Legal
Privacy Policy
This policy explains what SONARmetrics processes when you use the website, create an account, connect a commerce service, or ask us for support—and the choices available to you.
1. Who this policy covers
SONARmetrics provides commerce analytics, reconciliation, reporting, automation, and related support services. The service and sonarmetrics.io are operated by SIXTHSENSE SRL, Romanian company registration number 48739467, registered in Cluj-Napoca, Romania. References to SONARmetrics, we, or us mean SIXTHSENSE SRL unless an order form identifies another contracting entity.
For account, website, security, and service-administration information, SONARmetrics acts as a data controller. For customer, order, advertising, fulfillment, and other business data uploaded or connected by an organization, the organization normally acts as controller and SONARmetrics acts as its processor.
Privacy questions and requests can be sent to privacy@sonarmetrics.io. General correspondence can be sent to contact@sonarmetrics.io.
2. Information we process
Account and organization information
- Name, email address, profile image, authentication identities, organization membership, role, and account-security events.
- Company country, tax and fiscal settings, reporting currency, timezone, store model, and other workspace configuration.
- Support messages, invitations, administrative actions, audit events, and communications with us.
Connected commerce and operational information
- Orders, customer and shipping details, products and variants, transactions, fulfillment events, refunds, returns, disputes, chargebacks, payout adjustments, and marketplace tax information.
- Advertising accounts, campaigns, ad groups or sets, ads, spend, delivery metrics, conversion information, attribution evidence, and—when enabled—Facebook Page posts and comments.
- Warehouse, shipment, delivery, return, cancellation, COD, and inventory information from connected fulfillment providers.
- Supplier documents, COGS, operating costs, tax assumptions, annotations, calculated profit metrics, and reconciliation history.
Technical information
- IP address, browser and device information, session identifiers, timestamps, request and error logs, webhook identifiers, and security diagnostics.
- Encrypted connector credentials, OAuth tokens, API keys, and webhook secrets supplied by an authorized organization administrator.
3. Connected services and OAuth data
SONARmetrics accesses a provider only after a user or organization administrator selects Connect, is redirected to the provider, reviews the requested permissions, and authorizes the connection. We use the resulting grant only for the features below, store provider tokens encrypted, and do not receive provider passwords or MFA codes.
| Provider | Information used | Purpose |
|---|---|---|
| Google sign-in | Google account identifier, name, verified email, and profile image. | Create, secure, and sign in to a SONARmetrics account. This does not grant Google Ads, Gmail, Drive, or other product access. |
| Google Ads | Authorized customer-account structure, campaign and ad performance, spend, conversions, and currency/timezone metadata. | Advertising reporting, attribution, annotations, and profit calculation. This is a separate organization-controlled connector from Google sign-in. |
| Shopify / WooCommerce | Store, product, order, customer, fulfillment, payment, refund, return, dispute, and related operational data. | Commerce synchronization, order conclusions, financial reconciliation, and product reporting. |
| Meta | Authorized ad accounts, campaigns, ads, insights, Pages, Page posts, comments, and permitted Page actions. | Advertising analytics and, when enabled, Facebook comment review and management. |
| TikTok | Authorized advertiser accounts, campaigns, ad groups, ads, and reporting metrics. | Advertising reporting, attribution, and change annotations. |
| Fulfillment providers | Shipments, delivery and return states, COD/payment status, cancellations, and inventory. | Operational reconciliation, COD conclusion, and stock forecasting. |
| Slack / Discord | Workspace/server identity and channels visible to the configured bot. | Deliver notifications selected by the organization. SONARmetrics does not read message history. |
SONARmetrics’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. Google data is accessed only to provide the user-visible sign-in or Google Ads features described above. It is not sold, used for advertising, transferred to data brokers, used to build unrelated profiles, or used to train generalized AI models. Human access is limited to user-requested support, security or abuse investigation, legal obligations, or operations essential to the feature.
4. How we use information
- Authenticate users, maintain organization permissions, prevent abuse, and protect accounts.
- Import, normalize, reconcile, calculate, and display the analytics and operational features requested by the organization.
- Operate webhooks and scheduled synchronization, repair incomplete imports, and maintain auditability.
- Send account, invitation, support, security, synchronization, and configured notification messages.
- Provide SonoAI explanations and optional comment-assistance features when a user or organization enables and invokes them.
- Diagnose failures, improve reliability and security, enforce our Terms, and comply with law.
We do not sell personal information. We do not use connected store customer data to independently market to those customers or build cross-customer advertising profiles.
5. Legal grounds
Where the GDPR or similar law applies, we rely on performance of our contract to create accounts and deliver requested features; legitimate interests to secure, maintain, support, and improve the service; compliance with legal obligations; and consent only where the law requires it. When we rely on consent, it may be withdrawn without affecting earlier lawful processing. Organizations are responsible for establishing the lawful basis for business data they connect to SONARmetrics and for providing required notices to their customers and staff.
6. Sharing and service providers
We disclose information only as needed to provide the service, follow an organization’s instructions, protect the service, complete a corporate transaction, or comply with law. Infrastructure and service providers include:
- Supabase for authentication and related identity infrastructure.
- Vercel, Hetzner, and Cloudflare for application hosting, networking, and domain services.
- Google Workspace for service email.
- OpenAI for explicitly invoked AI features; only the context needed for that request is sent.
- The commerce, advertising, fulfillment, and notification providers an organization chooses to connect.
Providers process information under contractual and security obligations appropriate to their role. When personal data is transferred outside the European Economic Area to a country without an adequacy decision, we use an available lawful safeguard such as the European Commission’s Standard Contractual Clauses and appropriate supplementary measures. You may contact us for information about the safeguard relevant to your data. The current infrastructure providers, purposes, and processing footprints are maintained in our Subprocessor Register.
7. Retention and deletion
Connector credentials are retained until disconnect, rotation, or organization deletion. Raw processed webhook bodies and supplier source files are normally removed after 30 days; notification deliveries, completed jobs, synchronization history, and sanitized provider diagnostics after 90 days; webhook replay envelopes and security/audit events after 365 days. Imported orders, accounting evidence, calculations, and support records are retained while the workspace is active and afterward only as required by the customer agreement, applicable accounting or legal duties, dispute resolution, or a documented legal hold.
Disconnecting a connector removes its active credentials and stops future synchronization. For Google Ads, SONARmetrics also attempts to revoke the stored Google authorization. The disconnect dialog lets the organization retain imported reporting history or queue its permanent removal.
Account deletion removes the authentication identity and personal membership data. Shared business ledgers may be anonymized rather than removed when another organization member still relies on them. Organization deletion removes its tenant workspace and connected credentials. Restricted backup copies may remain for disaster recovery and are not used for ordinary processing.
See the Data Deletion page for self-service and provider-specific instructions.
8. Security
SONARmetrics uses access controls, tenant isolation, encrypted transport, encrypted connector secrets, signed webhook verification, least-privilege service credentials, logging, backups, and administrative safeguards. No system can guarantee absolute security. Report suspected vulnerabilities to security@sonarmetrics.io.
9. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or objection, and may withdraw consent. You may lodge a complaint with the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP) or your local supervisory authority. We may need to verify identity and authority before acting.
For data originating from a merchant’s store, customers should normally contact that merchant first because it controls the data and can submit the appropriate platform request.
10. Children
SONARmetrics is a business service and is not directed to children. Users must be legally able to enter a binding agreement and authorized to act for their organization.
11. Changes and contact
We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated through the service or by email when appropriate. Questions can be sent to privacy@sonarmetrics.io; general enquiries can be sent to contact@sonarmetrics.io.