PRIVACY POLICY
Last Updated: 5th February 2026.
1. INTRODUCTION
This Privacy Policy explains how Connily Marketing Management L.L.C ("Connily," "we," "us," or "our"), a limited liability company registered in the United Arab Emirates, collects, uses, stores, and protects your personal information when you use our platform, including our website at https://www.connily.com, our application at https://app.connily.com, our Shopify application, and any related services (collectively, the "Service").
Our registered address is:
Connily Marketing Management L.L.C
Tanvi Business Center
Dubai, United Arab Emirates
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with our data practices described in this policy, please do not use the Service.
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date above and, where appropriate, providing additional notice via email or through the Service.
2. INFORMATION WE COLLECT
Information You Provide Directly
When you create an account or use the Service, we collect information you provide, including:
- Account Information: Your name, email address, and password.
- Business Information: Your brand name, business details, and onboarding preferences you provide during setup.
- Support Communications: Any information you share when you contact us for support or provide feedback.
Information Collected Through Third-Party Integrations
When you connect third-party accounts to the Service, we access and store data necessary to provide the Service:
- Shopify: Store name, product catalogue data (product titles, descriptions, images, SKUs, pricing, inventory status, collections), order analytics and performance data, and store configuration details. We access this data through Shopify's APIs using OAuth authentication tokens. We do not access or store personal data of your end customers (shoppers).
- Instagram: Account identifiers, profile information, content you create or approve through the Service, and post performance analytics.
- Facebook: Page identifiers, profile information, content you create or approve through the Service, and post performance analytics.
We store OAuth tokens for these integrations solely for authentication purposes.
Information Collected Automatically
When you use the Service, we automatically collect:
- Usage Data: Pages visited, features used, actions taken within the Service, and interaction patterns.
- Technical Data: IP address, browser type and version, device type, operating system, and referring URLs.
- Cookie Data: Information collected through cookies and similar tracking technologies (see Section 5 below).
Payment Information
Payment details are collected and processed directly by our third-party payment processors (Stripe and Shopify Payments). We do not directly access, process, or store your full payment card details. We may receive limited transaction information such as the last four digits of your card and billing address for record-keeping purposes.
3. HOW WE USE YOUR INFORMATION
We use your information for the following purposes:
- Providing the Service: To operate, maintain, and deliver the features of the Service, including AI-powered content generation, scheduling, publishing, and analytics.
- AI Processing: To process your connected store data, analytics, and content briefs through artificial intelligence in order to generate content suggestions, recommendations, and performance insights. AI processing is performed using data you provide or that is accessed through your connected integrations.
- Account Management: To create and manage your account, process subscriptions, and handle billing through our payment processors.
- Communications: To send you service-related notifications, updates, support responses, and (where you have opted in) marketing communications via Klaviyo.
- Improvement and Analytics: To analyse usage patterns, diagnose technical issues, and improve the Service.
- Security: To detect, prevent, and address fraud, abuse, and security issues.
- Legal Compliance: To comply with applicable laws, regulations, and legal obligations.
We do not sell your personal information.
4. HOW WE SHARE YOUR INFORMATION
We share your information only in the following circumstances:
Third-Party Service Providers
We use the following third-party services that may process your data on our behalf:
- Bubble.io — Application hosting and database infrastructure
- Stripe — Payment processing
- Shopify — E-commerce integration and payment processing (for Shopify App users)
- Klaviyo — Email communications
- Google Analytics — Website analytics and usage tracking
- Meta (Facebook/Instagram) — Social media integrations and content publishing
- OpenAI — AI content generation and natural language processing
Each of these services processes data in accordance with their own privacy policies.
Legal Requirements
We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
In the event of a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your information.
5. COOKIES AND TRACKING TECHNOLOGIES
We use cookies and similar tracking technologies on our website and application.
Types of Cookies We Use
- Essential Cookies: Required for the Service to function, including session management and authentication. These cannot be disabled.
- Analytics Cookies: Used through Google Analytics to understand how visitors interact with our website, helping us improve the Service.
- Functionality Cookies: Used to remember your preferences and settings within the Service.
Managing Cookies
You can control cookies through your browser settings. Most browsers allow you to block or delete cookies. However, blocking essential cookies may prevent you from using certain features of the Service.
6. DATA STORAGE, TRANSFER, AND SECURITY
Data Storage
Your data is primarily stored on servers hosted by Bubble.io, which uses Amazon Web Services (AWS) infrastructure located in the United States.
International Data Transfers
As our servers are located in the United States and we operate from the United Arab Emirates, your data may be transferred to and processed in countries outside your country of residence, including the United States and the UAE. These countries may have data protection laws that differ from those in your jurisdiction.
For users in the European Economic Area (EEA) or United Kingdom (UK), we ensure that appropriate safeguards are in place for international transfers, such as standard contractual clauses or other legally recognised transfer mechanisms.
By using the Service, you consent to the transfer of your data to these locations as described in this policy.
Data Security
We implement reasonable technical and organisational measures to protect your personal information, including:
- Encryption of data in transit using SSL/TLS
- Secure authentication via OAuth for third-party integrations
- Access controls to limit who can access personal data
- Regular review of our data collection, storage, and processing practices
However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.
7. DATA RETENTION
We retain your personal information for as long as your account is active or as needed to provide the Service. Specifically:
- Account Data: Retained for the duration of your account and for up to 90 days after account deletion to allow for account recovery and to resolve any outstanding issues.
- Analytics and Performance Data: Retained for the duration of your account to power AI recommendations and historical reporting.
- Payment Records: Retained as required by applicable tax and financial regulations.
- Technical Logs: Retained for up to 12 months for security and troubleshooting purposes.
After the applicable retention period, we will delete or anonymise your data, unless a longer retention period is required by law.
When you uninstall the Connily Shopify app, we receive a data deletion webhook from Shopify and will delete your store data in accordance with Shopify's requirements.
8. YOUR RIGHTS
All Users
Regardless of your location, you may:
- Access your personal data by contacting us
- Update your account information through your account settings
- Delete your account by contacting us or through your account settings
- Opt out of marketing communications by using the unsubscribe link in any marketing email or by contacting us
European Economic Area and United Kingdom Users (GDPR)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure: Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: Request that we restrict the processing of your personal data.
- Right to Data Portability: Request to receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to the processing of your personal data for certain purposes, including direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
Legal Basis for Processing:
We process your personal data on the following legal bases:
- Contract: Processing necessary to perform our contract with you (providing the Service).
- Legitimate Interests: Processing necessary for our legitimate business interests, such as improving the Service, fraud prevention, and analytics.
- Consent: Where you have given consent for specific processing activities, such as marketing communications.
- Legal Obligation: Processing necessary to comply with applicable laws.
California Users (CCPA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: Request information about the categories and specific pieces of personal information we have collected, the sources, our purposes for collecting it, and the categories of third parties with whom we share it.
- Right to Delete: Request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Opt-Out: Opt out of the "sale" of your personal information. We do not sell personal information in the traditional sense, but certain data sharing activities may constitute a "sale" under the CCPA's broad definition.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
Exercising Your Rights
To exercise any of these rights, please contact us at hello@connily.com. We will respond to your request within the timeframes required by applicable law (generally within 30 days). We may need to verify your identity before processing your request.
9. CHILDREN'S PRIVACY
The Service is not intended for use by anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe we have collected information from a child, please contact us at hello@connily.com.
10. THIRD-PARTY LINKS AND SERVICES
The Service may contain links to third-party websites, services, or applications that are not operated by us. This Privacy Policy does not apply to those third-party services. We encourage you to review the privacy policies of any third-party services you access through or in connection with the Service.
11. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this policy
- Sending an email notification for significant changes
- Providing a notice within the Service
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
12. CONTACT US
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Connily Marketing Management L.L.C
Tanvi Business Center
Dubai, United Arab Emirates
Email: hello@connily.com
For data protection inquiries, complaints, or to exercise your rights, please email hello@connily.com with the subject line "Privacy Request."
If you are located in the EEA or UK and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority.

