Privacy policy
What we do with your data.
Last updated 4 September 2026
ShopARoll turns your photos into videos and ads. To do that we have to hold your photos, your business details and what you make, and send pieces of them to the AI services that do the work. This page says exactly what, where, for how long, and how to get it deleted.
1. Who we are
ShopARoll ("we", "us") runs shoparoll.com, app.shoparoll.com and the partner API. We are the data controller for the personal data described here. Contact us at hello@shoparoll.com.
2. What we collect
Your account
You sign in with Google. We ask Google for your name, email address and profile picture, and we store those along with the ID Google uses for your account. That is all we ask for at sign-in; the permission to upload to YouTube is asked for separately, only if you connect a channel.
Your business
Name, website, address, phone number, a description, your logo and your brand colours. We read these off the website you give us, or off the Google Maps listing you pick when you search for your shop, or you type them in. You can edit all of it in the app.
Your photos and videos
The photos and video clips you upload, the screenshots we take of your website if you use the capture tool, the pictures the AI draws for you, and the stills of any persona you create. If you build a persona from photos of a real person, those reference photos are stored too. Alongside each photo we keep a short written description that the AI produced, because that description is what the writing works from.
What you make
Video ideas, scripts, captions, ad copy, ad images, voiceovers, rendered videos, and the posts in your publish queue with their titles and descriptions.
Billing
Your Stripe customer ID, subscription ID and status, and a ledger of every credit granted, spent and refunded. Stripe holds your card details and billing address; we never see or store card numbers.
Connected channels
If you connect a YouTube channel: the channel's name and ID, and the token Google gives us to upload on your behalf. The token is stored encrypted. Section 6 says more.
API keys
If you create a partner API key, we store a one-way hash of it, its name, when it was made and when it was last used. We cannot recover the key itself.
Technical records
- Server logs. Each request to the app is logged with your IP address, the page or endpoint, the time, and your browser's user-agent string.
- AI usage records. For each AI job we record which provider and model ran, what kind of task it was, how many tokens or seconds it used, what it cost, how long it took, and whether it succeeded. These records don't contain your content.
- Staff audit log. When a member of our staff opens your account to help you, we log who, when, from which IP address, and what they did.
If you email us or leave your address
If you type your email address into a box on the landing page, we keep it with a note of where on the page it came from. If you email us, we keep the email so we can reply and refer back to it.
3. Why, and on what basis
Under UK and EU data protection law we need a lawful basis for each use. Here they are.
| What we do | Why we're allowed to |
|---|---|
| Run the product: store your content, write, draw, voice, animate, render and publish what you ask for | Performing our contract with you |
| Take payment, keep the credit ledger, issue receipts | Performing our contract; legal obligations around tax and accounting |
| Keep the service secure, detect abuse, keep logs | Our legitimate interest in running a safe service |
| Answer your support requests, including staff opening your account | Performing our contract |
| Tell you about changes to the service, prices or these terms | Performing our contract; legal obligations |
| Understand how the product is used, from aggregated usage records | Our legitimate interest in improving it |
| Email you about ShopARoll if you gave us your address on the landing page | Your consent, which you can withdraw by replying "stop" |
We don't use your content to train AI models. We don't sell personal data. We don't build advertising profiles.
4. Who processes it for us
We can't make the product alone. The services below each receive the part of your data they need to do one job, and only to return the result to us. Their own privacy policies govern what they keep.
| Service | What it does | What it receives |
|---|---|---|
| Sign-in; finding your shop on the map; uploading to YouTube if you connect a channel | Your Google account identity; your search for your shop; the videos you approve for upload | |
| Stripe | Payments and subscriptions | Your email, what you bought, and the card details you give Stripe directly |
| Amazon Web Services (Ireland) | Storage for uploads, drawn pictures, posters and finished videos | Your photos, videos and rendered files |
| OpenRouter, and the AI model providers it routes to | Describing your photos; drawing pictures you don't have; persona stills | Your photos, your brand details, and the description of what to draw |
| Language-model providers | Writing ideas, scripts, captions and ad copy | Your business details and the written descriptions of your photos, not the photos themselves |
| ElevenLabs | Voiceover | The script text |
| Runway | AI motion, turning a still into footage | The photo for that shot and a short description of the movement |
| Our hosting provider (France) | The servers and database | Everything in section 2 |
If you reach the partner API through another platform, such as an agent marketplace, that platform sees what you send through it and is a separate controller of that data under its own policy.
Fonts on shoparoll.com and in the app are loaded from Google Fonts, so your browser sends its IP address to Google when it fetches them. We use no analytics scripts, tag managers, pixels or advertising trackers on either site.
5. Where it lives
Our servers and database are in France. Media is stored on Amazon Web Services in Ireland, in a private bucket that is encrypted at rest. Nothing in it is public; the app checks that a file is yours and then gives your browser a link that works for 30 minutes.
Stripe, Google, OpenRouter, ElevenLabs and Runway process data in the United States and elsewhere. When your data leaves the UK or the EU we rely on the safeguards the law provides, including the UK–US Data Bridge and the EU–US Data Privacy Framework where the provider is certified, and standard contractual clauses otherwise.
6. YouTube and Google API Services
ShopARoll uses YouTube API Services to upload videos to a channel you connect. By connecting one you agree to YouTube's Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
- What we access. Your channel's name and ID, and permission to upload videos. We do not read your existing videos, comments, subscribers or analytics.
- What we store. The channel name and ID, and the refresh token Google issues, kept encrypted in our database. We mint a short-lived upload token from it each time you approve a post, and store nothing else from Google.
- What we do with it. Upload the videos you approve, with the title, description and tags you set. Nothing else.
- How to stop. Disconnect the channel in the app, which deletes the token, or revoke ShopARoll's access from your Google account permissions page.
Our use of information from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
7. How long we keep it
| Data | Kept for |
|---|---|
| Sign-in session | 30 days from sign-in, or until you sign out |
| Your account, business details, library, videos and ads | While your account is open |
| Working files from a render (per-shot clips, temporary parts) | Deleted 7 days after the video finishes. The finished video is not affected |
| Uploads that have never been used in a video or ad | Removed after 60 days without use. The library keeps a note saying so; anything used in a video is never swept |
| Animated shots you paid credits for | Kept, so a re-render never charges you twice |
| YouTube token | Until you disconnect the channel |
| API keys | Until you revoke them |
| Server logs | A few weeks, then overwritten |
| Credit ledger, AI usage records, Stripe records | Six years after the transaction, as accounting and tax law requires. These don't contain your content |
| Staff audit log | Two years |
| Email address left on the landing page | Until you ask us to stop |
| Everything, after you ask us to close your account | Deleted within 30 days, except the accounting records above. Backups roll off shortly after |
8. Cookies
The app sets two cookies. Both are strictly necessary, so there is no consent banner.
| Cookie | Purpose | Lasts |
|---|---|---|
sr_session | Keeps you signed in | 30 days |
sr_oauth_state | Protects the Google sign-in handshake against forgery | 10 minutes |
The landing site at shoparoll.com sets no cookies at all. Neither site sets third-party cookies.
9. Who at ShopARoll can see your data
A small number of staff have admin access. To help with a support problem they can open your account and see what you see. Each such session is written to an audit log with the staff member, your account, the time and the IP address, and while in your account they cannot spend your credits or buy anything.
10. Security
Everything travels over TLS. Media sits in a private, encrypted bucket and is served only through short-lived links after an ownership check. API keys are stored as hashes and YouTube tokens are encrypted. Access to production is limited to the people who run it. No system is perfect; if you think you've found a weakness, email hello@shoparoll.com and we will take it seriously.
11. Your rights
You can ask us to:
- tell you what personal data we hold about you, and give you a copy;
- correct anything that's wrong (most of it you can edit yourself in the app);
- delete your account and everything in it;
- restrict or object to a particular use;
- give you your data in a form you can take elsewhere. Your videos and ad images are already downloadable from the app;
- withdraw consent where consent is what we relied on.
Email hello@shoparoll.com from the address on your account. We answer within a month. If you aren't happy with how we handle it, you can complain to the UK Information Commissioner's Office at ico.org.uk, or to the data protection authority where you live.
12. Children
ShopARoll is for businesses and for adults. We don't knowingly hold data about anyone under 18. If you think we do, tell us and we will delete it.
13. Changes to this policy
When we add a service provider or change what we keep, we update this page and the date at the top. For a change that affects you materially we'll email the address on your account before it takes effect.
Questions, requests, complaints?
Email hello@shoparoll.com. A person reads it.
See also the terms of service.