Privacy Policy
Last updated: 7 August 2026
Short version: this website has no cookies, no analytics and no trackers. The only personal data we hold is what you type into the waitlist form. We use it to email you when we open access, and for nothing else. Ask us to delete it and we will, the same week.
What this policy covers. This page is about shopmedic.ai the website and the waitlist on it. The ShopMedic AI service — the agent that will work inside your store — is not available yet. When it launches it will come with its own service agreement and data processing terms, because it involves an entirely different category of data.
1. Who is responsible
The data controller is ELROTS S.R.L., a company registered in Romania, trading as ShopMedic AI.
- Trade register number: J40/10760/11.08.2016
- Tax identification number (CUI): 36418439
- Registered office: Șos. Alexandria 100, Bl. L28, Sc. 1, Et. 9, Ap. 39, room 2, Sector 5, 051539 Bucharest, Romania
- Email: hello@shopmedic.ai
Write to that address for anything in this policy. A person reads it, not a ticketing system.
2. What we collect, and why
Only what the waitlist form sends us, plus two things the form adds automatically:
| Data | Why we have it |
|---|---|
| Your email address (required) |
To email you once, when we open access to US stores. It is the only reason the form exists. |
| Your store URL (optional) |
So we know what kind of store you run and can tell whether ShopMedic AI is a fit for it before we bother you. |
| Your answer to "what breaks most often" (optional) |
It shapes what we build next. Please don't put anything confidential in that box — it's a free-text field, not a support channel. |
| The date and time you signed up | To honour the order of the waitlist and to prove, if ever asked, when consent was given. |
| A two-letter country code | To know which markets people are signing up from, so we can decide where to open first. It's the country, not a location. |
What we deliberately do not collect
- No IP addresses. Our form receives one, like every web request does, and discards it. We never write it down.
- No cookies. This site sets none of its own — not for analytics, not for preferences, not for anything. You won't get a consent banner here because there is nothing to consent to.
- No analytics or tracking pixels. No Google Analytics, no Meta pixel, no session recording, no third-party scripts of any kind. The page loads from one server and asks nothing of anyone else.
- No name, phone number, company or payment details. The form doesn't ask, so we don't have them.
3. Our legal basis
Consent — Article 6(1)(a) GDPR. You give it by choosing to submit the form, and you can take it back at any time, which costs you one email or one click on the unsubscribe link. Withdrawing consent doesn't affect anything we did while it was valid.
4. Who else sees it
Two companies, both acting as our processors under data processing agreements:
- Cloudflare, Inc. — hosts this site and stores the waitlist itself.
- Resend (Plus Five Five, Inc.) — delivers one internal email to us when somebody joins, so a signup doesn't sit unnoticed in a database. That email contains what you typed into the form. It goes to us and nowhere else.
Both are US companies with global infrastructure, so your details may be stored or processed outside the European Economic Area. Those transfers rely on the European Commission's Standard Contractual Clauses.
Cloudflare also keeps its own short-lived edge logs for security and abuse prevention, in the same way every host does. Those are Cloudflare's, governed by its own policy, and we do not use them.
Beyond that: nobody. We do not sell, rent, share or trade your email address. We do not send it to an advertising network. We do not use it to train AI models, ours or anyone else's. If that ever changes, we will ask you first — a notice at the bottom of a page is not a way to get consent.
5. How long we keep it
The waitlist itself lives with us until whichever comes first:
- you ask us to delete it;
- you unsubscribe from the launch email;
- 24 months after we open access to US stores, at which point the waitlist has served its purpose and gets deleted.
If ShopMedic AI never launches in the US, we delete the whole list and tell you we did.
6. Your rights
Under the GDPR you can ask us to:
- Show you what we hold about you (access);
- Correct it if it's wrong (rectification);
- Delete it (erasure);
- Stop using it while a dispute is sorted out (restriction);
- Hand it over in a machine-readable file (portability);
- Object to how we're using it;
- Withdraw your consent at any time.
Email hello@shopmedic.ai. We'll act within 30 days, and usually within a few days, because the list is small and deleting a row is not hard. We won't ask you to justify the request or try to talk you out of it.
If you think we've handled your data badly, you can complain to the Romanian supervisory authority, ANSPDCP, or to the authority in your own country. We'd rather you told us first, but that's your call, not ours.
7. Security
The site is served over HTTPS only. The waitlist is stored in Cloudflare's key-value storage, reachable only by the code that writes to it and by the account owner. Access to that account is protected by two-factor authentication. No copy of the list is kept on a laptop or in a spreadsheet.
We should be straight with you: no system is perfect. If the list is ever exposed, we will tell everyone on it directly and notify the supervisory authority within 72 hours, as the law requires.
8. Automated decisions and children
We don't make automated decisions about you and we don't profile you. This site isn't aimed at children and we don't knowingly collect anything from them.
9. Changes to this policy
If we change it, the date at the top changes with it. If a change actually affects you — a new processor, a new purpose, anything that widens what we do with your address — we'll email you about it rather than leave you to notice.