Last updated: July 11, 2026
Charlie OÜ ("Charlie", "we", "us") provides an AI email marketing platform for e-commerce brands, delivered primarily as an embedded app for Shopify stores.
Charlie OÜ
Lahepea 9, 10617 Tallinn, Estonia
Reg. 17461722 | VAT: EE102966275
Email: hello@charlieai.co
Processor — your store's data. When a merchant installs Charlie on their Shopify store, we process that store's data (customers, orders, products, checkouts, theme and content data) strictly on the merchant's behalf and instructions, to generate and send email campaigns. For this data the merchant is the data controller and Charlie is a data processor under Article 28 GDPR. Our Data Processing Addendum governs this processing and forms part of our terms with every merchant.
Controller — merchant account data. For the merchant's own account information (store domain, contact email, billing status, support conversations), Charlie is the data controller. The rest of this policy covers both roles and says which applies where relevant.
As processor (store data, on the merchant's behalf):
As controller (merchant account data):
No open or click tracking. Emails sent through Charlie contain no tracking pixels and no per-recipient click-tracking redirects. We believe recipient surveillance is neither necessary for good email marketing nor compatible with the spirit of the ePrivacy rules. We measure campaign success through delivery, bounce, complaint, and (where the merchant connects it) store order data instead.
No selling or sharing of data. Store data is never sold, never used to train AI models, never shared across merchants, and never used for our own marketing.
No advertising cookies on this site. charlieai.co uses only cookies strictly necessary for the service to function.
Charlie uses large language models from Anthropic to generate email content. What is sent to Anthropic is limited to the content needed to write the email: the campaign brief, brand kit, and relevant product information. We do not send customer lists or individual customer records to Anthropic. Under our commercial agreement, Anthropic does not use this data to train its models.
We use a small number of service providers to run Charlie. As required by our DPA, we maintain this list and notify merchants of changes.
| Subprocessor | Purpose | Location |
|---|---|---|
| DigitalOcean, LLC | Cloud hosting of application and databases | EU (Amsterdam, Netherlands data center) |
| Mailgun Technologies, Inc. / Twilio SendGrid | Email transmission (delivery of merchant emails and service notifications) | EU sending regions where available; US entity — SCCs in place |
| Anthropic, PBC | AI content generation (briefs, brand kit, and product content only — no customer lists) | USA — SCCs / EU-US Data Privacy Framework |
Charlie's application and databases are hosted in the European Union (DigitalOcean, Amsterdam). Store data is stored and processed in the EU. Where a subprocessor is established outside the EU/EEA (see table above), transfers are protected by the European Commission's Standard Contractual Clauses or an applicable adequacy decision such as the EU-US Data Privacy Framework.
All traffic is encrypted in transit (HTTPS/TLS). Shopify access tokens and other credentials are encrypted at rest. Every request from the embedded app is authenticated with short-lived Shopify session tokens, and workspace data is strictly isolated per merchant at the database-access layer. Access to production systems is limited to authorized personnel. No system is completely secure; if a breach affects personal data we will notify affected merchants and, where required, the supervisory authority without undue delay.
If you are a merchant (or a merchant's customer), you have the rights of access, rectification, erasure, restriction, portability, and objection under the GDPR, and the right to withdraw consent where processing is based on consent.
If you are a customer of a store that uses Charlie, please direct your request to that store — they are the controller of your data, and Shopify's compliance tooling routes their instructions to us automatically. We fulfil merchant-routed requests within the timelines described in section 9.
If you are a merchant, contact us at hello@charlieai.co. We respond within 30 days.
Our service is a business tool and is not directed at individuals under 18. We do not knowingly collect data from children.
We may update this policy from time to time. Material changes are communicated to merchants by email at least 14 days before taking effect. The "Last updated" date above reflects the most recent revision.
You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee, or with your local supervisory authority.
Charlie OÜ
Lahepea 9, 10617 Tallinn, Estonia
Email: hello@charlieai.co