Effective Date: August 7, 2026 · Last Updated: August 22, 2026
This Privacy Policy explains how AgoraCrew (hereinafter referred to as "we", "us", or "our") collects, processes, stores, and protects personal data in connection with our custom software engineering services, our Shopify applications, our HubSpot and monday.com marketplace applications, enterprise integration platforms, and our corporate website at agoracrew.com.
This policy applies to:
We are committed to full compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the UK Data Protection Act 2018, and Shopify's App Store Developer Guidelines.
For data processed on behalf of our clients (e.g., via Shopify apps, enterprise integrations, or our AI Support Agent), AgoraCrew acts as a data processor. The client (merchant or business) remains the data controller and is responsible for ensuring they have a lawful basis for sharing their customers' data with us.
For any data we process independently (such as client account information, website enquiries, or contact form submissions), we act as the data controller. Our registered contact for data protection matters is:
📧 Data Protection Contact: karim@agoracrew.com
📍 Registered Address: Budapest, Hungary
🏷️ Legal entity: Karim Hamza, sole trader (egyéni vállalkozó) registered in Hungary, trading as AgoraCrew — registration number 62541190, tax number HU92198362
The data we collect depends on the service context. We access and process only the minimum data required to fulfil the specific service engagement:
| Data Category | Specific Fields | Purpose |
|---|---|---|
| Client Contact Information | Name, email address, company name, phone number | Project communication, scoping, invoicing, and ongoing support |
| Website Enquiries | Name, email, project description (via contact form) | Respond to inbound project enquiries and provide scoping outlines |
| End Customer Identity (via Shopify apps / AI Support Agent) | First name, last name, email address | Personalise support responses, identify the customer within the merchant's CRM, and deliver AI-powered customer support |
| Order Data (via Shopify apps / AI Support Agent) | Order number, order status, tracking information | Fulfil order tracking lookups, operational exception reporting, and provide shipment updates |
| Chat Interactions (via AI Support Agent) | Messages exchanged during support conversations | Deliver real-time AI-powered support, resolve customer queries, and trigger growth workflows (cart recovery, win-back) |
| Integration Credentials (via AGORA Engine) | OAuth tokens, API keys (encrypted) | Authenticate and maintain real-time data sync between platforms (HubSpot, QuickBooks, Shopify, etc.) |
| Customer & Billing Contact Identity (via ARBridge for QuickBooks) | Customer name; billing contact email and name | Create and update the corresponding Company and Contact records in that same customer's own HubSpot account |
| Invoice & Payment Data (via ARBridge for QuickBooks) | Invoice amounts, dates, and status; payments applied against invoice balances | Create and update HubSpot Invoice records reflecting the customer's QuickBooks accounts-receivable activity |
| Derived AR Metrics (via ARBridge for QuickBooks) | AR aging buckets, credit-status flag (Good/Watch/Hold), lifetime revenue, trailing-12-month revenue, last-payment info | Computed from the synced QuickBooks data and written to the HubSpot Company record to give the customer visibility into their own receivables |
| Customer & Job Identity (via XSync for QuickBooks Desktop) | Customer and job name, including the QuickBooks customer:job hierarchy; billing contact name and email; billing address | Create and update the corresponding items on that same customer's own monday.com boards |
| Transaction & Item Data (via XSync for QuickBooks Desktop) | Invoice, estimate and sales order amounts, dates, status and balances; item names, descriptions and prices; free-text memos | Create and update board items reflecting the customer's QuickBooks activity, and keep balances current as payments are recorded against them in QuickBooks |
| Derived AR Metrics (via XSync for QuickBooks Desktop) | Credit-status flag (Good/Watch/Hold), AR aging, lifetime revenue and trailing-12-month revenue, computed from the synced QuickBooks data | Offered as mappable board columns, so a customer can see a receivables picture beside the work on their own boards. Written only into that same customer's own monday.com account, and only for the columns they choose to map |
| monday.com Account Identity (via XSync for QuickBooks Desktop) | monday.com account identifier and name; identifier and name of the user who authorised the connection | Identify which monday.com account an installation belongs to, keep each customer's data separated from every other customer's, and record who connected a QuickBooks company file |
🚫 We do not collect, store, or process payment details, credit card numbers, billing addresses, passwords, or browsing behaviour beyond what is strictly necessary for analytics (see Section 11).
🔒 ARBridge for QuickBooks — architecture note: ARBridge is a HubSpot Marketplace app. For each customer who installs it, it reads Customer, Invoice, and Payment records from that customer's own QuickBooks Desktop company file via QuickBooks Web Connector (using the qbXML protocol) and writes a derived financial picture into that same customer's own HubSpot account. Data is never aggregated or shared across customers, and is never sold or used for any purpose beyond this sync. ARBridge only ever issues read-only qbXML "Query" requests — there is no code path in the product capable of adding, modifying, or deleting anything in a customer's QuickBooks file; this is not a configuration setting, the write capability does not exist in the code. ARBridge stores two categories of credentials, both encrypted at rest (AES-256): a QuickBooks Web Connector username/password pair generated by ARBridge for that one connection, and a HubSpot OAuth refresh token, which is rotated. ARBridge never sees or stores a customer's actual HubSpot login credentials — access is via OAuth only. All data in transit uses TLS.
🔒 XSync for QuickBooks Desktop — architecture note: XSync for QuickBooks Desktop is a monday.com marketplace app. For each customer who installs it, it reads Customer, Job, Invoice, Estimate, Sales Order and Item records from that customer's own QuickBooks Desktop Enterprise company file via QuickBooks Web Connector (using the qbXML protocol) and creates and updates items on that same customer's own monday.com boards, according to a field mapping that customer configures. Data is never aggregated or shared across customers, and is never sold or used for any purpose beyond this sync. Like its HubSpot counterpart, it only ever issues read-only qbXML "Query" requests — there is no code path in the product capable of adding, modifying, or deleting anything in a customer's QuickBooks file; this is not a configuration setting, the write capability does not exist in the code. Credentials are encrypted at rest with AES-256-GCM under a versioned key ring: a QuickBooks Web Connector username/password pair generated for that one connection, and a monday.com OAuth refresh token, which is rotated on every use. The app never sees or stores a customer's actual monday.com login credentials — access is via OAuth only. All data in transit uses TLS. One consequence worth stating plainly: QuickBooks sends whole record types, so records of a type a customer has not enabled or whose plan does not yet include it are still read and held in staging, encrypted, rather than being discarded. They are not sent anywhere. This is what allows an upgrade or an un-pause to take effect on the next sync instead of requiring a fresh read of the customer's entire history, and that staged data is erased on the same ten-day clock as everything else.
We adhere strictly to the GDPR principle of data minimization (Article 5(1)(c)). This means:
In accordance with transparency requirements under GDPR (Articles 13–14) and Shopify's App Store guidelines, we inform all users of the following:
AI Interaction Notice: Several of our products and services use AI-powered automation. This includes our AI Support Agent & Growth Engine (which handles customer support conversations), our Order Exceptions Copilot (which analyses order data for operational issues), and AI components within custom software we build for clients. These AI systems process data to generate responses, identify patterns, and automate workflows.
Our AI systems operate under the following principles:
To deliver our software engineering services and AI-powered products, we work with the following categories of subprocessors:
| Subprocessor | Purpose | Data Shared |
|---|---|---|
| Anthropic (AI model infrastructure) — AI Support Agent only | Power AI support responses and exception analysis for the AI Support Agent | Customer name, email, order number, inquiry content (per-request, not persisted, not used for model training) |
| Cloudflare (edge network and TLS) | Serve agoracrew.com and the application endpoints; terminate TLS and filter abusive traffic |
Request metadata and, in transit only, the contents of requests to our applications |
| Shopify API | Retrieve order status, tracking data, and merchant store information | Order number (lookup only) |
| HubSpot / QuickBooks / Salesforce APIs | Enterprise data sync and integration services | Client-defined data mappings (varies per integration project) |
| HubSpot API (ARBridge for QuickBooks) | Create and update Company, Contact, and Invoice records within a single customer's own HubSpot account | Company/contact identity, invoice and payment data, and derived AR metrics (aging, credit status, lifetime and trailing-12-month revenue) — accessed and written only within that same customer's own HubSpot account via OAuth |
| QuickBooks Web Connector (ARBridge for QuickBooks) | Read-only qbXML queries against a customer's own QuickBooks Desktop company file | Customer, Invoice, and Payment records — query only; ARBridge has no code path capable of creating, modifying, or deleting QuickBooks data |
| monday.com API (XSync for QuickBooks Desktop) | Create and update board items within a single customer's own monday.com account, and read their boards and columns so QuickBooks fields can be mapped onto them | Customer and job identity, invoice, estimate, sales order and item records, and derived AR metrics (credit status, aging, lifetime and trailing-12-month revenue) — written only into that same customer's own monday.com account via OAuth. Nothing is ever written back into QuickBooks. |
| monday.com (identity and billing — XSync for QuickBooks Desktop) | Identify which monday.com account and user an installation belongs to, and administer the subscription through monday.com's own billing | monday.com account identifier and name, and the identifier and name of the user who authorised the connection. Payment details are handled entirely by monday.com and never reach us. |
| Render (application hosting) | Host the accounting integrations (ARBridge for QuickBooks and XSync for QuickBooks Desktop), their background jobs, and their managed PostgreSQL databases, in the EU | Encrypted data at rest and in transit |
Fontshare (api.fontshare.com) |
Serve the typefaces used on agoracrew.com and on our product documentation pages | No personal data is sent. As with any externally hosted font, the visitor's browser discloses its IP address and user agent to the font host when it requests the file |
| Formspree | Process contact form submissions | Name, email, project description |
| Vercel | Website hosting and anonymised analytics | Anonymised page view data (no PII) |
XSync for QuickBooks Desktop sends no data to any language model. Its AI features are exposed as tools for monday.com's own assistant: the app returns figures from your synced QuickBooks data, and monday's assistant writes the sentence. There is no AI provider in that application's data path, and none of your QuickBooks data reaches Anthropic or any other model provider through it.
All subprocessors are bound by data processing agreements. Anthropic does not retain, cache, or store customer data beyond the time required to process an individual API request, and does not use it to train models.
We apply strict data retention practices:
contact.privacyDeletion event (an end-customer of our customer exercising their GDPR right to be forgotten), ARBridge permanently purges that contact's personal data (email address and name) from its own database and durably prevents QuickBooks from re-populating that same data on a future sync.Our processing of personal data is based on the following lawful grounds under GDPR Article 6:
If you are located in the European Economic Area (EEA) or the United Kingdom, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us at karim@agoracrew.com. We will respond to all valid requests within 30 calendar days. If your request is complex, we will inform you of any extension (up to a maximum of 90 days total) as permitted under GDPR.
You also have the right to lodge a complaint with your local supervisory authority. For Hungary, this is the Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH).
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, or destruction:
Our website uses Vercel Web Analytics to collect anonymised, aggregate page view data. This service does not use cookies, does not track individual users, and does not collect personally identifiable information.
We may use a language preference cookie (agoracrew_lang_pref) to remember your language selection between English and French versions of our website. This cookie is strictly functional and contains no personal data.
Our AI-powered chat widget may use session-scoped storage to maintain conversation context during your visit. This data is not persisted after the session ends and is not used for tracking or advertising purposes.
We reserve the right to update this Privacy Policy at any time. When we make material changes, we will update the "Last Updated" date at the top of this page. For significant changes that affect how we process personal data, we will provide notice through our website or via direct communication to affected clients.
We encourage you to review this page periodically to stay informed about our data practices.
If you have any questions, concerns, or requests related to this Privacy Policy or your personal data, please contact us:
Our data protection team is available to respond to all enquiries regarding the processing of personal data, data subject access requests, or any concerns about how your information is handled.
✉️ karim@agoracrew.com