Europe SMS Marketing Privacy Policy
Effective date: 17 September 2026
Last updated: 18 September 2026
1. Who we are
Europe SMS Marketing is operated by Genius Nutrition SRL, trading as OBSEDIA ("Europe SMS Marketing", "OBSEDIA", "we", "us" or "our").
Our business details are:
- Legal entity: Genius Nutrition SRL
- Trade name: OBSEDIA
- VAT number: RO35355847
- Registered business address: Tamasi nr. 20, Buftea, Ilfov, Romania
- Privacy contact: privacy@obsedia.ai
- General contact: support@obsedia.ai
This Privacy Policy explains how we collect, use, disclose, protect and retain personal data when merchants and their authorised users access our website, install or use the Europe SMS Marketing Shopify application, contact us, or use our SMS campaign and automation services.
It also explains how Europe SMS Marketing processes personal data relating to customers and SMS recipients on behalf of merchants.
2. Scope
This Policy applies to:
- our public website and service pages;
- the Europe SMS Marketing embedded Shopify application;
- merchant onboarding, account administration, customer support and billing;
- immediate SMS campaigns and enabled SMS automations;
- SMS delivery, delivery reports, opt-out handling and campaign performance reporting;
- the limited storefront component used for eligible cart-recovery functions; and
- privacy requests and compliance operations connected with the Service.
The Service is designed for professional merchants using Shopify and for SMS delivery to supported European destinations. A destination or feature is supported only when it is shown as available in the Service.
This Policy does not govern the independent processing activities of Shopify, a merchant, a mobile network operator or another third party acting under its own privacy notice.
3. Our role and the merchant's role
3.1 When we act as controller
We act as a controller for personal data that we determine how and why to process for our own purposes. This includes data used to:
- administer merchant accounts and authorised users;
- authenticate access and maintain security;
- provide support and communicate about the Service;
- administer subscriptions, usage records and billing;
- prevent fraud, abuse and unauthorised use;
- maintain operational, security and audit records;
- comply with legal obligations and enforce our agreements; and
- improve the reliability and safety of the Service using aggregated or de-identified information.
3.2 When we act as processor
The merchant normally acts as controller for personal data relating to its customers, prospects and SMS recipients. Europe SMS Marketing acts as the merchant's processor when it receives or otherwise processes that data to provide the Service.
The merchant determines, among other matters:
- which individuals may receive a message;
- the purpose and legal basis for a campaign or automation;
- the content of the message;
- whether a message is marketing or strictly transactional;
- which Shopify segment or automation is used; and
- how the merchant responds to its customers' privacy requests.
Our Data Processing Terms are included in the Europe SMS Marketing Terms of Service. We process merchant customer data only on documented instructions, to provide and secure the Service, or as required by applicable law.
If you are a customer or SMS recipient of a merchant, the merchant's own privacy notice also applies. Privacy requests concerning merchant-controlled data should normally be directed to that merchant. We will assist the merchant and will respond directly where the law requires us to do so.
4. Personal data we process
The data processed depends on how the Service is used and which features are enabled.
4.1 Merchant and authorised-user data
We may process:
- name, business email address, user ID, role, account-owner status and preferred language;
- Shopify store domain, Shopify store identifier and installation status;
- authentication sessions, access and refresh tokens, granted scopes and session expiry information;
- account settings, permitted sender names, campaign and automation settings, budgets, kill switches and selected thresholds;
- subscription status, billing-cycle data, usage quantities, charge references, invoice-related information and payment status;
- support messages and information supplied in connection with a request; and
- security and audit events associated with the account.
Payment card information is not collected or stored by Europe SMS Marketing. Subscription approval and payment processing are handled through Shopify or another expressly identified payment channel.
4.2 Merchant customer and SMS-recipient data
When instructed by a merchant, we may process:
- Shopify customer identifiers;
- mobile telephone numbers;
- first names, where needed for an enabled message and made available by Shopify;
- SMS marketing-consent status, the date and source of that status, opt-out information and suppression status;
- membership in a Shopify customer segment and eligibility for a selected audience;
- campaign content, approved sender name and message category;
- message timestamps, status, provider reference, delivery report, failure reason, encoding and billable segment information;
- cart and checkout identifiers and associated lifecycle events;
- order identifiers, order and payment status, fulfilment and delivery status, cancellation and refund events;
- limited order-value and currency information used for deterministic campaign attribution and reporting;
- responses to a cash-on-delivery confirmation request; and
- hashes, internal identifiers and timestamps used for deduplication, tenant separation, consent evidence, security, billing reconciliation and auditability.
Order numbers, order totals and currencies may be used to personalise order and payment confirmation messages, as well as for attribution where applicable. We also process cart and checkout recovery URLs, shipment tracking URLs where available, cash-on-delivery responses, unsubscribe actions and the associated security records.
For order-related automations, Europe SMS Marketing is designed to extract only the data required to establish the relevant event and message eligibility. It does not require product line items, postal addresses or customer email addresses for its retained automation evidence.
4.3 Shopify webhook data
Shopify may deliver webhook payloads containing personal data associated with a customer, checkout, order, fulfilment, refund or privacy request. Europe SMS Marketing authenticates these payloads, stores them in encrypted form for a limited processing period, extracts the minimum evidence required for the enabled feature, and then removes the payload according to the retention periods in Section 10.
4.4 Storefront cart-recovery data
Where the merchant enables the storefront cart-recovery component, it operates only for a logged-in Shopify customer and only when Shopify's customer-privacy signal permits marketing processing.
The component sends Europe SMS Marketing an opaque cart identifier. It does not use that storefront request to collect a telephone number, email address, customer name, postal address, customer access token or free-text message. The identifier is accepted only after Shopify verifies that the cart belongs to the same authenticated customer. Missing or conflicting privacy and identity information causes the operation to stop.
4.5 Technical and security data
We may process:
- IP address and request metadata;
- browser, device and application information supplied with a request;
- authentication and session events;
- timestamps, response status and bounded error information;
- operational counters and service-health information; and
- security events needed to detect abuse or investigate an incident.
Europe SMS Marketing is designed not to place telephone numbers, message bodies, webhook bodies, authentication credentials or encryption material in ordinary application logs.
4.6 Data we do not intentionally request
The Service is not designed to process special-category data, government identifiers, payment-card data, account passwords, medical records or similarly sensitive material in SMS content. Merchants must not submit such information unless Europe SMS Marketing has expressly agreed to the processing in writing and the merchant has established every required legal condition.
5. Sources of personal data
We obtain personal data from:
- merchants and their authorised users;
- Shopify, through authorised APIs, authenticated webhooks, application sessions and billing events;
- customers and recipients when they reply to an SMS, use a permitted confirmation action, or submit a privacy request;
- the SMS delivery provider and telecommunications operators, through submission results and delivery reports;
- our hosting, security and technical systems; and
- public authorities or professional advisers where necessary for a legal matter.
We do not buy contact lists or obtain telephone numbers from data brokers for merchant campaigns.
6. Why we process personal data
When we act as controller, we process personal data for the following purposes and legal bases:
| Purpose | Legal basis under applicable European data-protection law |
|---|---|
| Provide the Service, administer an account and deliver requested support | Performance of a contract or steps requested before entering a contract |
| Manage relationships with merchant representatives | Our legitimate interest in operating and supporting a business service |
| Authenticate users, secure the Service, prevent abuse and investigate incidents | Our legitimate interests in protecting the Service, merchants, recipients and our legal rights |
| Maintain accurate usage, billing and reconciliation records | Performance of a contract, legitimate interests and compliance with legal obligations |
| Keep accounting, tax and legally required business records | Compliance with legal obligations |
| Establish, exercise or defend legal claims | Our legitimate interests and, where applicable, compliance with legal obligations |
| Send essential service, security and contractual communications | Performance of a contract and our legitimate interests in operating the Service |
| Send our own optional marketing communications | Consent where consent is required, or another lawful basis expressly permitted by applicable law |
Where we rely on legitimate interests, we assess whether the processing is necessary, proportionate and compatible with the rights and reasonable expectations of the affected individual.
When Europe SMS Marketing processes merchant customer data as a processor, the merchant is responsible for selecting and documenting the applicable legal basis. Europe SMS Marketing does not treat installation of the application, possession of a telephone number, or a customer's purchase as automatic permission to send marketing SMS.
7. SMS eligibility, consent and opt-out controls
Europe SMS Marketing distinguishes marketing messages from strictly transactional messages. Marketing automations may include welcome, cart recovery, checkout recovery, win-back and post-purchase or cross-sell messages.
The subscribed audience uses the store’s SMS subscription status. The optional All contacts audience can include people who are not subscribed; selecting that audience does not establish consent or another lawful basis. Merchants must obtain any permission required for the message and destination and must honour withdrawals and objections.
Shopify-recorded withdrawals are excluded until a valid later re-subscription is verified. Recorded in-app STOP/unsubscribe and redaction restrictions remain enforced and are not overridden by ordinary customer synchronization.
Including an unsubscribe link in a message is a merchant-controlled option. Omitting that link does not remove applicable opt-out obligations or override an existing withdrawal.
Strictly transactional automations may include order confirmation, payment confirmation, shipment, delivery and cash-on-delivery actions. A transactional message must remain limited to the relevant service event.
Messages containing promotional content must be treated by the merchant as marketing, even when sent through an order-related automation. The merchant is responsible for the purpose and lawfulness of its final text. Automation controls do not constitute a legal assessment of merchant-written content.
Before an automated message is dispatched, the Service is designed to check the relevant consent or purpose, opt-out status, merchant controls, frequency limit, budget, duplicate state, cancellation evidence and provider outcome. Missing, contradictory or expired evidence causes the message to be blocked or suppressed.
A recipient may use the opt-out method stated in the message or contact the merchant. Where reply-based opt-out is supported, an effective STOP request is recorded and blocks later messages within the scope required by applicable law. We may retain a restricted suppression record so that the recipient is not added back to an audience improperly.
Merchants remain responsible for the validity of consent, the accuracy of their notices, sender identification and the lawfulness of each campaign.
8. Automated processing and profiling
Europe SMS Marketing applies merchant-selected rules to determine whether a recipient is eligible for an audience or automation. Rules can use consent status, Shopify segment membership, cart or checkout status, purchase inactivity, order status and delivery events.
These rules support message scheduling, suppression and reporting. Europe SMS Marketing does not use them to make decisions that produce legal effects or similarly significant effects concerning an individual. The Service does not use merchant customer data to build advertising profiles for OBSEDIA or for unrelated third parties.
9. How we disclose personal data
We disclose personal data only as necessary for the purposes in this Policy:
- Shopify: to authenticate the merchant, obtain authorised store information, receive events, administer platform billing and keep the application integrated with the merchant's store. Shopify processes data under its own agreements and privacy terms.
- SMS delivery providers. We use specialist providers to submit SMS messages to telecommunications networks and obtain delivery information. Depending on the message, these providers process recipient phone numbers, sender identifiers, message content and submission or delivery metadata.
- Railway Corporation — hosting infrastructure. We use Railway to host the Europe SMS Marketing application, its background processing services and its PostgreSQL database. This infrastructure processes the store, customer, consent, message, delivery, usage and security data described in this Policy. Our production application services and primary database are currently hosted in Amsterdam, Netherlands. This primary hosting location does not, by itself, mean that every support activity, backup or other provider operation takes place within the EEA.
- Professional advisers: to obtain legal, accounting, security or insurance services, subject to appropriate confidentiality duties.
- Authorities and legal recipients: where disclosure is required by applicable law, a binding legal request, or necessary to protect legal rights and safety.
- Business-transaction recipients: if all or part of the business is reorganised, financed, acquired or transferred, subject to confidentiality and applicable data-protection requirements.
| Railway infrastructure information | Details |
|---|---|
| Legal entity | Railway Corporation |
| Business address | 548 Market St PMB 68956, San Francisco, California 94104, United States |
| Privacy contact | privacy@railway.com |
| Services | Application hosting, background processing infrastructure, PostgreSQL database hosting and configured backup storage |
| Primary application and database location | Amsterdam, Netherlands |
See Railway Privacy and Railway subprocessors.
SMS delivery provider identities and processing details are subject to the subprocessor information requirements of our Data Processing Terms. Confidentiality does not restrict legally required disclosures or data-protection rights. See Data processing agreement for information about a separately signed copy.
Processors acting for us are subject to written data-protection and security obligations appropriate to their role.
We do not:
- sell personal data;
- share personal data for cross-context behavioural advertising;
- disclose personal data to data brokers;
- use merchant customer or SMS-recipient data to advertise OBSEDIA's own services; or
- permit subprocessors to use merchant customer data for their own unrelated marketing.
We have not sold or shared personal data for cross-context behavioural advertising during the preceding 12 months.
10. Retention and deletion
We keep personal data only for as long as necessary for the relevant purpose, merchant instructions, security and integrity requirements, legal obligations and the establishment, exercise or defence of claims.
The Service currently applies the following operational retention periods:
| Data | Retention |
|---|---|
| Encrypted ordinary customer and checkout webhook payloads | Up to 7 days |
| Metadata for ordinary customer and checkout webhooks | Up to 30 days |
| Encrypted privacy-request webhook payloads | Up to 30 days, or earlier after secure delivery or completion where supported |
| Metadata for privacy-request and uninstall receipts | Up to 31 days |
| Storefront cart-identity candidate | Up to 30 days |
| Customer contact record used by the Service | Up to 732 days from the relevant accepted update, unless earlier deletion or a new lawful update applies |
| Consent and suppression evidence | Up to 2,196 days from the relevant event, where needed to demonstrate permission or prevent unlawful re-enrolment |
| Order and automation evidence | Generally up to 2 years from the relevant event, subject to an earlier linked-record expiry or privacy request |
| Cash-on-delivery action token | 24 hours for use; related audit evidence follows the shorter applicable evidence-retention period |
| Merchant account, campaign, delivery, audit and billing records | For the active merchant relationship and thereafter only as needed for contractual, accounting, fraud-prevention or legal-claims purposes |
| Support correspondence | For the time needed to resolve the request and maintain an appropriate record of the resolution |
Cart and checkout recovery links remain valid for up to seven days, depending on the flow, and may expire earlier when the associated record expires or the recovery is no longer applicable. Link validity is separate from the retention period of the underlying records.
Retention can be shorter where a customer or shop is erased, the merchant uninstalls the application, a source record expires, or continued processing is no longer permitted.
When a merchant uninstalls Europe SMS Marketing, the Service deletes active Shopify sessions and tenant customer data processed for messaging. A minimal authenticated uninstall receipt may be retained for up to 31 days to prevent stale or duplicate events from recreating data. Data required by law or necessary for an unresolved billing or legal claim may be isolated and retained only for that purpose.
Shopify privacy webhooks are used to process customer-access, customer-erasure and shop-erasure requests. We securely delete or irreversibly de-identify data when its retention period ends, subject to technically necessary deletion cycles for protected backups.
11. Security
We apply technical and organisational measures designed to protect personal data according to its nature and risk. These measures include, as applicable:
- HTTPS for public connections and encrypted private networking between application services and the database;
- authenticated and tenant-bound Shopify access;
- encryption at rest for telephone numbers, first names, SMS content and webhook payloads using authenticated encryption;
- tenant-specific keyed lookup values that prevent the same telephone number from being correlated across merchants;
- role and access restrictions based on operational need;
- protected secret and key handling;
- authenticated Shopify webhooks;
- authenticated provider requests and delivery-report processing;
- data minimisation and bounded retention;
- suppression, deduplication, budget and fail-closed sending controls;
- separation of production and non-production information;
- restricted and redacted operational logging; and
- incident-detection and response procedures.
No transmission or storage method is completely secure. We will notify the Merchant without undue delay after becoming aware of a personal-data breach affecting Merchant Personal Data. Information may be provided in stages as the investigation progresses. We will investigate and mitigate the incident, cooperate with the Merchant and notify affected individuals or authorities where required by applicable law and our contractual obligations.
12. International data transfers
The Service is operated for the European market, but a provider or its authorised personnel may process personal data from a country outside the European Economic Area, the United Kingdom or Switzerland.
We will not carry out a restricted international transfer without a legally valid basis and any required safeguards. The safeguards applicable to a particular transfer depend on the processing operation and the relevant provider relationship. Primary hosting in the EEA does not, by itself, establish the location or transfer arrangements of all provider operations.
Information about the safeguards relevant to a particular processing operation can be requested at privacy@obsedia.ai. Commercially sensitive and security-sensitive terms may be redacted from any copy supplied.
13. European privacy rights
Subject to applicable law, you may have the right to:
- obtain confirmation that your personal data is processed and access that data;
- correct inaccurate or incomplete data;
- request deletion;
- restrict processing;
- receive eligible data in a structured, commonly used and machine-readable format;
- object to processing based on legitimate interests;
- object at any time to direct marketing, including related profiling;
- withdraw consent at any time, without affecting processing lawfully completed before withdrawal;
- obtain information about applicable international-transfer safeguards; and
- lodge a complaint with the data-protection authority in the country where you live, work, or believe an infringement occurred.
Europe SMS Marketing does not make solely automated decisions that produce legal or similarly significant effects about merchant customers or SMS recipients.
To exercise a right relating to data for which Europe SMS Marketing is controller, email privacy@obsedia.ai. We may request information reasonably necessary to verify your identity and protect the data from unauthorised disclosure.
We normally respond within one month. Where legally permitted, that period may be extended by two further months because of the complexity or number of requests, and we will inform you of the extension within the initial month.
If Europe SMS Marketing processes the relevant data for a merchant, please identify the merchant in your request. We may refer the request to that merchant and assist it in responding.
14. United States state privacy notice
This Section applies only where a United States state privacy law applies to Europe SMS Marketing's processing of your personal information. It supplements the rest of this Policy and does not imply that the Service offers SMS delivery to destinations outside its supported European coverage.
Depending on your state and the applicable law, you may have the right to:
- know whether we process your personal information;
- access personal information and receive details about its sources, purposes and recipients;
- correct inaccuracies;
- request deletion;
- obtain a portable copy of eligible information;
- opt out of sale, targeted advertising or qualifying profiling;
- limit specified uses and disclosures of sensitive personal information;
- use an authorised agent;
- appeal a refusal of a privacy request; and
- exercise your rights without unlawful discrimination.
During the preceding 12 months, the controller-side information we may have collected falls into these categories:
| Category | Examples | Business purpose | Recipient categories |
|---|---|---|---|
| Identifiers | Name, business email, user ID, store domain, IP address | Account administration, authentication, support and security | Shopify, infrastructure providers and professional advisers as needed |
| Commercial information | Subscription, billing cycle, usage and support history | Provide, bill and support the Service | Shopify and professional advisers as needed |
| Internet or electronic activity | Session, request, device and security events | Authentication, security, troubleshooting and fraud prevention | Shopify and infrastructure providers |
| Professional information | Business role, account-owner or collaborator status | Authorisation and business relationship management | Shopify and infrastructure providers |
| Communications | Support messages and communications with us | Respond to requests and maintain service records | Communications provider and professional advisers as needed |
| Sensitive personal information | Authentication credentials or tokens and, where applicable, contents of communications processed to deliver the Service | Provide and secure the requested Service | Shopify, infrastructure providers and the SMS provider as strictly necessary |
Merchant customer data is processed on behalf of the relevant merchant and is described in Sections 3 and 4. We do not use sensitive personal information to infer characteristics about individuals or for purposes that require a separate right to limit under applicable California law.
We do not sell personal information, share it for cross-context behavioural advertising, process it for targeted advertising, or offer a financial incentive in exchange for personal information. Therefore, there is no separate sale or targeted-advertising opt-out required for our current practices.
To submit a request or an appeal, email privacy@obsedia.ai and state the right you wish to exercise. We will verify and respond to the request as required by applicable law, generally within 45 days where that period applies. An authorised agent may act for you if the agent provides legally sufficient proof of authority and we can verify the request.
Do Not Track and Global Privacy Control
Europe SMS Marketing does not track individuals across unaffiliated websites for behavioural advertising. We do not sell or share personal information for targeted or cross-context behavioural advertising. Because those activities do not occur, a browser Do Not Track or Global Privacy Control signal does not change our current processing practices. If our practices change, we will update this Policy and implement any legally required preference-signal handling before beginning the new processing.
California direct-marketing disclosure
We do not disclose personal information to third parties for their own direct-marketing purposes.
15. Cookies and similar technologies
Europe SMS Marketing does not use advertising cookies, advertising pixels or cross-site behavioural analytics.
The website and embedded application may use strictly necessary cookies, session tokens, local storage or similar technologies supplied by us or Shopify to authenticate users, protect requests, maintain the selected language and provide core functionality. These technologies cannot be disabled through a consent preference without affecting the operation or security of the Service.
If we introduce optional analytics or advertising technologies, we will update this Policy and obtain consent before use where required.
16. Children
Europe SMS Marketing is a business service and is not directed to children. Merchant accounts may be created and used only by individuals who are at least 18 years old and authorised to represent a business.
Merchants must not use the Service to target children or process children's personal data unless they have established every consent, notice and other safeguard required by applicable law. If you believe a child's personal data has been processed unlawfully, contact privacy@obsedia.ai and identify the relevant merchant if known.
17. Changes to this Policy
We may update this Policy when the Service, our processing practices or applicable law changes. We will publish the revised version with a new last-updated date.
We will provide additional notice of a material change through the Service, the merchant account or the registered business email where appropriate. If a change requires consent, we will obtain that consent before applying the changed processing.
18. Contact
For privacy questions, requests or complaints:
Genius Nutrition SRL, trading as OBSEDIA
Tamasi nr. 20
Buftea, Ilfov
Romania
VAT: RO35355847
Email: privacy@obsedia.ai
For general service enquiries: support@obsedia.ai