Privacy Policy
Shooopr (shpr.ai) — operated by Milk Bottle Labs Limited
1. Who we are
Shooopr (shpr.ai) is a storefront intelligence platform operated by Milk Bottle Labs Limited, a private company limited by shares registered in Ireland.
| Data controller | Milk Bottle Labs Limited |
| Company number (CRO) | 568068 |
| Registered / business address | Milk Bottle House, 8 Mount Street Upper, Dublin 2, Ireland, D02 FT59 |
| VAT number | IE3382592SH |
| Contact | hello@shpr.ai |
Milk Bottle Labs Limited is the controller of the personal data described in this policy. This policy explains what we collect, why, on what legal basis, who we share it with, and the rights you have under the General Data Protection Regulation (GDPR) and the Irish Data Protection Acts 1988–2018.
2. Scope
This policy covers the shpr.ai website, the Shooopr application, and the diagnostic services we provide through them. It applies to three distinct groups: (a) our account holders and visitors to our site, (b) the operators of online stores that are the subject of diagnostics run through the platform, and (c) people who use the free store scan without holding an account. Section 5 deals with the second group and section 6 with the third.
3. Data we collect from account holders
3.1 Account and identity data
- Name and email address, provided at registration and verified by email.
- Account type (merchant or agency) and plan tier.
- The store domain or domains you register for diagnostics.
3.2 Billing data
Payments are processed by Stripe. We do not receive or store your full card details. We receive from Stripe: your billing name and address, VAT number if supplied, the last four digits of your card, and your subscription and invoice history. Stripe acts as an independent controller for the payment data it processes; its own privacy policy applies to that processing.
3.3 Diagnostic and usage data
- Diagnostic results, Health Scores, and report history for the stores registered to your account.
- Annual revenue figures you optionally enter to enable revenue-impact estimates. These are stored against your account and never published.
- Service usage records: which diagnostics you run, when, and against which registered store.
3.4 Communications
Emails you send to us, and records of the transactional emails we send you (account verification, alerts, reports, and service notices).
4. How we use account holder data, and the legal bases
| Providing the service (running diagnostics, storing results, displaying reports) | Performance of a contract — Art. 6(1)(b) GDPR |
| Billing, VAT, invoicing, and tax compliance | Legal obligation — Art. 6(1)(c); contract — Art. 6(1)(b) |
| Account verification and service emails | Performance of a contract — Art. 6(1)(b) |
| Product and marketing emails | Consent — Art. 6(1)(a). You can withdraw consent at any time via the unsubscribe link. |
| Preventing abuse of the platform (including enforcement of domain-change restrictions) | Legitimate interests — Art. 6(1)(f): protecting the integrity of the service |
| Improving the service and diagnosing faults | Legitimate interests — Art. 6(1)(f) |
5. Data relating to third-party stores
Shooopr works from the outside in. Diagnostics are run against the publicly accessible pages of an online store — the same pages any shopper's browser would load. The platform does not install anything on the store, does not request or receive privileged access, and does not access any store's administrative systems, customer databases, or order data. Some diagnostics do interact with your public storefront as a shopper would; see the Terms for exactly what they create.
5.1 What we process
- Publicly rendered page content of storefront pages (for example the homepage, a product page, and cart page), retrieved by an automated browser.
- Publicly available technical characteristics: page performance measurements, markup structure, accessibility attributes, structured data, and similar signals.
5.1a Test data we create on your store
Test data we create on your store. When you run a diagnostic that interacts with your storefront, we enter an email address we control into your checkout or newsletter form. This creates an abandoned checkout and, for welcome-flow audits, a subscriber on your marketing list. Any email your store sends to that address is received by us, stored, and shown to you in your report. These addresses are not real customers and are used for no other purpose.
5.2 Whether this includes personal data
This material is overwhelmingly business and website data rather than personal data. However, public storefront pages can incidentally contain personal data — for example a named business owner on an about page, or customer names displayed in public product reviews. Where such data appears within retrieved page content, we process it only as an incidental part of the page, we do not extract it, index it, profile it, or use it for any purpose beyond producing the diagnostic result, and it is retained only as part of the stored diagnostic record.
5.3 Legal basis
We process publicly available storefront data on the basis of legitimate interests (Art. 6(1)(f) GDPR): providing store operators and their authorised agents with diagnostic intelligence about their own storefronts. Our terms of service require every account holder to warrant that they own, or are authorised to run diagnostics on, each store they register. We have balanced this interest against the rights of individuals whose data may incidentally appear on public pages and concluded that the processing — limited, incidental, drawn exclusively from information already published to the open web, and never used to profile individuals — does not override those rights. This section describes diagnostics run by account holders. The free store scan is run by people who do not hold an account and have not given that warranty; the basis for that processing is set out in section 6.
5.4 If your store has been the subject of a diagnostic
If you operate a store and believe it has been registered on the platform without authorisation, contact hello@shpr.ai. We will investigate, and where a breach of our terms is established we will remove the store and the associated diagnostic history and may terminate the offending account.
6. The free store scan
The free store scan at shpr.ai/scan can be used without an account. Anyone may enter a domain and receive a summary of what we can observe about it from outside.
6.1 What the scan processes
When a domain is submitted we retrieve that domain's publicly accessible homepage — the same page any browser would load — and query its public DNS records, including SPF, DKIM, DMARC and MX. This is business and technical information about a website. It is published to the open web by the domain's operator and is not, in the ordinary case, personal data. We do not log in, install anything, or access any administrative system, customer database or order data.
6.2 The person running the scan
We do not require an account, a name or an email address in order to run a scan. To keep the scan free and to prevent abuse we limit each internet connection to 20 scans in any 24-hour period. We do this by storing a one-way cryptographic hash of the IP address together with a count. We do not store the IP address itself, and the hash cannot be reversed to recover it. The legal basis is legitimate interests — Art. 6(1)(f) GDPR: protecting the availability of a free service against automated abuse.
A scan result is cached for up to seven days per domain, so that revisiting a result does not re-run the checks.
6.3 Scans of a domain you operate, run by someone else
Because no account is required, a scan may be run against a domain by someone who does not operate it — for example an agency assessing a prospective client. A scan result describes only information that the domain already publishes to the open web. We do not assert or verify any relationship between the person running a scan and the domain scanned, and a scan result is not evidence of one.
If a scan result relating to a domain you operate concerns you, contact hello@shpr.ai. We will remove the cached result and, on request, block the domain from future free scans.
6.4 If you give us your email address
After the scan has run, you may optionally give an email address to receive the full itemised result. Giving it is never required to see the headline finding, and no finding is withheld from you if you do not.
If you provide one, we store: the email address; the domain that was scanned; the date and time; the same one-way hash of the IP address described in 6.2; whether you ticked the optional monitoring box; the exact wording of the consent statement shown to you at that moment; and a token that lets you unsubscribe without signing in.
The domain that was scanned is stored alongside the address because it is what makes the report we send you specific to the store you asked about.
6.5 What we do with it, and the legal bases
- Sending you the report you asked for — performance of a contract, or steps taken at your request prior to entering one, Art. 6(1)(b) GDPR. This is a transactional email. It is sent whether or not you tick the monitoring box.
- Ongoing monitoring emails, telling you when that store's results change — consent, Art. 6(1)(a). The box is never pre-ticked, and you can withdraw consent at any time using the unsubscribe link in any email, without signing in and without contacting us.
- We do not use an address given through the free scan for any other marketing.
6.6 Who we share it with
Your email address and the scanned domain are shared with Resend, our email processor, in order to send the report and any monitoring emails you have consented to. Resend processes this data on our instructions under a data processing agreement. It is not shared with anyone else and it is never sold.
6.7 How long we keep it
Scan results are cached for seven days per domain. Rate-limiting hashes are kept for 24 hours. An email address given through the free scan is kept for 24 months from your last interaction with us, or until you unsubscribe or ask us to erase it, whichever is sooner.
6.8 Your rights
The rights described in section 11 apply in full to data collected through the free store scan, including the right to erasure and the right to object to processing based on legitimate interests. Email hello@shpr.ai.
7. Automated analysis and AI-generated summaries
Some diagnostic results include a written summary generated by a large language model (Anthropic's Claude, accessed via the Anthropic API). The input to that processing is the diagnostic output and excerpts of publicly available storefront content; account holder personal data is not included in these prompts beyond the store domain. Anthropic processes this data as our processor under its commercial terms and does not train its models on data submitted via the API. No decision producing legal or similarly significant effects on any individual is made by automated means.
8. Who we share data with
We use a small number of service providers (processors) to run the platform. Each processes data only on our instructions under a data processing agreement:
| Supabase | Database, authentication, file storage, and serverless functions (application hosting of account and diagnostic data) |
| Stripe | Payment processing, subscription billing, and VAT calculation (independent controller for payment data) |
| Browserless | Automated browser sessions used to load public storefront pages |
| GTmetrix (Carbon60) | Page performance measurement |
| Anthropic | AI-generated diagnostic summaries (API processing only) |
| Resend | Transactional and service email delivery |
| Lovable | Application build and hosting infrastructure |
| Google Workspace | Business email and internal document storage |
We do not sell personal data, and we do not share it with advertisers. We may disclose data where required by law, to enforce our terms, or in connection with a corporate transaction affecting Milk Bottle Labs Limited, in which case this policy will continue to apply to the data transferred.
9. International transfers
Some of our processors are located in, or operate infrastructure in, the United States and Canada. Where personal data is transferred outside the European Economic Area, the transfer is protected by an adequacy decision (including the EU–US Data Privacy Framework where the processor is certified) or by the European Commission's Standard Contractual Clauses, together with any supplementary measures required. Details of the mechanism applying to a specific processor are available on request.
10. How long we keep data
- Account and diagnostic data: for the life of the account. If you delete your account, personal data is deleted or irreversibly anonymised within 30 days, except where retention is legally required.
- Diagnostic history for a registered store is permanently deleted if the store's domain is changed on the account, as described in our domain-change policy.
- Billing and invoice records: retained for the period required by Irish tax law (currently six years).
- Email correspondence: retained for up to two years after the account closes, for dispute and support purposes.
- Free scan results: cached for seven days per domain. Rate-limiting hashes: 24 hours.
- Email addresses given through the free store scan: 24 months from last interaction, or until unsubscribe or erasure request.
11. Your rights
Under the GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data erased; restrict or object to processing (including any processing based on legitimate interests); receive your data in a portable format; and withdraw consent at any time where processing is based on consent. To exercise any of these rights, email hello@shpr.ai. We will respond within one month.
You also have the right to lodge a complaint with the Data Protection Commission (DPC), 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland — www.dataprotection.ie — or with the supervisory authority in your own EU member state.
12. Cookies
Our use of cookies and similar technologies is described in our Cookie Policy.
13. Security
Account data is protected by encrypted connections (TLS), encryption at rest on our database infrastructure, row-level access controls, verified-email authentication, and breached-password screening at registration. Access to production data within Milk Bottle Labs is restricted and logged. No internet service can guarantee absolute security; if we become aware of a breach affecting your personal data we will notify you and the DPC as required by Articles 33 and 34 GDPR.
14. Children
The service is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has created an account, contact hello@shpr.ai and we will delete it.
15. Changes to this policy
We may update this policy as the service evolves. Material changes will be notified by email to account holders and by a notice on the site before they take effect. The date of the current version appears at the top of this page.
16. Contact
Questions about this policy or about your personal data: hello@shpr.ai, or by post to Milk Bottle Labs Limited, Milk Bottle House, 8 Mount Street Upper, Dublin 2, Ireland, D02 FT59.