Privacy Policy

Last updated: 2 May 2026 · Governing Law: Swiss Law (revDSG) + GDPR · Carbonaa SA, Genève, Switzerland

1. Information We Collect

Merchant Information

  • Business name, email, website URL
  • Carbon assessment reports and company data
  • E-commerce platform details and API keys
  • Transaction data (products sold, offsets processed)

Client Information

  • Email address (if provided during checkout)
  • Transaction data (product, CO2 offset amount, payment)
  • IP address and browser information

2. How We Use Information

We use collected information to:

  • Process carbon offset transactions
  • Generate offset certificates
  • Provide merchant intelligence and workspaces
  • Improve our service and customer experience
  • Comply with legal obligations

2a. Legal Basis for Processing (GDPR Art. 6)

Processing ActivityLegal BasisRetention
Platform access & API provisioningContract (Art. 6(1)(b))Duration + 90 days
KYC/AML identity verificationLegal obligation (Art. 6(1)(c))10 years (Swiss GwG)
Billing & invoicingContract + legal obligation10 years (Swiss OR Art. 958f)
Fraud detection & securityLegitimate interest (Art. 6(1)(f))24 months rolling
Carbon offset transaction processingContract (Art. 6(1)(b))Duration + 90 days
Marketing communicationsConsent (Art. 6(1)(a))Until consent withdrawn
Platform intelligence & improvementLegitimate interest (pseudonymised)24 months
Support ticket historyLegitimate interest (Art. 6(1)(f))3 years

3. Data Sharing & Sub-processors

We share data with the following sub-processors and partners. All transfers to non-EU/EEA countries are protected by Standard Contractual Clauses (EU Commission Decision 2021/914):

Sub-processorPurposeLocationSafeguard
Stripe Inc.Payment processingUSAEU SCCs in place
Base44 Ltd.Application platformEUEU data residency
Supabase Inc.File storageUSAEU SCCs in place
Twilio SendGridTransactional email deliveryUSAEU SCCs in place
ClimateTrade S.L.Carbon credit retirement & certificatesEU (Spain)DPA in place · Verra Registry partner

We never sell your personal data to third parties. For an up-to-date sub-processor list, contact support@carbonaa.org.

4. Data Security

We implement industry-standard security measures including encryption, secure hosting, and regular security audits. However, no method of transmission over the internet is 100% secure.

5. Your Rights (GDPR Arts. 15–22)

Under GDPR and the Swiss revDSG, you have the right to:

  • Access your personal data (Art. 15)
  • Rectification of inaccurate or incomplete data (Art. 16)
  • Erasure ("right to be forgotten") (Art. 17)
  • Restriction of processing (Art. 18)
  • Objection to processing for direct marketing or legitimate interests (Art. 21)
  • Data portability — receive your data in a structured, machine-readable format (Art. 20)
  • Opt out of marketing communications at any time
  • Lodge a complaint with the competent data protection supervisory authority

To exercise any of these rights, contact us at support@carbonaa.net or privacy@carbonaa.org.

6. Cookies

We use cookies for authentication, intelligence, and widget functionality. You can control cookies through your browser settings.

7. Data Retention

We retain merchant data for the duration of service plus 7 years for accounting purposes. Client transaction data is retained for 3 years for verification and compliance.

8. International Data Transfers

Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.

9. Children's Privacy

Our engine is not directed to individuals under 18. We do not knowingly collect data from children.

10. Changes to Privacy Policy

We may update this policy periodically. We' ll notify you of significant changes via email or workspace alert.

11. Shopify App Data Practices

Data collected via the Carbonaa Shopify app:

  • Shopify store domain — required for installation and webhook routing
  • Shopify access token — stored encrypted, used only to register webhooks and manage the Carbon Offset product in your store
  • Client email and name (from orders/create webhook) — used only to link offset certificate records; redacted on GDPR request
  • Order total and line items — used to calculate estimated CO₂ footprint and detect customer opt-in

Data NOT collected: credit card numbers, customer payment details, customer addresses beyond the Shopify order webhook, browsing behaviour.

Data retention: Client name and email are retained until a GDPR redaction request is received, after which they are replaced with "[redacted]" . Offset transaction records are retained permanently for certificate integrity and audit purposes. Shopify access tokens are deleted when the app is uninstalled.

GDPR compliance: Carbonaa handles customers/data_request, customers/redact, and shop/redact Shopify mandatory webhooks. Redaction requests are processed within 30 days. Contact: privacy@carbonaa.org

Billing notice: Carbonaa does not charge recurring Shopify subscription fees. Carbon credits are purchased separately through secure Stripe checkout as one-time transactions. There are no automatic charges.

12. Contact Us

For privacy questions or to exercise your rights, contact us at:
privacy@carbonaa.org
Carbonaa SA · Rue de la Rôtisserie 2, 1204 Genève, Switzerland
GDPR/revDSG DPO: privacy@carbonaa.org

Carbonaa

Carbon offset & compliance for industry.

Solutions

Resources

Legal

© 2026 Carbonaa SA. All rights reserved. · Geneva, Switzerland
base44
Edit with Base44