Privacy policy for the Sphen Shopify app.
This policy covers Sphen, an embedded Shopify admin app provided by Niccos GmbH. It explains what data the app processes when a merchant installs and uses it. Last updated: August 2026.
Controller
The controller responsible for data processing is:
Niccos GmbH
Ida-Frank-Straße 4
79206 Breisach am Rhein
Germany
Commercial register: HRB 732578
Register court: Local Court Freiburg
Sphen is provided to merchants by Niccos GmbH. Sichtbar is the technical service provider and supplies infrastructure, support and processing services to Niccos GmbH. Where Sichtbar processes personal data on documented instructions, it acts as a processor under Art. 28 GDPR and is not the merchant-facing app provider.
What the app processes
The app processes the merchant's shop data — in particular products, collections, pages, blog articles and the status of the theme embed — to run GEO/SEO audits and generate AI content suggestions. Suggestions only take effect once the merchant reviews and applies them in the app. The processing legal basis is Art. 6(1)(b) GDPR where processing is necessary to provide the app. Where personal data is processed on a merchant's documented instructions, the controller-processor obligations are governed by Art. 28 GDPR; Art. 28 GDPR is not a processing legal basis.
To generate content suggestions, Sphen uses AI language-model providers as subprocessors engaged by Sichtbar in its role as the technical processor under data-processing agreements. Product, collection, page and blog text of the shop is transmitted for generation. The current list of subprocessors, recipients and third-country transfers used by Sichtbar is maintained in the German privacy policy.
Protected customer data (pending Shopify approval, currently inactive)
For extended analytics features, the Sphen app has requested access to protected customer data from Shopify. These features remain inactive until Shopify grants approval. Planned are, first, order data (order totals, refunds, attribution of orders to optimized content) for revenue attribution — buyer names, e-mail addresses or postal addresses of end customers are not surfaced in the app — and, second, a first-party web pixel that collects storefront events such as page views and purchases solely for the respective merchant's analytics. These features involve no advertising, no cross-site tracking of storefront visitors and no sale of data.
Product analytics in the app interface (Microsoft Clarity)
To understand how the app is actually used, Sphen loads Microsoft Clarity inside its own embedded admin interface. Clarity records usage of the app screens: views of app pages, clicks, scrolling and pointer movement, screen size, browser and operating system, an approximate region derived from the IP address, and a replay of the interaction with the app interface. Heatmaps are derived from the same data. Microsoft Corporation acts as a recipient and subprocessor for this feature and processes the data in the United States. This concerns the merchant as the user of the app, not the shop's end customers: no Clarity code runs in the storefront and no storefront visitor data is collected.
Recording is active by default as soon as a merchant uses the app. It is not based on consent and nothing has to be agreed to. The merchant can switch it off at any time in the app under Settings > Integrations, in the Product analytics card. Switching it off stops the running session immediately and prevents the Clarity script from being loaded on later page loads. That choice is stored per shop on our side, so it also applies to every future visit. This is enforced in the app's own code, not by a setting in Microsoft's dashboard: the Clarity script is added to the page only after an authenticated check has confirmed that the shop in question has not switched recording off.
The legal basis is our legitimate interest in measuring and improving the interface of our own app, Art. 6(1)(f) GDPR. The balancing of interests rests on safeguards that are implemented in the app's own code rather than promised in a dashboard. First, the entire app interface is marked as masked (the data-clarity-mask attribute), so text, input values and images are replaced with placeholders in the browser before anything is transmitted: a replay shows layout and interaction, not shop, customer or order content. Second, the session-token and signature parameters that Shopify appends to the app URL (id_token, hmac, signature, session, timestamp) are removed from the visible address before the recorder is loaded, so they are not part of the recorded URLs. Third, only the merchant's use of the admin app is recorded: no Clarity code runs in the storefront and no storefront visitor is recorded. Fourth, the data is used for product analytics only, never for advertising, ad personalization, profiling or automated decisions about the merchant. Microsoft may additionally process it for its own purposes under the Clarity terms of use.
Because recording is on by default, Clarity sets the first-party cookies _clck (lifetime up to one year) and _clsk (lifetime one day) in the app frame by default, from the first use of the app, in order to recognize a returning session. Switching recording off in Settings > Integrations prevents further Clarity cookies from being set, because no Clarity code is loaded any more; cookies already stored remain in the browser until they expire and can be deleted in the browser at any time.
Merchants have the right to object to this processing at any time under Art. 21(1) GDPR. The switch in the app under Settings > Integrations is the direct way to exercise it and takes effect immediately; an objection can also be sent to kontakt@niccos.com and we will switch recording off for that shop. Recordings already collected are not deleted automatically, and we delete them on request. Microsoft is listed in the subprocessor table in the German privacy policy.
Retention and security
Attribution data derived from orders is stored for at most 12 months from the order date and then deleted automatically; raw pixel events are deleted after 30 days. Pixel session identifiers are hashed before storage. All data is encrypted in transit (TLS) and encrypted at rest by the technical hosting providers; Shopify API access tokens are additionally encrypted at the application layer. Processing runs on hosting and infrastructure subprocessors engaged by Sichtbar as the technical processor under data-processing agreements (see the German privacy policy for the provider list and third-country transfer details).
Optional Google connections
Merchants can optionally connect Google Analytics 4 via OAuth directly in the app; the app requests only the read-only Google Analytics scope (analytics.readonly), and the merchant can revoke the connection at any time. The app has no Search Console connect flow of its own: where the merchant's organization has already connected Google Search Console through the Sichtbar technical platform, the app only reads search-performance reporting data from that existing connection.
Uninstall, GDPR webhooks and deletion requests
Upon app uninstall, shop data is deleted via Shopify's GDPR redaction webhooks (shop/redact and customers/redact). Data-access requests arriving via the customers/data_request webhook are handled on behalf of Niccos GmbH within the statutory periods. Merchants can also request deletion from Niccos GmbH at kontakt@niccos.com.
Data subject rights
Under the GDPR, data subjects have the rights to access, rectification, erasure, restriction of processing, data portability and objection, as well as the right to lodge a complaint with a supervisory authority. Rights requests must be sent to Niccos GmbH at kontakt@niccos.com. Sichtbar may provide authorized technical support on Niccos GmbH's behalf. Additional information about Sichtbar's technical infrastructure, recipients and international transfers is set out in the Sichtbar technical-service privacy policy.
The app's terms of service and support pageare available separately.