Privacy Policy

Last updated: July 28, 2026

This Privacy Policy explains how Optimum Web Marketing Consultants LLC (“we,” “us,” or “our”) collects, uses, discloses and protects information in connection with the O7 Buy Later application (the “App”) for BigCommerce stores, and the related dashboard and website pages we operate (together, the “Service”).

By installing or using the App, the merchant operating the BigCommerce store (the “Merchant”) agrees to this Policy. If you are a shopper on a store that uses the App, please also read the privacy notice of that store.

1. Our role: controller and processor

  • For Merchant account data (the store profile and the account of the person who installs the App), we act as a controller.
  • For shopper data processed inside a Merchant’s store (saved items, cart and order activity), the Merchant is the controller and we act as a processor acting on the Merchant’s instructions. Shoppers should direct requests about their data to the store they shopped with; we assist the Merchant in responding.

2. Information we collect

2.1 Store and Merchant information

When the App is installed, BigCommerce provides us with an authorization token and store identifiers. Using that token we retrieve and store the store profile, which may include: store name, store hash, store domain and URL, store owner first and last name, store administrator e-mail address, phone number, business address and country, industry, and BigCommerce plan name. We also store the OAuth access token and the permission scopes granted to the App.

2.2 Shopper activity data

The App records only the data needed to provide the save-for-later feature and its analytics:

  • The BigCommerce customer ID — a numeric identifier assigned by the store. It is pseudonymous: on its own it does not reveal a shopper’s identity.
  • Product ID, variant ID, selected options and quantity of items saved for later.
  • Cart ID of the shopper’s most recent known cart, so the Merchant can see what is currently in that cart.
  • Order ID, order total and product names when an order confirmation page shows that a previously saved item was purchased.
  • Event records — the type of action (item saved, moved back to cart, removed, purchase completed, coupon created) with a timestamp.
  • Discount coupon records generated by the Merchant for a specific customer — the code, discount type and amount, targeted product IDs, expiry date and usage status.

The save-for-later feature is available only to shoppers who are signed in to the store. Signed-out and guest visitors are shown a sign-in prompt and no data about them is recorded.

2.3 Information we do NOT collect

  • Shopper names, e-mail addresses, postal addresses or phone numbers.
  • Payment card numbers or any payment credentials. We never receive or process card data.
  • Passwords or BigCommerce account credentials of shoppers.
  • Browsing history outside the cart and order confirmation pages of the store.
  • Special categories of personal data (health, biometric, political, religious or similar).

2.4 Technical and log data

Our servers automatically record standard request logs, which may include IP address, browser user-agent string, requested URL, response status and timestamp. These logs are used for security, abuse prevention and debugging, and are rotated on a short cycle.

3. Cookies and local storage

WhereWhat is storedPurpose
Storefront (cart page widget)NoneThe widget sets no cookies and writes nothing to local storage. Its requests are sent without credentials.
Merchant dashboard inside the BigCommerce adminstore_session — an httpOnly session cookieStrictly necessary: authenticates the Merchant’s dashboard session. No advertising or tracking purpose.
Our internal administration paneladmin_token — an httpOnly session cookieStrictly necessary: authenticates our own staff. Not set on shopper devices.

We do not use advertising cookies, cross-site tracking, fingerprinting, or third-party analytics trackers on the storefront.

4. How we use information

  • To provide the save-for-later list and restore items to the cart.
  • To produce the Merchant’s dashboard statistics, conversion funnel, customer journey view and revenue attribution.
  • To let the Merchant view a customer’s current cart and issue a targeted win-back discount coupon.
  • To generate AI-written summaries of the store’s aggregate performance (see section 5).
  • To operate, secure, troubleshoot and improve the Service.
  • To contact the Merchant about service, security or legal matters.
  • To comply with legal obligations and enforce our Terms of Service.

Where the GDPR or UK GDPR applies, our legal bases are: performance of a contract (providing the Service to the Merchant), our legitimate interests (security, abuse prevention, product improvement), and compliance with legal obligations. For shopper data, the Merchant is responsible for establishing the legal basis and for providing any required notice or consent.

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

5. Artificial intelligence processing

The AI Insights feature sends a summary of the store’s activity to Anthropic’s Claude API to generate written recommendations. Only aggregate, non-identifying data is sent: counts of saved / moved / purchased events, conversion percentages, revenue totals, product names and prices, and a compact recent daily trend.

Customer IDs, order IDs, coupon codes and any Merchant contact details are not included in the data sent to the AI provider. Insights are generated at most once per store per calendar day and the result is cached.

6. Disclosure and sub-processors

We do not sell or rent data. We share it only with the service providers below, under contract and only as needed to run the Service:

ProviderPurposeData involved
BigCommerce, Inc.Platform the App runs on; product, cart, order and coupon operationsStore credentials, product / cart / order and coupon data
Anthropic, PBCAI Insights generationAggregate, non-identifying store metrics only
DigitalOcean, LLCApplication and database hosting (United States)All data stored by the Service

We may also disclose information when required by law, court order or a valid governmental request, to protect our rights or the safety of others, or in connection with a merger, acquisition or sale of assets (in which case we will notify affected Merchants).

7. International transfers

Our servers are located in the United States. If you access the Service from the European Economic Area, the United Kingdom, or another region with different data protection laws, your data will be transferred to and processed in the United States. Where required, such transfers rely on the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.

8. Retention and deletion

  • Saved items and event records are retained for as long as the App is installed on the store, so that the Merchant’s historical analytics remain accurate.
  • Saved items whose product no longer exists in the store catalogue are automatically deactivated and hidden.
  • When the App is uninstalled, the store is deactivated, the injected storefront scripts are removed, and no further data is collected.
  • A Merchant may request deletion of all data associated with their store at any time by e-mailing us; we will complete the deletion within 30 days, except where retention is required by law.
  • Server request logs are retained for a short period for security and debugging purposes.

9. Security

We apply technical and organisational measures appropriate to the data we handle, including:

  • All traffic served over HTTPS/TLS.
  • Per-shopper requests are authenticated with BigCommerce’s signed Current Customer token, so a shopper can only ever read or modify their own saved items and coupons.
  • Merchant dashboard access requires an authenticated, signed session bound to the specific store.
  • Session cookies are httpOnly; store credentials are never exposed to the browser.
  • Error responses exclude internal diagnostics; details are logged server-side only.
  • Access to production systems is limited to authorised personnel.

No method of transmission or storage is completely secure. We cannot guarantee absolute security, but we will notify affected Merchants and, where required, regulators, without undue delay after becoming aware of a personal data breach.

10. Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. Residents of California may request disclosure of the categories of personal information collected and request its deletion, and have the right not to be discriminated against for exercising those rights.

Shoppers: please contact the store you shopped with. That Merchant is the controller of your data; we will support them in fulfilling your request.
Merchants: contact us at admin@optimum7.com. We respond within 30 days.

If you are in the EEA or UK you also have the right to lodge a complaint with your local supervisory authority.

11. Children

The Service is a business tool and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child’s data has been provided to us, contact us and we will delete it.

12. Changes to this Policy

We may update this Policy from time to time. The “Last updated” date above will change, and material changes will be communicated to Merchants through the App dashboard or by e-mail before they take effect. Continued use of the Service after the effective date constitutes acceptance.

13. Contact us

Optimum Web Marketing Consultants LLC
admin@optimum7.com