Privacy Statement

Last updated: 14-08-2026

This privacy statement explains what personal data ShopReport processes, why, and what rights you have. ShopReport is a dashboard for online store owners who connect their Magento or WooCommerce store to see orders, inventory, and analytics in one place.

1. Who is responsible?

Data controller: 3webapps B.V., registered with the Dutch Chamber of Commerce (KVK) under number 61834890, located at Regulusweg 5, 2516 AC The Hague, the Netherlands. For privacy questions: [email protected].

2. What data we process

We distinguish three categories:

3. The Claude/MCP connector

ShopReport offers an optional connector that makes orders, products, and statistics available to Claude (Anthropic) via the Model Context Protocol. This only happens if you activate it yourself — either through an access token you create, or through an OAuth connection that you explicitly approve and for which you choose which shop is granted access.

When the connector is active, ShopReport only shares with Anthropic the data needed to answer the question you (or your AI assistant) asked — for example order overviews, product lists, or revenue figures for the connected shop, limited to what your subscription allows. No password, payment detail, or API key is ever shared. You can revoke the connection at any time via Settings → Connections or, for admins, via the admin panel.

For how Anthropic subsequently processes this data, please refer to Anthropic's privacy policy.

4. Why we process this data

5. Who we share data with

We never sell personal data to third parties.

6. Retention period

We retain data for as long as your account is active. After cancellation, we retain account data for a maximum of 90 days in case of reactivation and to meet statutory retention obligations (including tax retention periods for invoicing data), after which it is deleted or anonymized.

7. Security

Sensitive fields (API tokens, OAuth tokens, API keys) are stored encrypted. Connections run over TLS. Access to admin functions is restricted and logged in an audit log. We offer two-factor authentication for accounts.

8. Cookies

We use functional cookies to keep you logged in (session) and to prevent CSRF attacks. On our public website we place two first-party cookies (_vuid, _vsid) to measure aggregated visitor traffic — these do not contain personal data and are not shared with third parties.

9. Your rights

Under the GDPR you have the right to:

You can exercise these rights via [email protected]. You also have the right to file a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).

10. Changes

We may amend this privacy statement. In the event of material changes, we will inform active users by email or via a notification in the dashboard.

11. Contact

Questions about this privacy statement? Email [email protected] or use the contact form.