Privacy & compliance

Symbiotic is built to protect consumer autonomy and avoid deceptive design patterns.

Data minimization

We store no direct shopper contact PII. Value-exchange opt-ins are forwarded to the merchant's marketing platform; we keep only a verified flag and timestamp. Device fingerprints are one-way hashes used solely for abuse prevention.

Consent

Marketing opt-in is unbundled and never pre-checked. A discount is never conditioned on newsletter sign-up (GDPR coupling ban / DPDP unbundled consent). Accept and decline options carry equal visual weight.

CCPA / CPRA

Where a discount is offered in exchange for contact information, merchants present a Notice of Financial Incentive with material terms and a good-faith data valuation, plus a clear opt-out.

Your rights

Shopify's mandatory data-request and redaction webhooks are honored automatically. Contact your merchant to exercise access or deletion rights over any marketing consent you provided.