data requirements: at-rest and in-transit encryption, Postgres RLS isolation per organization, admin access logging, retention aligned with the contract term plus 30 days, cascading deletion when the app is uninstalled.
10. Changes
This policy may evolve. The last updated date is shown at the top of the page. Substantial changes will be notified by email to active Merchants.
11. Contact
For any question: hello@noaya.app