Last updated: 25 August 2026
Vadour (“Vadour”, “we”, “us”) operates the analytics platform available at app.vadour.com and the related PrestaShop/WooCommerce plugins. Our data protection contact is alex at vadour.com.
| Category | What | Why (legal basis) |
|---|---|---|
| Account data | Name, email, hashed password | Contract performance |
| Billing data | Stripe customer/subscription IDs (no raw card data — Stripe holds that) | Contract performance |
| Store analytics | Order IDs, product names/prices, UTM parameters, click IDs (fbclid, gclid), device type, country (IP-derived, not stored raw) | Contract performance — you instruct us to process this data to deliver the service |
| End-customer identifiers | Customer name, email and store customer ID; hashed email (SHA-256) and device fingerprint for attribution | Contract performance — customer analytics, matching, segmentation and attribution requested by the merchant |
| AI conversations | Questions, answers, conversation summaries, tool results and diagnostic metadata; these may contain store data and customer data supplied in a question or returned by an authorised tool | Contract performance — answering merchant questions and maintaining conversation context; legitimate interest — security and reliability diagnostics |
| Usage data | Pages visited in the app, feature usage (via PostHog, anonymised), and marketing-site visits (via Google Analytics 4, consent-based) | Legitimate interest for product improvement; consent for marketing-site analytics |
| Error logs | Stack traces, request metadata (via Sentry) | Legitimate interest — service reliability |
We do not store raw payment card numbers. We may store shopper names and email addresses imported from your connected commerce or CRM systems. We do not sell or share your data with third parties for advertising.
Vadour acts as a data processoron your behalf for the analytics data belonging to your store's customers. You (the merchant) remain the data controller for that data. By using Vadour you agree to our Data Processing Agreement (DPA), available on request at alex at vadour.com.
You are responsible for informing your end customers that their order and session data is processed by Vadouras a sub-processor for analytics purposes. A suggested disclosure for your privacy policy is available on request.
Vadour's primary application database is hosted by Hetzner in Germany. Some sub-processors, including AI routing and model providers, may process requests outside the EEA. Where required, those transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism. We do not claim that every AI request remains within the EU unless an EU-only processing arrangement is expressly agreed.
| Sub-processor | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US (SCC) |
| Resend | Transactional email | US (SCC) |
| PostHog | Product analytics (anonymised) | EU (PostHog Cloud EU) |
| Google Analytics | Marketing-site traffic analytics (consent-based, IP anonymisation enabled) | US/EU (Google) |
| Sentry | Error tracking | US (SCC) |
| OpenRouter | AI request routing. Vadour requests zero-data-retention endpoints and disables provider data collection for routed requests. | Global / US (transfer safeguards apply) |
| AI model providers selected through OpenRouter (including Cerebras, Groq, Google and Anthropic) | Generate plans and answers from the question and the minimum store/tool context needed for the request. Customer identity is rendered by Vadour outside model output where supported. | Global; depends on the selected zero-data-retention endpoint |
| Google Cloud Vertex AI | Direct AI processing only when enabled by Vadour's provider configuration. Direct fallback is disabled by default. | EU region when configured; Google's global service operations may apply |
You have the right to:
To exercise any of these rights, email alex at vadour.com. We respond within 30 days. You also have the right to lodge a complaint with Spain (AEPD).
The Vadour tracking pixel placed on your store sets a first-party session cookie (vctr_sid) to enable cross-session attribution. This cookie does not track users across domains and expires after 30 days of inactivity. No third-party advertising cookies are set by the Vadour pixel.
The Vadour dashboard app uses a session authentication cookie (authjs.session-token). This is strictly necessary for the service to function and does not require consent.
We use PostHog for anonymised product analytics and Google Analytics 4 for marketing-site traffic measurement. Both are disabled until you accept analytics in our cookie banner. Google Analytics IP anonymisation is enabled.
We will notify you by email at least 14 days before any material change to this policy. Continued use of the service after that date constitutes acceptance.
alex at vadour.com