● Legal

Privacy Policy

Last updated: May 15, 2026

This Privacy Policy describes how Sonoma ("Sonoma," "we," "us," or "our") collects, uses, and shares information when you use our website at sonoma-system.com and our service (collectively, the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Who we are

Sonoma is operated by Mihaela Micovska, based in Skopje, North Macedonia, reachable at info@sonoma-system.com. Mihaela Micovska is the data controller for personal information processed through the Service.

2. Information we collect

We collect the following categories of information:

Account information. When you sign up, we collect your name, email address, business name, and Shopify store URL.

Payment information. Payments are processed by Lemon Squeezy, our merchant of record. We do not store credit card numbers. We receive transaction confirmations, the last four digits of your card, and billing country.

Store data. When you connect your Shopify store, we access product, order, and customer data through the Shopify Admin API under the scopes you grant during installation. This data is used to operate the Service and is not sold or shared with third parties for marketing purposes.

Marketing platform data. When you connect Instagram, TikTok, Meta Ads, Klaviyo, or other platforms, we access only the data necessary to perform the actions you request through the Service.

Communication data. Messages you send through the Telegram or WhatsApp interface, or through the dashboard, are stored to provide conversation history and improve service quality.

Usage data. We collect information about how you use the Service: pages visited, features used, time spent, and device information.

Cookies and similar technologies. See our Cookie Policy.

3. How we use information

We use information to:

  • Provide, maintain, and improve the Service
  • Process payments and manage your subscription
  • Operate AI agents that perform marketing tasks on your behalf
  • Communicate with you about your account, the Service, and updates
  • Detect and prevent fraud, abuse, and security incidents
  • Comply with legal obligations

4. AI processing

Sonoma uses third-party AI providers, including Anthropic, to operate the AI employees that perform marketing work for you. When you send a message or instruction through the Service, the content of that message and relevant store context may be sent to these providers solely to generate a response or action. These providers process this data under their own privacy commitments and do not retain content for training purposes under our agreements.

5. How we share information

We share information only as follows:

  • Service providers who help us operate the Service. Our service providers include Lemon Squeezy (payment processing, merchant of record), Vercel (hosting), Railway (backend infrastructure), Supabase (database), Anthropic (AI processing), Resend (email delivery), and analytics tools. These providers are contractually limited to processing data on our behalf.
  • Connected platforms when you instruct an AI employee to take action on a connected platform (e.g., posting to Instagram). We share only what is necessary to complete the action.
  • Legal compliance when required by law, court order, or to protect rights, property, or safety.
  • Business transfers in the event of a merger, acquisition, or sale of assets, in which case any successor will be bound by this Policy.

We do not sell personal information.

6. Data retention

We retain your information for as long as your account is active and for a reasonable period after to comply with legal obligations, resolve disputes, and enforce agreements. You can request deletion at any time by emailing info@sonoma-system.com.

7. Your rights

Depending on your location, you may have rights to:

  • Access the personal information we hold about you
  • Request correction of inaccurate information
  • Request deletion of your information
  • Object to or restrict certain processing
  • Receive a portable copy of your information
  • Withdraw consent where processing is based on consent

To exercise these rights, email info@sonoma-system.com. We will respond within 30 days.

EU/EEA residents: You have rights under the GDPR. You may also lodge a complaint with your local data protection authority.

California residents: You have rights under the CCPA, including the right to know, delete, and opt out of the sale of personal information. We do not sell personal information.

8. International data transfers

The Service operates globally. Your information may be transferred to and processed in countries other than your own. We rely on appropriate safeguards, including standard contractual clauses, where required.

9. Security

We use commercially reasonable measures to protect your information, including encryption in transit and at rest, access controls, and regular security reviews. No system is perfectly secure, and we cannot guarantee absolute security.

10. Children

The Service is not directed to children under 18. We do not knowingly collect information from children. If you believe a child has provided us information, contact info@sonoma-system.com.

11. Changes to this Policy

We may update this Policy from time to time. We will post the new version on this page and update the "Last updated" date. Material changes will be communicated by email.

12. Contact

Questions about this Policy: info@sonoma-system.com.