Privacy Policy
Last updated: 2 May 2026 · Governing Law: Swiss Law (revDSG) + GDPR · Carbonaa SA, Genève, Switzerland
1. Information We Collect
Merchant Information
- Business name, email, website URL
- Carbon assessment reports and company data
- E-commerce platform details and API keys
- Transaction data (products sold, offsets processed)
Client Information
- Email address (if provided during checkout)
- Transaction data (product, CO2 offset amount, payment)
- IP address and browser information
2. How We Use Information
We use collected information to:
- Process carbon offset transactions
- Generate offset certificates
- Provide merchant intelligence and workspaces
- Improve our service and customer experience
- Comply with legal obligations
2a. Legal Basis for Processing (GDPR Art. 6)
| Processing Activity | Legal Basis | Retention |
|---|---|---|
| Platform access & API provisioning | Contract (Art. 6(1)(b)) | Duration + 90 days |
| KYC/AML identity verification | Legal obligation (Art. 6(1)(c)) | 10 years (Swiss GwG) |
| Billing & invoicing | Contract + legal obligation | 10 years (Swiss OR Art. 958f) |
| Fraud detection & security | Legitimate interest (Art. 6(1)(f)) | 24 months rolling |
| Carbon offset transaction processing | Contract (Art. 6(1)(b)) | Duration + 90 days |
| Marketing communications | Consent (Art. 6(1)(a)) | Until consent withdrawn |
| Platform intelligence & improvement | Legitimate interest (pseudonymised) | 24 months |
| Support ticket history | Legitimate interest (Art. 6(1)(f)) | 3 years |
3. Data Sharing & Sub-processors
We share data with the following sub-processors and partners. All transfers to non-EU/EEA countries are protected by Standard Contractual Clauses (EU Commission Decision 2021/914):
| Sub-processor | Purpose | Location | Safeguard |
|---|---|---|---|
| Stripe Inc. | Payment processing | USA | EU SCCs in place |
| Base44 Ltd. | Application platform | EU | EU data residency |
| Supabase Inc. | File storage | USA | EU SCCs in place |
| Twilio SendGrid | Transactional email delivery | USA | EU SCCs in place |
| ClimateTrade S.L. | Carbon credit retirement & certificates | EU (Spain) | DPA in place · Verra Registry partner |
We never sell your personal data to third parties. For an up-to-date sub-processor list, contact support@carbonaa.org.
4. Data Security
We implement industry-standard security measures including encryption, secure hosting, and regular security audits. However, no method of transmission over the internet is 100% secure.
5. Your Rights (GDPR Arts. 15–22)
Under GDPR and the Swiss revDSG, you have the right to:
- Access your personal data (Art. 15)
- Rectification of inaccurate or incomplete data (Art. 16)
- Erasure ("right to be forgotten") (Art. 17)
- Restriction of processing (Art. 18)
- Objection to processing for direct marketing or legitimate interests (Art. 21)
- Data portability — receive your data in a structured, machine-readable format (Art. 20)
- Opt out of marketing communications at any time
- Lodge a complaint with the competent data protection supervisory authority
To exercise any of these rights, contact us at support@carbonaa.net or privacy@carbonaa.org.
6. Cookies
We use cookies for authentication, intelligence, and widget functionality. You can control cookies through your browser settings.
7. Data Retention
We retain merchant data for the duration of service plus 7 years for accounting purposes. Client transaction data is retained for 3 years for verification and compliance.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
9. Children's Privacy
Our engine is not directed to individuals under 18. We do not knowingly collect data from children.
10. Changes to Privacy Policy
We may update this policy periodically. We' ll notify you of significant changes via email or workspace alert.
11. Shopify App Data Practices
Data collected via the Carbonaa Shopify app:
- Shopify store domain — required for installation and webhook routing
- Shopify access token — stored encrypted, used only to register webhooks and manage the Carbon Offset product in your store
- Client email and name (from orders/create webhook) — used only to link offset certificate records; redacted on GDPR request
- Order total and line items — used to calculate estimated CO₂ footprint and detect customer opt-in
Data NOT collected: credit card numbers, customer payment details, customer addresses beyond the Shopify order webhook, browsing behaviour.
Data retention: Client name and email are retained until a GDPR redaction request is received, after which they are replaced with "[redacted]" . Offset transaction records are retained permanently for certificate integrity and audit purposes. Shopify access tokens are deleted when the app is uninstalled.
GDPR compliance: Carbonaa handles customers/data_request, customers/redact, and shop/redact Shopify mandatory webhooks. Redaction requests are processed within 30 days. Contact: privacy@carbonaa.org
Billing notice: Carbonaa does not charge recurring Shopify subscription fees. Carbon credits are purchased separately through secure Stripe checkout as one-time transactions. There are no automatic charges.
12. Contact Us
For privacy questions or to exercise your rights, contact us at:
privacy@carbonaa.org
Carbonaa SA · Rue de la Rôtisserie 2, 1204 Genève, Switzerland
GDPR/revDSG DPO: privacy@carbonaa.org