Privacy policy

Last updated: October 9, 2026

This policy explains what personal data we process, why, who we share it with and how to use your rights. It covers the amplify.tn site, the app.amplify.tn app and the stores hosted by Amplify.

Who is responsible for your data

[raison sociale et forme juridique] ([identifiant unique RNE], [adresse du siège]) is the controller for the data of merchants, their team members and visitors to our site.

For the data of a store's customers (the people who place orders), the merchant is the controller. We process it on their behalf, following their instructions, only to run their store.

This processing follows Organic Law No. 2004-63 of 27 July 2004 on the protection of personal data.

The data we process

For merchants and their teams:

  • your account: name, email address, password (stored hashed, never in plain text);
  • your sign-ins: date, IP address and browser of each session, to keep your account safe;
  • your store: name, contact details, products, images, theme, settings, team members and their roles;
  • connections to other services: delivery company credentials, Meta Pixel and token (encrypted);
  • the assistant: your messages, the replies, and for each reply what it changed and the credits used; your feedback on replies;
  • your credit purchases: the pack, the reference and the payment status (the payment itself happens outside the platform);
  • your conversations with our support.

For store customers (on the merchant's behalf):

  • the order: name, phone, governorate, city, address, any note, the products ordered and delivery tracking;
  • the customer's history in that store only (orders placed, delivered or refused), which helps the merchant confirm orders. This history is never shared with other stores;
  • the IP address when the order is placed, used to limit abuse.

For store visitors: pages viewed, the product looked at, where the visit came from (link, campaign, social network) and the type of device. These statistics rely on a random identifier stored in the browser; we don't store the IP address, and the identifier is made unrecognisable with a key that changes every day.

For visitors to our amplify.tn site: no cookies, no analytics, no advertising.

Why we use it

  • To provide the service: create your account, run your store, process orders, hand them to carriers, compute your analytics (performance of the contract).
  • To keep the service secure: confirm email addresses, detect abuse and fraud, limit repeated requests, keep a record of our team's actions (legitimate interest).
  • To run the assistant and check the quality of its replies (performance of the contract).
  • To write to you about your account: email confirmation, forgotten password, important changes (performance of the contract).
  • To meet our legal obligations, such as accounting (legal obligation).

We don't sell your data and don't use it for advertising.

Who we share it with

We use providers that process data on our behalf, only for the needs of the service:

  • Contabo (Germany): hosting of the servers and the database;
  • Cloudflare: domain names, storage of images and backups;
  • Oxahost (Tunisia): sending the emails about your account;
  • OpenRouter (United States) and the providers of the models it serves us, first of all Anthropic (United States): the AI models behind the assistant and AI writing, which receive your messages and the relevant content of your store, without keeping it to train their models;
  • Langfuse: monitoring the quality of the assistant's replies, when it is enabled.

When the merchant turns them on, data is also sent to:

  • the delivery company they chose (Afex, First Delivery…): the recipient's name, phone and address, and the amount to collect;
  • Meta, if the merchant connects their Pixel or the Conversions API: visit and order events, with the phone number hashed, the IP address, the browser and Meta's advertising identifiers.

We may also give data to the authorities when the law requires it.

Transfers outside Tunisia

Some providers are outside Tunisia (European Union, United States). These transfers are handled in line with Law No. 2004-63 and limited to what the service needs.

How long we keep it

  • Account and store: while the account is active, then 30 days after it's closed.
  • A store's orders and customers: as long as the store exists, unless the merchant asks for deletion.
  • Detailed visit statistics: 3 months, then only anonymous totals.
  • Backups: 14 days, then they are erased.
  • Credit purchases: as long as the law requires for accounting records.

Security

Connections are encrypted (HTTPS), passwords and connected services' credentials are stored hashed or encrypted, each store sees only its own data, and our team's access is limited and logged. No system is perfectly secure: if an incident affects your data, we tell you and inform the competent authority as the law requires.

Your rights

You can access your data, have it corrected or deleted, and object to its processing on legitimate grounds. Write to us at support@amplify.tn; we answer within one month at most.

If you ordered from a store, contact the merchant first, as they are responsible for your data. We will help them answer your request.

You can also contact Tunisia's National Authority for the Protection of Personal Data (inpdp.tn).

Minors

The Amplify platform is for people aged 18 and over.

Changes

We will update this policy when the service or the law changes. For an important change, we tell you by email or in the app.

Contact us

For any question about your data: support@amplify.tn.