Aida Merchant Services · Legal

Privacy Policy

1. Who is responsible

Aida Merchant Services is operated by Gabriel Gerrits in Odense, Denmark. For account administration, website communications and service operations, Aida acts as the data controller. When a merchant uses Aida to record sales and keep customer, loyalty and invoice records, the merchant is the controller of that personal data and Aida acts as processor under the Data Protection terms (see section 2a).

2. Data we process

  • Account data: name, company, email address, password credentials handled by the authentication provider, workspace membership and role.
  • Merchant business data: business, legal and trading name, company number, address, country, category, website, contact person, email and phone, number of locations, expected card volume, bank details you add for invoices, your locations, products and prices, and the status of your payment account as reported by our payment processor (for example whether card payments and payouts are enabled and which verification details are outstanding).
  • Team data: team members’ email addresses and roles, shift opening and closing records, and the staff member recorded on a sale.
  • Older workspace content: if you used the earlier Aida Analytics workspace, the companies, contacts, notes, tasks, imported CSV data and files you added there.
  • Integration data: access credentials you choose to connect, provider account identifiers, imported records, company-intelligence results and email-send metadata. Saved tokens are encrypted and are not returned to the browser.
  • Service data: necessary session cookies, request records, error logs, security events, timestamps and basic device or network information used to operate and protect the service.
  • Communications: messages and support requests sent to Aida.

2a. Your customers’ data (Aida as processor)

When you use Aida for your business, Aida stores and processes the following about your customers on your behalf. You decide what to record, and Aida uses it only to provide the service to you, as set out in the Data Protection terms.

  • Customer profiles: name, email address and phone number where you or your customer enter them, the dates of the first and latest purchase, total spend and number of purchases.
  • Loyalty: reward balances (cashback credit or points), the reward earned or redeemed on each purchase, and offer redemptions.
  • Sales: for each sale, the items, prices, VAT, discounts, tips, payment method (card, cash, split or bank transfer), status, refunds and disputes, the location and staff member, any note, and the email address used to send a receipt.
  • Business customers and invoices: company name, contact person, CVR or VAT number, EAN number, billing address and payment terms, plus invoices, B2B orders and their payment status.
  • Payment references: payment-processor identifiers for payments, charges, refunds, disputes and payouts. Card details are entered on the payment processor’s secure forms and go directly to it; Aida does not store full card numbers.

Each merchant’s customer data is kept separate from other merchants’ data. It is kept while your merchant account is active and then deleted or returned as described in the Data Protection terms, unless the law requires us to keep it. Your customers can contact you to exercise their rights, and we will help you respond.

3. Why we use data

We use account and service data to provide the service and perform our agreement with you; to secure, troubleshoot and improve Aida based on our legitimate interests in operating a reliable product; to respond to requests; and to meet legal obligations. Where consent is the appropriate basis, you may withdraw it at any time without affecting earlier processing.

4. AI and connected services

When you request AI analysis or AI-assisted CSV repair, relevant content is sent to Aida’s configured AI provider to produce the requested result. Aida currently uses OpenAI for these functions and requests that API responses are not stored by setting supported storage controls. Connected third-party services, such as our payment processor, receive or return data only when you initiate the corresponding feature. Their own terms and privacy notices also apply to your account with them.

5. Service providers and transfers

Aida does not sell personal data.

Aida uses service providers for hosting and storage, authentication, AI functions, and customer-directed integrations. These currently include Cloudflare (hosting, storage and inbound email routing), Supabase (sign-in), OpenAI (AI functions), Resend (outgoing email) and Google Workspace (company mailboxes); the full list is on the Subprocessors page. Payments, payouts and Aida’s fees are processed by our payment processor, Stripe Payments Europe, Ltd. and its affiliates, which receives the payment and account details needed to provide those services, including identity checks for connected accounts. The payment processor’s own privacy policy also applies. Some providers may process data outside the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses or another lawful safeguard.

6. Retention

Account and workspace data are retained while the account is active and for a limited period afterward when needed for recovery, security, disputes or legal duties. Support and security records are retained only as long as reasonably necessary for those purposes. Connected credentials are removed when the integration is disconnected or the related account is deleted, subject to limited backups and legal retention requirements. You may request deletion or export using the contact details below.

7. Cookies

Aida uses essential cookies for sign-in, session security and the selected workspace. The service does not currently use advertising cookies. If optional analytics or marketing cookies are introduced, this policy and any required consent controls will be updated first. The cookies we use are listed on our Cookies page.

8. Your rights

Depending on the circumstances, you may ask for access, correction, deletion, restriction, portability, or object to processing based on legitimate interests. You may also withdraw consent and complain to the Danish Data Protection Agency (Datatilsynet). We may need to verify your identity. If your request concerns data that a merchant keeps in Aida (for example because you are a customer of a business that uses Aida), contact that merchant first; we will assist them as required.

9. Changes

Material changes will be posted here with a revised effective date and, where appropriate, communicated through the service or by email.

Contact

Aida Merchant Services, operated by Gabriel Gerrits, Odense, Denmark.

Questions or requests can be sent through our Contact page or by phone on +45 25 56 07 08.