Last updated:
1. Introduction
Conomize is a commerce discovery and information service. We publish structured information about merchants and their offers, and we make that information available to people and to AI-powered shopping interfaces. We do not sell products, we do not operate checkouts, and we do not process payments.
This policy applies to the Conomize website (conomize.com and its localized market and language paths), the public read-only API, and the public read-only MCP endpoint.
2. Who we are
Conomize is a brand and service operated within the European Union. Conomize is not a separately incorporated company; the operator of the service determines the purposes and means of the processing described in this policy and acts as data controller.
Contact for privacy matters: info@conomize.com
Full identification details of the operator are provided on request at info@conomize.com and to competent authorities.
We have not designated a Data Protection Officer. Privacy requests are handled by the contact address above.
3. Scope
Conomize launches commercially in Italy and Luxembourg but is accessible internationally. We use the EU General Data Protection Regulation (Regulation (EU) 2016/679) and EU ePrivacy principles as our baseline for everyone. Where we materially target additional jurisdictions, we will review and, if necessary, extend this policy for local requirements.
This policy does not apply to merchant websites, affiliate networks or any other third-party site you reach from Conomize. Those environments are governed by their own privacy notices.
4. Personal data we collect
Conomize has no user accounts, no login, no newsletter and no advertising technology. In practice we process personal data in only two situations.
a) Partnership enquiries. When you submit the Founding Merchant / For Brands form, we receive the fields you complete: contact name, company name, email address, the market/country you select, and optionally a merchant name, a website address and a free-text message. Any additional personal data you choose to type into the message field is also processed.
b) Technical data generated by visiting the site. When your browser or an automated client requests a page, an API response or the MCP endpoint, our hosting infrastructure necessarily receives connection data such as the IP address, the requested URL, timestamp, user agent and referrer. This is inherent to how the internet works and is used for delivery, security and abuse prevention.
We do not knowingly collect special categories of personal data, and you should not include them in the enquiry form.
5. How we collect data
- Directly from you, when you submit the partnership enquiry form or email us.
- Automatically, through the technical request data described above.
- We do not buy personal data, we do not enrich it from data brokers, and we do not build advertising profiles.
6. Purposes of processing
- To read, assess and reply to a partnership or merchant enquiry, and to hold the related business conversation.
- To deliver the website, the public API and the MCP endpoint, and to keep them available, secure and free from abuse.
- To comply with legal obligations that apply to us.
We do not use enquiry data for unrelated marketing, and we do not send newsletters.
7. Legal bases
- Partnership enquiries: our legitimate interest, and yours, in responding to a business contact you initiated, and steps taken at your request prior to entering into a possible agreement (Art. 6(1)(f) and, where relevant, Art. 6(1)(b) GDPR).
- Technical and security data: our legitimate interest in operating a functioning, secure service (Art. 6(1)(f) GDPR), and the technical necessity of transmitting the content you requested.
- Legal obligations: compliance where the law requires it (Art. 6(1)(c) GDPR).
We do not currently rely on consent, because we do not operate any non-essential cookie, tracker or marketing technology. If that ever changes, consent will be requested before the technology is activated.
8. Founding Merchant / partnership enquiries
When the form is submitted, two things happen: the submission is stored in our private database, and a notification email is generated so a human can respond.
- The notification is sent to info@conomize.com, from Conomize <info@conomize.com>, using our sending domain notify.conomize.com.
- The Reply-To address is set to the email address you submitted, so our reply reaches you directly.
- The email contains the fields you submitted, so that we can evaluate the enquiry.
- Stored enquiries are private. They are not readable through the website, the public API or the MCP endpoint, and public read access to that data is disabled at database level.
9. Website technical data
Conomize does not run analytics software, advertising pixels, session recording, heat-mapping, fingerprinting or any third-party marketing tag. Usage events generated inside the interface stay in the memory of your own browser tab for the duration of your visit; they are not transmitted to us or to anyone else.
Server-side request logging is performed by our hosting infrastructure as part of normal operation. The precise log fields and their retention are set by that infrastructure.
Details of the server log fields, log retention and hosting region applied by our infrastructure provider are available on request at info@conomize.com.
11. Affiliate and commercial relationships
Some links on Conomize are affiliate or referral links, which means we may receive a commission on qualifying actions or purchases. Not every merchant on Conomize is an affiliate partner, and not every link is an affiliate link.
When you follow such a link, you leave Conomize. The destination site and, where one is involved, the affiliate network may set their own cookies or identifiers to attribute the visit. That processing happens under their privacy notices, not ours. Conomize does not receive your purchase details, your payment data or your identity from those parties as part of the affiliate mechanism.
A commercial relationship is never the same as verification. Verification on Conomize means evidence-backed information about an offer or destination; it is not granted because a merchant pays us or works with us.
12. Third-party merchant websites
Merchant sites are independent third-party environments. Once you arrive there, that merchant is responsible for its own data processing, terms, pricing, orders, payment, delivery, returns and customer service. Please read the privacy notice of the site you are on before providing personal data.
13. Public API and MCP
Conomize publishes a read-only API and a read-only MCP endpoint so that software and AI assistants can access our public catalogue information. These interfaces expose merchant and offer information only.
- They are public, unauthenticated and read-only; they cannot write to, modify or delete our data.
- They do not expose partnership enquiries, private commercial terms, or any user data.
- Requests reach our infrastructure as ordinary web requests and are subject to the same technical logging described above.
We do not receive your conversations with an AI assistant, we cannot see your chat history, and AI providers do not send us your personal information. If an assistant queries Conomize, we see a request for public catalogue data — not who asked for it.
14. Recipients and service providers
We keep the number of parties involved deliberately small. Personal data may be processed on our behalf by:
- Our application, hosting and database infrastructure provider, which hosts the website and stores partnership enquiries.
- Our transactional email infrastructure, which renders and delivers the enquiry notification from our sending domain notify.conomize.com.
- Professional advisers or authorities, where we are legally required to disclose information.
In addition, page styling loads a web font from Google's font services. When your browser requests that font, your IP address is transmitted to Google as the technical operator of that service. No Conomize cookie or identifier is involved.
A current list of our infrastructure and email providers, and of their sub-processors, is available on request at info@conomize.com.
15. International data transfers
Some of the providers above, or their sub-processors, may process data outside the European Economic Area. Where that happens, an appropriate transfer mechanism under Chapter V GDPR must be in place.
Where such a transfer occurs, we rely on the transfer mechanism put in place by the provider concerned. Details are available on request at info@conomize.com.
16. Data retention
- Partnership enquiries are kept for as long as needed to handle the enquiry and any resulting business relationship, and afterwards only where a legal or evidential reason requires it. Enquiries that lead nowhere are deleted once they are no longer useful to the discussion.
- Notification emails persist in our mailbox under the same criteria.
- Technical request logs are retained for the period applied by our infrastructure provider for operational and security purposes.
Where a retention period is determined by a provider rather than by us, we state the applicable criteria rather than a fixed period. Details are available on request at info@conomize.com.
17. Security
- Traffic is served over HTTPS.
- Partnership enquiries are stored in a database with row-level security enabled and no public read, update or delete access; the data is not reachable from the browser, the public API or MCP.
- Private commercial information, such as affiliate arrangements, is held in server-only modules that are never bundled into the public site or exposed by public endpoints.
- Credentials with elevated privileges are held server-side only.
No system is perfectly secure, but we design for least exposure: the smallest possible amount of personal data, in the smallest possible number of places.
18. Your rights
Subject to the conditions in the GDPR, you may request:
- access to your personal data;
- rectification of inaccurate or incomplete data;
- erasure, where the conditions are met;
- restriction of processing;
- objection to processing based on legitimate interests, on grounds relating to your particular situation;
- portability, where processing is based on consent or contract and is carried out by automated means.
Conomize does not make automated decisions producing legal or similarly significant effects about you. To exercise a right, write to info@conomize.com. We may need to ask a question to confirm that the request relates to your own data.
19. Withdrawing consent
We do not currently process any personal data on the basis of consent. If we ever introduce a technology or activity that requires consent, you will be asked first, and withdrawing consent will be as easy as giving it, without affecting processing that took place beforehand.
20. Right to lodge a complaint
You may lodge a complaint with a data protection supervisory authority — in the EU, typically the authority of the Member State of your habitual residence, place of work, or the place of the alleged infringement.
In Luxembourg, that authority is the Commission nationale pour la protection des données (CNPD). Users in Italy may address the Garante per la protezione dei dati personali. Users elsewhere should contact their own competent authority.
21. Children
Conomize publishes commercial information for a general adult audience and is not directed at children. The partnership enquiry form is intended for business contacts acting for a merchant. We do not knowingly process personal data of children through this website; if you believe a child has sent us personal data, contact info@conomize.com and we will remove it.
22. Changes to this Privacy Policy
As the product evolves, this policy will be updated to match what the software actually does. The date below always reflects the last substantive change. Material changes will be made visible on the site.
23. Contact
Privacy questions and data subject requests: info@conomize.com
Controller: Conomize, reachable at info@conomize.com.