Ripli

Legal

Privacy Policy

Last updated: 26 August 2026

This policy explains how RIPLI LTD collects, uses, stores, and protects your personal data when you use the Ripli platform and related services.

Site analytics

Choose whether Ripli can use first-party site analytics. Marketing settings are separate.

1. Data controller

The data controller is RIPLI LTD, a company registered in England and Wales (Company No. 17120779), with its registered office at 128 City Road, London, EC1V 2NX.

Contact: admin@ripli.ai

2. Data we collect

  • Account data: Name, email address, and authentication credentials when you create an account.
  • Uploaded content: Product images, logos, packaging photos, and other media you upload for AI processing.
  • Shopify app data: Shop domain, Shopify shop ID, granted app scopes, product and media IDs, selected product metadata, app installation state, Shopify billing state, and webhook delivery metadata needed to operate the embedded Shopify app.
  • Usage data: Generation history, credit usage, feature interactions, and session analytics.
  • Payment data: Processed by Stripe for direct Ripli billing and by Shopify Billing for Shopify-installed merchants. Ripli does not store your card number, CVV, or full card details on our servers.
  • Communications: Emails and support messages you send to us.
  • Business outreach data: A company name and domain, a published role-based business email address, the public source URL, relevant public product or website details, and our outreach, objection, and suppression records.
  • Optional advertising measurement: If Meta advertising measurement is enabled and you consent, limited records of eligible public page visits and approved sign-up or subscription milestones.

3. Shopify embedded app

If you install Ripli from Shopify, Shopify provides app installation and session data so the app can open inside Shopify Admin, load selected products and media, publish generated media back to products, and bill subscriptions or credit top-ups through Shopify Billing.

Ripli currently requests the narrow Shopify scopes read_products, write_products, and write_files for product access, product media updates, and file uploads. Ripli does not request protected customer data scopes such as orders or customer records for the current app experience.

Shopify privacy webhooks are processed at /api/v1/shopify/app/webhooks, including customers/data_request, customers/redact, and shop/redact. Customer data request and redaction webhook payloads are scrubbed during processing. Shop redaction removes or redacts Shopify installation data, staff user records, channel mappings, publish job records, imported Shopify media references, and Shopify billing mirrors within 30 days unless a longer retention period is required for legal, fraud-prevention, accounting, or dispute purposes.

4. Lawful bases for processing

  • Contract performance: Processing your data to provide the Ripli service, generate outputs, and manage your account.
  • Legitimate interests: Analytics, fraud prevention, service improvement, platform security, and limited relevant business-to-business outreach to corporate subscribers. We apply a purpose, necessity, and balancing assessment before relying on this basis.
  • Consent: Marketing to individual subscribers and optional communications where consent is required. You can withdraw consent at any time.

5. Business-to-business outreach

We may contact a company at a role-based business address published on its own website when the message is relevant to that company and the recipient is a corporate subscriber. Before sending, we record the public source, confirm the organisation is a separate legal entity, document why the contact is relevant, and apply a legitimate interests assessment. We do not use this route for sole traders or unincorporated partnerships unless consent or another valid permission applies.

The first message identifies Ripli, explains where the address was found, links to this policy, and provides an unsubscribe option. You may object to direct marketing at any time. We stop marketing to that address and retain only the minimum suppression record needed to honour the objection. We do not use provider open-tracking pixels in this outreach.

6. AI processing and your content

Ripli does not use your uploaded content to train AI models. Your images and media are processed solely to generate the outputs you request. Generated outputs are stored in your account and are not shared with other users or used for model training.

AI model providers process your content only to fulfil generation requests and do not retain your data for their own training purposes under our data processing agreements.

7. Third-party service providers and data recipients

  • Stripe: Payment processing. See Stripe's privacy policy.
  • Shopify: Embedded app installation, authentication, Admin API access, app billing, and mandatory privacy webhooks for Shopify-installed merchants.
  • AI model providers: Image, video, and creative generation. Providers may include OpenAI, Anthropic, Google/Gemini/Veo, Black Forest Labs/fal.ai, xAI/Grok, Qwen, Venice, Sora, and similar providers depending on the selected workflow.
  • Hosting and storage providers: Cloud infrastructure for serving the platform and storing uploaded or generated outputs.
  • Google Analytics 4:Consent-gated measurement using registered page titles, routes, events, and campaign labels. See Google's privacy policy and business data responsibility information.
  • Meta: With your explicit consent, Meta receives approved event data through the browser Pixel and server Conversions API. Meta’s role changes with the purpose and stage of processing, as described in section 8. Measurement remains off until you consent.
  • OSPEA first-party site analytics: Collection is currently disabled. Legacy analytics events, where present, are retained for no more than 90 days.

8. Optional Meta advertising measurement

With your explicit consent, Ripli uses one shared Meta Dataset and Pixel. Ripli’s purpose is to understand whether ads on Facebook and Instagram lead to the approved public activity listed below. The browser Pixel may collect eligible public activity only after consent. The server Conversions API (CAPI) may report approved milestones only after Ripli confirms them and checks that consent is still granted.

When these tools are active, Meta may use the approved event data to match activity, provide measurement and analytics, target and deliver ads, improve the effectiveness of ad delivery, personalize features, content, ads and recommendations, and provide, improve and secure Meta products. Meta may combine or aggregate event data with other information as described in its Business Tools Terms and Privacy Policy. This disclosure does not authorize Ripli to upload Customer Lists, create Custom Audiences, select audiences, or use any event outside the categories below. Those activities remain outside this phase and would require separate approval, notice, consent and controls.

On Ripli-owned surfaces, the allowed categories are page visits, new waitlist sign-ups, completed account registration or access, and first paid subscription activation. Shopify controls delivery on its App Store listing, where the categories are listing views, install clicks, and completed app installations. Ripli controls delivery on ripli.ai, its public tools, and its public Studio entry and login pages. Shopify and Ripli delivery remain separate in reporting even though they use one shared Dataset and Pixel.

Measurement is off by default. Meta browser resources, cookies, similar browser storage, and events are absent until you give explicit consent. You can withdraw consent at any time through the Analytics settings control in the site footer. Withdrawal stops later browser and server delivery and removes Ripli-owned Meta browser storage. The Conversions API is never used to bypass consent. Separately, you can use Meta Ad Preferences, including Activity information from ad partners, to control how Meta uses activity received from businesses for ads. Meta controls those settings; Ripli cannot change them for you.

For an approved page visit, Meta may receive the query-free public page address and its page category. After consent, Ripli may also use limited browser-generated Meta identifiers when they are available so Meta can connect an approved milestone to the same visit and avoid duplicate counting. Ripli’s server delivery does not include your email address, IP address, browser or device details, raw page query or referrer, workspace or shop name, prompts, uploaded or generated media, generation activity, downloads, login activity, or activity inside the authenticated Studio workspace.

For the matching, measurement and analytics services that Ripli requests, Ripli is the controller and Meta acts as Ripli’s processor. For collection and transmission through Meta Business Tools for certain advertising-related uses, Ripli and Meta act as joint controllers where applicable. After Meta receives event data and processes it for its own purposes under its terms, Meta acts as an independent controller. For UK personal data, the relevant Meta company is Meta Platforms, Inc.; for EEA personal data, it is Meta Platforms Ireland Limited. Meta’s Privacy Policy identifies the responsible Meta company for other locations. Read Meta’s Business Tools Terms. Meta’s current Business Tools Terms say it may retain event data for up to two years.

9. International data transfers

Your data may be processed outside the United Kingdom by AI model providers and cloud infrastructure services. Where transfers occur, appropriate safeguards are in place, including standard contractual clauses or adequacy decisions recognised by the UK Government.

10. Data retention

  • Account data: Retained while your account is active and for a reasonable period after closure for legal and operational purposes.
  • Uploaded content: Retained while your account is active. Deleted upon account closure unless required for legal compliance.
  • Generated outputs: Retained while your account is active. Available for download during your subscription period.
  • Shopify app data: Retained while the app is installed and redacted or deleted after Shopify privacy webhooks, uninstall, or written deletion request, subject to the 30-day Shopify privacy webhook window and legal/accounting retention needs.
  • Payment records: Retained as required by UK tax and accounting regulations (typically 6 years).
  • Business outreach data: Reviewed routinely and deleted or anonymised when it is no longer relevant. If you object or unsubscribe, we retain a minimal suppression record so we do not contact you again.
  • Google Analytics 4:Event-level data is retained for 2 months and user-level data for up to 14 months, with user retention reset on new activity. See Google's data-retention documentation.
  • Legacy OSPEA analytics events: Collection is currently disabled; existing events are deleted after no more than 90 days.

11. Your rights

Under UK GDPR, you have the right to:

  • Access: Request a copy of the personal data we hold about you.
  • Rectification: Request correction of inaccurate personal data.
  • Erasure: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request your data in a structured, commonly used, machine-readable format.
  • Objection: Object to processing based on legitimate interests. Your right to object to direct marketing is absolute, and we will stop that processing.
  • Restriction: Request restricted processing in certain circumstances.

To exercise any of these rights, contact us at admin@ripli.ai. We will respond within one month.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.

12. Cookies

Ripli uses essential cookies required for the platform to function (authentication, session management). Google Analytics 4 loads only after your explicit consent. OSPEA site analytics is currently disabled and sends no script or event request from Ripli. You can withdraw GA4 consent at any time; withdrawal stops collection and removes Ripli-owned analytics cookies and storage. Analytics receives canonical page labels and validated campaign labels (utm_source, utm_medium, utm_campaign) only. We do not collect a raw URL, a raw referrer, utm_term, or utm_content: analytics receives at most the referring site's domain, never a full referrer URL. Meta's browser Pixel and related cookies or similar storage remain off by default and load only after explicit consent, as described above.

13. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated via email or a notice on the platform. The "Last updated" date at the top of this page indicates when the policy was last revised.

Contact

For any questions about this privacy policy or your data, contact:
RIPLI LTD
128 City Road, London, EC1V 2NX
admin@ripli.ai