How BOBBI protects merchant and shopper data in BOBBI Smart Store: EU hosting, GDPR compliance, access control and careful handling of store data.
BOBBI turns online stores into AI-powered Smart Stores. Merchants trust us with their catalog and their customers' shopping sessions — this page explains, in plain language, how we protect that data.
Every purchase made through a BOBBI Smart Store is completed in the store's native platform checkout (Shopify or SHOPLINE). Card numbers and payment credentials never pass through, and are never stored on, BOBBI systems. This keeps the strictest payment-security requirements (PCI DSS) where they belong: with the platform's certified checkout.
Our servers and databases run on Hetzner Online GmbH infrastructure in Germany and Finland. Merchant data, store catalogs, and shopper interaction data are stored and processed inside the European Union. Where a sub-processor operates outside the EU (see below), transfers rely on the EU–US Data Privacy Framework or Standard Contractual Clauses.
The BOBBI app requests read-only store scopes (products, inventory, content, analytics). We do not request write access to orders, customers, or payment settings, and we do not access protected customer data beyond what powers the shopping experience.
Full details are in our Privacy Policy .
BOBBI Oy is an early-stage Finnish company. We do not yet hold a SOC 2 or ISO 27001 certification — at our size, we invest in the practices above rather than audit paperwork. As the company grows, formal certification is on our roadmap. If your organization needs a security questionnaire filled in or a data processing agreement signed, contact us and we will respond quickly.
Found a security issue? Please email founder.chatbob@gmail.com with the details. We appreciate responsible disclosure and will acknowledge reports promptly.
Eero