Legal
Last updated: March 4, 2026
We built Ocean for businesses and agencies who take their Shopify stores seriously. This policy explains exactly what data we collect, why, and how you can control it.
Ocean is a visual Shopify theme editor for merchants and agencies, available at oceaneditor.com. The service is operated by a company registered in Romania (EU), acting as the data controller for the personal data described in this policy.
As an EU-registered entity, we are subject to the General Data Protection Regulation (GDPR) and supervised by Romania's data protection authority, ANSPDCP.
For any privacy-related requests or legal correspondence, contact us at support@oceaneditor.com. We will provide full registered company details upon request for legitimate legal purposes.
We only collect data that is necessary to provide the service. Here is what we collect and where it comes from:
Under GDPR, we must have a lawful basis for every processing activity. Here is what we do with your data and why:
Where we rely on legitimate interest (Art. 6.1.f), we have determined that our interest in operating a secure, improving product does not override your rights — particularly because: (a) we are a B2B service, so users are business professionals with a reasonable expectation that the tools they use to run their business collect operational data; (b) we limit collection to what is necessary; and (c) you can object at any time by contacting us.
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Contract performance (6.1.b) |
| Syncing and editing your Shopify theme files | Contract performance (6.1.b) |
| Sending transactional emails (verification, invites, password reset) | Contract performance (6.1.b) |
| Processing subscription payments via Lemon Squeezy | Contract performance (6.1.b) |
| Security monitoring and audit logging | Legitimate interest (6.1.f) — protecting our platform and users |
| Product analytics within the authenticated editor | Legitimate interest (6.1.f) — understanding how the product is used to improve it |
| Analytics on the marketing website | Consent (6.1.a) — collected via cookie banner |
| Retaining billing records | Legal obligation (6.1.c) — financial records retained 7 years |
Some of our processors are based outside the European Economic Area (EEA). Where this is the case, we rely on appropriate safeguards:
You can request a copy of the applicable transfer mechanisms by contacting us at support@oceaneditor.com.
| Data type | Retention period |
|---|---|
| Account profile (name, email, photo) | For the duration of your account. Deleted within 30 days of account deletion. |
| Shopify store tokens and data | Deleted within 30 days of account or store disconnection. |
| AI conversation history (server-side) | Retained while your account is active. Deleted within 30 days of account deletion. |
| AI conversation history (browser cache) | 14-day TTL in your browser's local storage. Cleared when you clear browser data. |
| Security event logs (IP, user agent) | 1 year, then deleted. |
| Billing and subscription records | 7 years from the date of the transaction (legal obligation). |
| Analytics data | 1 year, then anonymized. |
| Waitlist email | Until you unsubscribe or 3 years of inactivity. |
As an EU data subject, you have the following rights. To exercise any of them, email support@oceaneditor.com. We will respond within 30 days.
You also have the right to lodge a complaint with Romania's supervisory authority: ANSPDCP — Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal.
We use HTTP-only session cookies issued by Supabase to keep you signed in. These are essential to provide the service and do not require your consent.
On our marketing website, we use PostHog and Vercel Analytics to understand traffic and improve the site. These require your consent and are only initialized after you accept via our cookie banner.
Inside the authenticated editor, we use PostHog to understand how the product is used (which features are used, where users get stuck). This is based on legitimate interest and is disclosed here.
We also use Vercel Speed Insights to monitor Core Web Vitals. This collects anonymous performance metrics only.
We do not use advertising networks, retargeting pixels, or social media tracking cookies.
Analytics on our public marketing site (oceaneditor.com) requires your consent. We rely on consent as the legal basis for analytics cookies placed before you sign in.
Inside the authenticated editor, analytics are collected under legitimate interest — you have an established business relationship with us and a reasonable expectation that a professional SaaS tool monitors usage to improve the product.
You may block analytics cookies at any time using your browser settings without affecting core product functionality.
Ocean's AI editor features are powered by Google Gemini. When you use AI in the editor:
Important: Do not include sensitive personal data of your customers or third parties in AI prompts. Theme code and store configuration are appropriate inputs; customer PII is not.
Google's processing of data via the Gemini API is governed by their Data Processing Addendum and Standard Contractual Clauses.
We take reasonable technical and organizational measures to protect your data:
No system is 100% secure. If you believe your account has been compromised, contact us immediately at support@oceaneditor.com.
We may update this policy as our product and legal obligations evolve. For material changes, we will notify you by email at least 14 days before the change takes effect.
The "Last updated" date at the top of this page reflects when the current version was published. Continued use of Ocean after a change takes effect constitutes acceptance of the updated policy.
For any questions, requests, or complaints about this policy:
To lodge a complaint with Romania's supervisory authority: www.dataprotection.ro