Privacy Policy
This document was last updated on 6 September 2026. Please review it carefully.
Table of contents
1. Data Controller
The data controller for personal data processed through Evidio is:
O2CODE (O2C) 55 rue Grignan, 13006 Marseille, France SIREN: 941 272 577 VAT: FR12 941 272 577
For privacy inquiries, contact us through our contact form at evidio.io/contact.
2. Chrome Extension Permissions
The Evidio extension requests the permissions below. Each is listed with what it is used for, because a permission name on its own does not say what a program does with it.
• Side panel and context menu: open the Evidio panel beside the page you are on, and offer "analyse this store" from the right-click menu. • Storage, including unlimited storage: keep your preferences and a working copy of your workspace on your device, so the panel opens immediately and stays readable offline. • Tabs: know which page the panel is describing, and open a store or a result in a new tab when you ask. • Scripting: read publicly visible information from a storefront at the moment an analysis runs. The script is injected for the duration of that read only. • Offscreen document: parse the HTML collected during an analysis in an isolated document, without altering the page you are reading. • Cookies: read one technical cookie that Meta's advertising library sets on us and that is required to query it. Evidio does not read the cookies of the stores you analyse, nor those of any other site. • Google sign-in: sign you in with Google, if you choose that method. • Alarms: resume scheduled background work, such as finishing a collection already under way. • Network rules on the sites you visit: remove the header that prevents a Trustpilot review page from being displayed inside Evidio. It applies to Trustpilot review pages and to nothing else. • Access to the sites you visit: an analysis works on the storefront you are on, and Evidio cannot know its address in advance, which is why Chrome asks for this permission in its broadest form.
That last permission deserves a precise explanation. On any page you open, a script checks locally whether the page is a Shopify storefront, by looking for the markers a Shopify theme leaves in the document. On a page that is not one, the script stops there. On a storefront, the extension notes on your device the language, the currency and the review widgets it saw, so that a later analysis does not have to reopen the page. None of that leaves your device: what reaches our servers is the analysis you trigger, and nothing else.
Evidio does not request access to your browsing history, your bookmarks, your downloads or your passwords. The floating button shown on storefronts can be switched off in the extension's settings.
3. Data We Collect
We collect minimal data, strictly necessary for the service to function:
Account data (all users): • Email address (for authentication) • Name (for account identification) • Hashed password (if using email/password authentication) • Google account ID (if using Google OAuth: we do not access your Google data beyond name and email)
Usage data: • Plan type • Device identifier (a random ID generated by the extension, not linked to your hardware) • Monthly usage counters (number of analyses and contact extractions performed) • A log of the analyses you start: the address requested, its source, the moment, and whether a credit was spent (kept for twelve months)
Payment data: • Processed entirely by Stripe. We store only the Stripe customer ID. Never your card details.
Anonymous analytics: • We use Umami, a privacy-friendly analytics tool that does not use cookies and does not track personal data. We collect aggregate page views and visit counts only on our website.
Withdrawal declarations: • Full name and email address • Plan, purchase date and optional order or invoice reference • Declaration reference, submission timestamp, acknowledgement status and processing status
Research data (dashboard): • The storefronts you analyse and the public information read from them: catalogue, prices, detected applications, advertising signals and traffic estimates • Your own annotations: tags, notes, statuses, favourites, saved products and comparisons
4. Data We Do NOT Collect
This is important to understand:
• We do NOT track your browsing history or web activity. • We do NOT sell, rent, or share any personal data with third parties. • We do NOT use tracking pixels, fingerprinting, or cross-site tracking. • We do NOT access your Google account data beyond basic profile info (name, email) when using OAuth. • We do NOT collect the content of pages you visit, except for the Shopify store analysis you explicitly trigger.
5. How We Use Your Data
We use collected data exclusively for:
• Authenticating your account and validating your plan • Enforcing plan limits (monthly analysis quota, device limits) • Processing payments through Stripe • Sending transactional emails (payment receipts, account notifications and withdrawal acknowledgements) • Recording and processing consumer withdrawal declarations • Improving the service based on aggregate, anonymized usage statistics • Maintaining a shared record of public storefront information, so that a store already analysed by one account does not have to be collected again for the next. That record holds public facts about shops. It does not hold your annotations, and contributions to it carry no account identifier
We do not use your data for advertising, profiling, or any purpose beyond operating the Evidio service.
6. Data Storage and Security
Server data (accounts, usage counters) is stored on secure servers hosted in the European Union.
Research data (analysed stores, saved products, comparisons, tags and notes) is stored on the same servers, inside your workspace, and is readable only by the accounts you have given access to it. Public storefront information is additionally kept in a shared record. Each observation there carries a contributor marker derived from your account through a one-way process and a secret we hold. It exists solely to tell two contributors apart when a piece of information has to be corroborated, it is never disclosed to anyone, and only we could trace it back to you: it is pseudonymised data, not anonymous data.
We implement appropriate technical measures to protect your data, including: • Encrypted connections (HTTPS/TLS) for all communications between the extension and our servers • Hashed passwords (never stored in plain text) • Database access restricted to application services only • No direct database access from the extension
The Chrome extension keeps a working copy on your device so the panel stays usable offline. It is a copy: the dashboard your account signs into is the reference.
7. Data Retention
Account data: Retained as long as your account exists. Deleted upon account deletion request.
Usage data: Usage counters reset monthly.
Analysis log: each analysis you start is recorded with the address requested, its source, the moment and whether a credit was spent. It is what lets us answer “why was I charged” and measure what the shared record spares us. It is kept for twelve months, then deleted automatically.
Payment data: Retained by Stripe according to their data retention policy and applicable financial regulations.
Research data: Retained as long as your account exists, or until you delete it. Deleting a store removes it from your workspace on every device. Public storefront information already contributed to the shared record is not removed with it, because it describes a shop rather than a person. The contributor marker that accompanied it is detached from your account when you delete it, so those observations remain without a voice.
Withdrawal declarations: Retained only as long as necessary to process the request, comply with legal obligations and establish proof of its handling, then deleted or archived in accordance with applicable law.
8. Your Rights (GDPR)
Under the General Data Protection Regulation (GDPR), you have the following rights:
• Right of access: Request a copy of all personal data we hold about you. • Right to rectification: Request correction of inaccurate data. • Right to erasure: Request deletion of your personal data. • Right to data portability: Receive your data in a structured, machine-readable format. • Right to object: Object to processing of your data for specific purposes. • Right to restriction: Request limitation of data processing.
To exercise any of these rights, contact us through our contact form at evidio.io/contact. We will respond within 30 days.
You also have the right to lodge a complaint with the CNIL (French Data Protection Authority) at cnil.fr.
9. Cookies
The Evidio website uses minimal cookies:
• Authentication cookies: Strictly necessary for maintaining your login session. These are first-party, secure cookies. • Theme preference: Stored in your browser to remember your dark/light mode preference. • Cookie consent: Stored in your browser to remember your consent choice.
We use Umami for analytics, which does not use cookies and is fully GDPR-compliant.
The Evidio Chrome extension does not use cookies.
10. Third-Party Services
We use the following third-party services:
• Stripe (stripe.com): Payment processing. Subject to Stripe's privacy policy. • Google OAuth (google.com): Optional authentication. Subject to Google's privacy policy. We only access your name and email. • Umami (umami.is): Privacy-friendly website analytics. No personal data collected.
We do not share your personal data with any other third parties.
11. Chrome Web Store Compliance
The use of information received from Google APIs by Evidio adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Specifically: • We only use data for the single purpose of providing the Evidio competitive intelligence service. • We do not transfer data to third parties except as necessary to provide the service (Stripe for payments). • We do not use data for advertising or to determine creditworthiness. • We do not sell user data to data brokers or information resellers. • All data transmissions use encrypted connections (HTTPS).
12. Children's Privacy
Evidio is not intended for use by individuals under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us immediately.
13. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date. For material changes, we will notify users via email.
Continued use of the service after changes constitutes acceptance of the updated policy.
14. Contact
For privacy-related inquiries, please contact us through our contact form at evidio.io/contact.
O2CODE (O2C) 55 rue Grignan, 13006 Marseille, France SIREN: 941 272 577
Last updated: 6 September 2026
O2CODE (O2C) — SIREN 941 272 577 — Marseille, France