Privacy Policy
Last updated: August 5, 2026
1. Who we are
Emailer ("we", "us"), operated at where-its-at.app, provides email automation services to WooCommerce store owners ("merchants"). This policy explains what we collect and how we use it — both for merchants who hold accounts with us, and for shoppers whose data merchants process through our platform.
2. Data we collect from merchants
- Account details: email address and a securely hashed password (we never store plaintext passwords);
- Store connection details: store name, URL, and API credentials generated for the connection;
- Billing information, processed by our payment provider — card details never touch our servers;
- Operational logs needed to run and secure the service.
3. Data we process on behalf of merchants
When a merchant connects their store, we process shopper data as a processor on the merchant's behalf: email addresses, order and cart activity, and email engagement (deliveries, clicks, unsubscribes). We use this data solely to provide the service to that merchant — we never sell it, never use it for advertising, and never combine one store's customer data with another's.
4. How we protect it
- Encryption in transit everywhere; credentials and tokens stored hashed;
- Per-store data isolation enforced at the database layer;
- Suppression records stored as keyed cryptographic hashes rather than plaintext addresses;
- Access limited to what operating the service requires.
5. Your rights (GDPR and similar laws)
Shoppers can unsubscribe from any store's marketing instantly via the one-click link in every email. For access, correction, or erasure of personal data, contact the store you purchased from (the data controller), or contact us and we will assist. Erasure requests remove personal identifiers from our systems while preserving an anonymous suppression record so the address is never emailed again.
6. Data retention
Merchant account data is retained while the account is active and deleted on request after closure. Shopper event data is retained while the merchant's store is connected, subject to the merchant's own retention choices and erasure requests.
7. Subprocessors
We use Amazon Web Services (email delivery and infrastructure) and Railway (application hosting). Payment processing is handled by Stripe. Each processes data only as needed to provide their service to us.
8. Contact
Privacy questions: support@where-its-at.app. Abuse reports: abuse@where-its-at.app.