Legal

Privacy Policy

Last updated: June 20, 2026

Introduction

MGR Products BV ("Layer Insights", "we", "us") operates the Layer Insights SaaS platform (layerinsights.io) and the Layer Insights Shopify App. This Privacy Policy explains how we collect, use, and protect personal data in accordance with the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).

What data we collect

We collect the following categories of data:


Account data: name, email address, company name, and billing information when you register.

Usage data: dashboard activity, feature usage, API calls, and session logs.

Shopify merchant data: store URL, product catalog metadata, order events (anonymised by default), and pixel event data passed through our dual-dispatch system.

End-customer event data: hashed email addresses (SHA-256), click IDs (fbclid, gclid, ttclid), and browser/device signals — processed strictly as a data processor on behalf of the merchant.

How we use it

We use collected data to:


• Operate and improve the Layer Insights platform and its 27 modules.

• Send CAPI events to ad platforms (Meta, Google, TikTok, Pinterest, Snapchat, LinkedIn) on behalf of merchants.

• Calculate EMQ scores, identity graphs, and attribution models.

• Send transactional emails, weekly performance digests, and drop alerts.

• Comply with legal obligations.


We do not sell personal data to third parties.

Shopify merchant data

When you install the Layer Insights Shopify App, we act as a data processor under GDPR Article 28. We process order and customer event data solely to provide the services you have configured. We respond to Shopify GDPR webhooks (customer/shop redact, customer data request) within 30 days. Data deletion requests are processed automatically via our webhook handler.

Third-party platforms

Layer Insights transmits event data to ad platforms (Meta Conversions API, Google Enhanced Conversions, TikTok Events API, Pinterest API, Snapchat CAPI, LinkedIn CAPI) as instructed by merchants. Each platform has its own data processing terms which govern their use of this data. We apply SHA-256 hashing to all PII (email, phone, name) before transmission.

Data retention

• Raw event logs: 90 days rolling window.

• Aggregated analytics data: 24 months.

• Account and billing data: 7 years (legal retention obligation).

• Identity graph data: deleted within 30 days of account closure.


You can request deletion of your data at any time by emailing privacy@layerinsights.io.

GDPR rights

Under GDPR, you have the right to:


Access: request a copy of your personal data.

Rectification: correct inaccurate data.

Erasure: request deletion ("right to be forgotten").

Restriction: limit how we process your data.

Portability: receive your data in a machine-readable format.

Object: object to processing based on legitimate interests.


To exercise any right, email privacy@layerinsights.io. We will respond within 30 days. You may also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) at autoriteitpersoonsgegevens.nl.

Cookies

We use the following cookies:


_lf_id (first-party, 365 days): Layer Insights visitor identity token. Used for identity stitching across sessions.

_lf_session (session): temporary session identifier.

Analytics cookies: only set with explicit consent via your consent banner (CookieBot, OneTrust, or Shopify Privacy API). Layer Insights auto-detects your consent solution and respects granted/denied signals.


We do not set advertising or tracking cookies on the merchant's storefront without consent.

Security

We implement industry-standard security measures including:


• TLS 1.3 for all data in transit.

• AES-256 encryption for data at rest.

• SHA-256 hashing for all PII before transmission to ad platforms.

• EU data residency (Amsterdam, Netherlands) for all customer data.

• SOC 2 Type II audit in progress (expected Q4 2026).

• Regular penetration testing by an independent third party.

Contact

MGR Products BV

Registered in Amsterdam, Netherlands

KVK: [registration number]


Privacy questions: privacy@layerinsights.io

General: hello@layerinsights.io


For GDPR-related requests, please use the subject line "GDPR Request — [your name]".

MGR Products BV · Amsterdam, Netherlands · privacy@layerinsights.io