Privacy Policy
Effective Date: July 19, 2026 Version: 2.0.0
1. Introduction
This Privacy Policy explains how SetRoasFlow ("SetRoasFlow", "we", "our", or the "Operator") collects, uses, stores, shares and protects Personal Data when providing the SetRoasFlow platform and related services.
SetRoasFlow is a privacy-first Customer Data Platform (CDP) designed for ecommerce businesses. The platform enables merchants to collect, process, enrich and route customer events from their digital properties to third-party advertising, analytics and marketing platforms through secure server-side infrastructure.
This Privacy Policy applies to:
- the SetRoasFlow website;
- merchant accounts;
- the SetRoasFlow dashboard;
- APIs;
- the SmartScript;
- official platform integrations;
- plugins;
- software development kits (SDKs);
- any other services provided under the SetRoasFlow brand.
This Privacy Policy does not replace the privacy policies published by merchants using SetRoasFlow. Merchants remain responsible for informing their own customers about how their Personal Data is collected and processed.
2. About the Operator
During the beta phase, the SetRoasFlow platform is operated by:
Matteo De Giuseppe Italy
Throughout this Privacy Policy, references to "SetRoasFlow", "Operator", "we", "our" and "us" refer to the individual operating the platform.
If the ownership or legal structure of SetRoasFlow changes in the future, this Privacy Policy will be updated accordingly without affecting the rights granted to users under applicable law.
3. Scope
This Privacy Policy governs the processing of Personal Data in connection with:
- the SetRoasFlow website;
- merchant registration;
- account administration;
- customer support;
- operation of the Customer Data Platform;
- server-side event processing;
- customer profile management;
- audience synchronization;
- integrations with merchant-selected destinations;
- platform security;
- fraud prevention;
- legal compliance.
This Privacy Policy applies regardless of how a merchant connects to SetRoasFlow, including through:
- the SetRoasFlow SmartScript;
- official ecommerce plugins;
- supported APIs;
- SDKs;
- custom integrations;
- future integration methods officially supported by SetRoasFlow.
4. Definitions
For the purposes of this Privacy Policy:
Connected Property means any website, ecommerce store, mobile application or other digital property connected to the SetRoasFlow platform.
Collection Method means any supported mechanism used to transmit data to SetRoasFlow, including the SmartScript, official plugins, APIs, SDKs and future supported integrations.
Destination means any third-party service selected and configured by the Merchant to receive events, conversions, customer audiences or other information processed by SetRoasFlow.
Customer Profile means the structured representation of a customer generated by SetRoasFlow through identity resolution, event processing and data enrichment according to Merchant instructions.
Merchant means the business or organization using the SetRoasFlow platform.
Merchant Customer Data means Personal Data processed by SetRoasFlow solely on behalf of a Merchant in connection with the Services.
Personal Data means any information relating to an identified or identifiable natural person, as defined by applicable privacy laws.
5. Our Privacy Roles
SetRoasFlow performs different privacy roles depending on the context in which Personal Data is processed.
When SetRoasFlow acts as a Controller
SetRoasFlow acts as an independent Controller for Personal Data relating to:
- account registration;
- authentication;
- account administration;
- billing (when applicable);
- customer support;
- communications;
- platform security;
- fraud prevention;
- operation of the SetRoasFlow website;
- compliance with legal obligations.
In these situations, SetRoasFlow determines the purposes and means of processing.
When SetRoasFlow acts as a Processor
For Merchant Customer Data processed through the Customer Data Platform, SetRoasFlow generally acts as a Processor (or equivalent role under applicable law) on behalf of the Merchant.
In this capacity, SetRoasFlow processes Personal Data exclusively according to the Merchant's documented instructions and applicable law.
The Merchant remains responsible for:
- determining the purposes of processing;
- establishing a lawful basis for processing;
- obtaining any required consent;
- responding to data subject requests where required by law;
- ensuring that Personal Data transmitted to SetRoasFlow complies with applicable privacy legislation.
6. Categories of Personal Data
The categories of Personal Data processed by SetRoasFlow depend on the Services used, the Merchant's configuration and the Collection Methods implemented.
6.1 Account Information
When creating or managing a SetRoasFlow account, we may process information including:
- name;
- business name;
- email address;
- authentication credentials;
- account preferences;
- subscription information;
- communication preferences;
- support requests.
This information is processed by SetRoasFlow as an independent Controller.
6.2 Merchant Customer Data
When providing the Customer Data Platform, SetRoasFlow processes Personal Data on behalf of Merchants.
Depending on the Merchant's implementation, this may include:
- customer identifiers;
- email address;
- telephone number;
- customer identifiers generated by Connected Properties;
- browser identifiers;
- device identifiers;
- IP address;
- purchase information;
- transaction values;
- order identifiers;
- product information;
- event timestamps;
- attribution identifiers;
- consent signals;
- technical metadata.
The specific categories transmitted to SetRoasFlow are determined by the Merchant and the Collection Methods they implement.
6.3 Customer Profiles
As instructed by the Merchant, SetRoasFlow may generate Customer Profiles by processing events received from Connected Properties.
Customer Profiles may include:
- unique internal customer identifier;
- purchase history;
- lifetime value;
- average order value;
- order frequency;
- first purchase date;
- latest purchase date;
- repeat customer status;
- customer segmentation;
- audience memberships;
- attribution history;
- event history.
Customer Profiles are created solely for the Merchant's benefit and are not used by SetRoasFlow for its own advertising or marketing purposes.
6.4 Technical Information
SetRoasFlow may process technical information necessary to operate the Services, including:
- IP addresses;
- browser information;
- operating system;
- language settings;
- time zone;
- HTTP headers;
- device characteristics;
- network information;
- diagnostic information;
- platform logs;
- API request metadata.
Technical information is used for platform functionality, security, fraud prevention, diagnostics and service improvement.
7. How We Collect Information
Information may be collected through one or more Collection Methods depending on the Merchant's implementation.
Collection Methods currently supported include:
- the SetRoasFlow SmartScript;
- official ecommerce plugins;
- server-side APIs;
- webhooks;
- SDKs;
- custom integrations approved by SetRoasFlow.
Additional Collection Methods may be introduced in future versions of the Services.
7.1 SmartScript
The SetRoasFlow SmartScript is a JavaScript library that allows Connected Properties to transmit events to the SetRoasFlow platform.
Depending on Merchant configuration and applicable consent requirements, the SmartScript may collect:
- page views;
- user interactions;
- ecommerce events;
- browser identifiers;
- consent status;
- attribution parameters;
- technical metadata.
The SmartScript operates according to Merchant configuration and applicable privacy requirements.
7.2 Official Integrations
SetRoasFlow provides official integrations for supported ecommerce platforms.
These integrations may receive information from the connected platform, including ecommerce events, order information, customer identifiers and configuration data necessary to provide the Services.
Each integration operates using the permissions explicitly granted by the Merchant during installation.
7.3 APIs
Merchants may transmit information directly through supported APIs.
API integrations remain under the Merchant's control and must only transmit information that the Merchant is authorized to process.
7.4 Webhooks
Certain Collection Methods rely on webhooks generated by ecommerce platforms or Connected Properties.
Webhook events are used to improve reliability, validate transactions and synchronize customer information.
Webhook authenticity is verified before processing.
8. Identity Resolution and Customer Profiles
One of the primary purposes of SetRoasFlow is to assist Merchants in building accurate first-party customer records.
To accomplish this, SetRoasFlow may associate multiple events originating from the same individual into a unified Customer Profile using identifiers supplied by the Merchant or generated through supported Collection Methods.
Identity resolution may combine information originating from:
- browser events;
- server-side events;
- ecommerce transactions;
- authenticated customer sessions;
- consented customer identifiers;
- first-party cookies;
- platform integrations.
Identity resolution is performed solely to provide the Services requested by the Merchant.
SetRoasFlow does not independently use Customer Profiles for advertising, profiling or commercial purposes unrelated to providing the Services.
9. Collection Methods
SetRoasFlow is designed to support multiple methods of event collection.
Supported Collection Methods may include:
- SmartScript;
- ecommerce plugins;
- APIs;
- SDKs;
- server-side integrations;
- webhooks;
- future integration technologies.
The availability of specific Collection Methods may change over time as the platform evolves.
10. Merchant-selected Destinations
Merchants may choose to connect SetRoasFlow with third-party advertising, analytics or marketing platforms.
Examples include:
- Meta;
- Google;
- TikTok;
- Pinterest;
- Snapchat;
- Reddit;
- Klaviyo;
- other supported destinations.
SetRoasFlow only transmits information to Destinations that have been explicitly configured by the Merchant.
The Merchant remains responsible for determining whether it has an appropriate legal basis for transmitting Personal Data to those Destinations.
SetRoasFlow does not independently select advertising or marketing recipients on behalf of Merchants.
11. How We Use Personal Data
SetRoasFlow processes Personal Data only for purposes that are necessary to provide, secure and improve the Services requested by the Merchant or to operate the SetRoasFlow platform.
Depending on the context, Personal Data may be processed for one or more of the following purposes:
- providing the Customer Data Platform;
- receiving and processing events from Connected Properties;
- resolving customer identities across multiple events;
- generating Customer Profiles;
- calculating customer metrics, including lifetime value, purchase frequency and average order value;
- creating Merchant-defined customer segments;
- synchronizing audiences with Merchant-selected Destinations;
- transmitting conversion events to third-party platforms;
- monitoring event delivery and processing status;
- providing reporting and analytics;
- authenticating users and securing Merchant accounts;
- detecting fraud, abuse and unauthorized access;
- maintaining platform reliability and availability;
- complying with applicable legal obligations.
SetRoasFlow does not sell Merchant Customer Data.
SetRoasFlow does not use Merchant Customer Data to build advertising profiles for its own benefit.
12. Privacy-First Processing
Privacy has been incorporated into the design of SetRoasFlow from the beginning.
The platform is designed to minimize unnecessary collection, storage and disclosure of Personal Data while allowing Merchants to operate effective server-side measurement and customer engagement workflows.
Core privacy principles include:
- data minimization;
- purpose limitation;
- least-privilege access;
- privacy by design;
- secure-by-default infrastructure;
- Merchant-controlled processing;
- consent-aware processing;
- cryptographic protection of identifiers where appropriate.
13. Hashing of Personal Identifiers
Where supported by a Destination or required by the Merchant's configuration, SetRoasFlow normalizes and cryptographically hashes personal identifiers before transmitting them to third-party platforms.
Identifiers that may be hashed include:
- email addresses;
- telephone numbers;
- other supported identifiers.
Hashing currently uses the SHA-256 algorithm or another industry-standard algorithm where required by an integrated Destination.
Hashing reduces the exposure of plaintext identifiers during transmission but does not eliminate the possibility that hashed identifiers may still constitute Personal Data under applicable privacy laws.
Accordingly, SetRoasFlow treats hashed identifiers with the same level of protection as other Personal Data.
Certain technical identifiers — in particular the IP address and browser User-Agent — may be transmitted to advertising Destinations in non-hashed form where the receiving platform requires them for event matching and fraud prevention through its server-side (Conversions) API. Where the end user has not provided consent or has opted out, these identifiers are removed or anonymized before any transmission occurs.
14. Consent Management
SetRoasFlow is designed to respect the privacy choices made by end users.
For Merchant Customer Data, consent collection remains the responsibility of the Merchant.
SetRoasFlow does not provide legal advice regarding whether consent is required under applicable law.
Instead, the platform processes consent signals received from the Connected Property and applies the Merchant's configuration during event processing.
Depending on the applicable jurisdiction and Merchant configuration, SetRoasFlow may:
- process events only after consent has been obtained;
- suppress certain identifiers;
- disable transmission to selected Destinations;
- apply destination-specific privacy controls;
- prevent event dispatch when required consent is unavailable.
15. International Processing
The SetRoasFlow platform operates using infrastructure and service providers that may process information in multiple jurisdictions.
Merchant-selected Destinations may also process information outside the country in which the data originated.
Where applicable, SetRoasFlow implements appropriate safeguards intended to protect Personal Data during international transfers.
Merchants remain responsible for evaluating whether their own use of specific Destinations complies with applicable privacy laws.
16. Sharing of Personal Data
SetRoasFlow shares Personal Data only where necessary to provide the Services, comply with legal obligations or upon the Merchant's documented instructions.
Categories of recipients may include:
Infrastructure Providers
Trusted service providers that host or operate parts of the platform infrastructure.
Examples include cloud hosting, databases, networking services and infrastructure security providers.
Merchant-selected Destinations
Advertising, analytics and marketing platforms explicitly connected by the Merchant.
SetRoasFlow transmits information only to Destinations that have been configured by the Merchant.
Examples may include advertising platforms, analytics services, customer engagement tools and email marketing providers.
Professional Advisors
Where necessary, Personal Data may be disclosed to legal, accounting or professional advisors subject to confidentiality obligations.
Competent Authorities
SetRoasFlow may disclose Personal Data where required by applicable law, judicial order or lawful request from competent public authorities.
Whenever legally permitted, we will seek to limit the scope of such disclosures.
17. Data Minimization
SetRoasFlow is designed to process only the Personal Data reasonably necessary to provide the requested Services.
Merchants should avoid transmitting information that is unrelated to the intended purposes of processing.
Unless explicitly required by a supported integration, Merchants should not transmit:
- payment card information;
- government-issued identification numbers;
- health information;
- biometric information;
- special categories of Personal Data under applicable law;
- any other information that is unnecessary for conversion measurement, customer analytics or audience activation.
If such information is inadvertently received, SetRoasFlow reserves the right to delete or anonymize it where reasonably practicable.
18. Data Retention
SetRoasFlow retains Personal Data only for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements and maintain the security of the platform.
Retention periods vary depending on the category of information being processed.
Account Information
Account information is retained for the duration of the Merchant relationship and for a reasonable period thereafter where necessary for legal, accounting, tax or security purposes.
Merchant Customer Data
Merchant Customer Data is retained according to the Merchant's instructions, the applicable subscription features and the Data Retention Policy.
Merchants may request deletion of their Customer Data, subject to applicable legal obligations.
Customer Profiles
Customer Profiles are retained only while necessary to provide the Customer Data Platform and associated Services.
SetRoasFlow periodically reviews stored information and may delete or anonymize data that is no longer required.
Operational Logs
Operational and diagnostic logs are retained only for the period reasonably necessary to:
- maintain platform security;
- investigate incidents;
- diagnose technical problems;
- improve service reliability.
Logs are not retained indefinitely.
19. Security Measures
Protecting Personal Data is a core design principle of SetRoasFlow.
The platform implements technical and organizational measures intended to protect Personal Data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure and unauthorized access.
Depending on the Service, these measures may include:
- encrypted communications using TLS;
- secure infrastructure hosted by trusted providers;
- server-side processing;
- cryptographic hashing of supported identifiers before transmission to compatible Destinations;
- role-based access controls;
- authentication mechanisms;
- infrastructure monitoring;
- audit logging;
- webhook signature verification;
- secret management;
- regular software updates.
Although SetRoasFlow implements appropriate safeguards, no method of transmission or storage can be guaranteed to be completely secure.
20. Cookies and Similar Technologies
SetRoasFlow uses cookies and similar technologies on its own website and platform where necessary to:
- authenticate users;
- maintain secure sessions;
- remember preferences;
- improve website functionality;
- protect against fraud and abuse;
- measure website performance.
Certain Collection Methods used by Merchants may also rely on first-party cookies or similar technologies within Connected Properties.
The use of cookies on Merchant-operated websites remains the responsibility of the respective Merchant.
Additional information is available in the SetRoasFlow Cookie Policy.
21. Your Privacy Rights
Depending on your jurisdiction and the context in which SetRoasFlow processes your Personal Data, you may have rights including:
- the right to access your Personal Data;
- the right to request correction of inaccurate information;
- the right to request deletion;
- the right to restrict processing;
- the right to object to certain processing activities;
- the right to data portability;
- the right to withdraw consent where processing relies on consent;
- the right to lodge a complaint with a competent supervisory authority where applicable.
Merchant Customer Data
Where SetRoasFlow processes Personal Data solely on behalf of a Merchant, requests relating to Merchant Customer Data should generally be directed to the relevant Merchant, who acts as the Controller of that information.
SetRoasFlow will reasonably assist Merchants in responding to valid requests where required by applicable law or contractual obligations.
22. Children's Privacy
The Services are intended for businesses and are not directed to children.
SetRoasFlow does not knowingly collect Personal Data directly from children through its own website.
Merchants are responsible for ensuring that their own Connected Properties comply with applicable laws relating to children's privacy.
If we become aware that Personal Data has been collected in violation of applicable law, we may delete such information where reasonably practicable.
23. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect:
- changes to the Services;
- new platform features;
- additional integrations;
- changes in applicable law;
- security improvements;
- operational changes.
When material changes are made, we will update the "Effective Date" and the version number shown at the beginning of this document.
Where required by applicable law, additional notice may be provided.
24. Contact
Questions regarding this Privacy Policy or the processing of Personal Data may be directed to:
Operator Matteo De Giuseppe Italy
Email [email protected]
25. Related Documents
This Privacy Policy should be read together with:
- Terms of Service;
- Data Processing Addendum (DPA);
- Cookie Policy;
- Data Retention Policy;
- Security Overview;
- Subprocessors List;
- Trust Center.
Version History
| Version | Date | Description |
|---|---|---|
| 2.0.0 | July 19, 2026 | Complete rewrite reflecting SetRoasFlow as a privacy-first Customer Data Platform supporting multiple collection methods and merchant-selected destinations. |