Privacy Policy for The GPT Shop

Last Updated: 05/28/2025

thegptshop.online ("The GPT Shop", "we", "us", or "our"), a business based in Mexico, operates the website thegptshop.online (the "Service").

This Privacy Policy informs you of our policies regarding the collection, use, and disclosure of personal data when you use our Service and the choices you have associated with that data.

We use your data to provide and improve the Service. By using the Service, you agree to the collection and use of information in accordance with this policy.

We are committed to protecting your privacy and handling your data in an open and transparent manner. We aim to comply with applicable data protection laws, including considering principles from regulations like the General Data Protection Regulation (GDPR) as a standard for best practice, alongside Mexican data protection laws.

1. Information Collection and Use

We collect several different types of information for various purposes to provide and improve our Service to you.

Types of Data Collected

Below are the types of data we collect:

  • Personal Data (for Purchase and Communication):

    • Email Address: When you purchase Access Codes or sign up for our waitlist or educational materials, we collect your email address to deliver the codes, send purchase confirmations, provide customer support, and send informational or marketing communications (with your consent).
    • Payment Information: When you make a purchase, your payment is processed by Stripe, our third-party payment processor. We do not directly collect or store your full credit card or debit card numbers. Stripe may collect information necessary to process your payment, and their use of your information is governed by their privacy policy.
    • Communication Data: If you contact us directly (e.g., via email for support), we may receive additional information about you such as your name, email address, the contents of the message and/or attachments you may send us, and any other information you may choose to provide.
  • Usage Data (Website Analytics):

    • We may also collect information on how the Service is accessed and used ("Usage Data"). This Usage Data may include information such as your computer's Internet Protocol address (e.g., IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers, and other diagnostic data.
    • This data is typically collected through cookies and similar tracking technologies (see Section 5 below).

2. How We Use Your Information

We use the collected data for various purposes:

  • To provide and maintain our Service (e.g., process your purchases and deliver Access Codes).
  • To notify you about changes to our Service.
  • To provide customer support.
  • To gather analysis or valuable information so that we can improve our Service.
  • To monitor the usage of our Service.
  • To detect, prevent, and address technical issues.
  • To send you news, special offers, and general information about other goods, services, and events which we offer that are similar to those that you have already purchased or enquired about, unless you have opted not to receive such information. This includes educational materials about creating and monetizing Custom GPTs.
  • To manage your subscription to our mailing lists (e.g., via MailerLite), including processing double opt-ins and unsubscribe requests.

3. Legal Basis for Processing Personal Data

(Especially if targeting individuals in GDPR-relevant areas)

If you are from the European Economic Area (EEA) or other regions with similar data protection laws, our legal basis for collecting and using the personal information described in this Privacy Policy depends on the Personal Data we collect and the specific context in which we collect it:

  • Contract: Processing your email to fulfill a purchase (deliver Access Codes) is necessary for the performance of a contract with you.
  • Consent: We will rely on your consent to send you marketing or educational emails. You can withdraw your consent at any time (e.g., via an unsubscribe link).
  • Legitimate Interests: Processing Usage Data for website analytics or using email for essential service communications (e.g., security alerts, important updates about your purchase if not marketing) may be based on our legitimate interests, provided these are not overridden by your data protection interests or fundamental rights and freedoms.
  • Legal Obligations: We may process your data if necessary to comply with a legal obligation.

4. Data Sharing and Disclosure

We do not sell your Personal Data.

We may share your Personal Data in the following limited circumstances:

  • Service Providers: We may employ third-party companies and individuals to facilitate our Service ("Service Providers"), provide the Service on our behalf, perform Service-related services, or assist us in analyzing how our Service is used. These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

    • Stripe: For payment processing. (Review Stripe's Privacy Policy)
    • MailerLite: For managing email communications, educational sequences, and subscriptions, including double opt-in and unsubscribe functionalities. (Review MailerLite's Privacy Policy)
    • Vercel: Our website hosting provider. (Review Vercel's Privacy Policy)
    • (No other analytics providers currently specified)
  • Legal Requirements: We may disclose your Personal Data in the good faith belief that such action is necessary to:

    • To comply with a legal obligation (e.g., if required by Mexican law or other applicable jurisdictions).
    • To protect and defend the rights or property of The GPT Shop.
    • To prevent or investigate possible wrongdoing in connection with the Service.
    • To protect the personal safety of users of the Service or the public.
    • To protect against legal liability.
  • Business Transfers: If we are involved in a merger, acquisition, or asset sale, your Personal Data may be transferred. We will provide notice before your Personal Data is transferred and becomes subject to a different Privacy Policy.

5. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track the activity on our Service and we hold certain information.

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies are also used such as beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we may use:

  • Session Cookies: We use Session Cookies to operate our Service.
  • Preference Cookies: We use Preference Cookies to remember your preferences and various settings.
  • Security Cookies: We use Security Cookies for security purposes.
  • (No specific analytics cookies specified if no provider is listed above)

6. Data Security

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data (e.g., HTTPS for our website, relying on secure third-party processors like Stripe and MailerLite), we cannot guarantee its absolute security.

7. Data Retention

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy.

We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws in Mexico), resolve disputes, and enforce our legal agreements and policies.

For marketing communications, we will retain your email address until you opt-out or unsubscribe.

8. Your Data Protection Rights

Depending on your location and applicable laws, you may have certain data protection rights. These may include:

  • The right to access: You have the right to request copies of your personal data.
  • The right to rectification: You have the right to request that we correct any information you believe is inaccurate or complete information you believe is incomplete.
  • The right to erasure (right to be forgotten): You have the right to request that we erase your personal data, under certain conditions.
  • The right to restrict processing: You have the right to request that we restrict the processing of your personal data, under certain conditions.
  • The right to object to processing: You have the right to object to our processing of your personal data, under certain conditions (e.g., for direct marketing).
  • The right to data portability: You have the right to request that we transfer the data that we have collected to another organization, or directly to you, under certain conditions.
  • The right to withdraw consent: If we are relying on your consent to process your personal data, you have the right to withdraw that consent at any time.

If you wish to exercise any of these rights, please contact us at support@thegptshop.online. We will respond to your request in accordance with applicable data protection laws. You may also have the right to lodge a complaint with a data protection supervisory authority in your jurisdiction.

9. International Data Transfers

Your information, including Personal Data, may be transferred to — and maintained on — computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction (e.g., our servers are hosted by Vercel in the USA, MailerLite servers may be in the EEA or USA).

If you are located outside the United States and Mexico and choose to provide information to us, please note that we transfer the data, including Personal Data, to the United States and Mexico for processing. Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

10. Children's Privacy

Our Service does not address anyone under the age of 18 ("Children").

We do not knowingly collect personally identifiable information from anyone under the age of 18. If you are a parent or guardian and you are aware that your Child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

11. Links to Other Sites

Our Service may contain links to other sites that are not operated by us (e.g., links to Custom GPTs, Stripe, MailerLite). If you click a third-party link, you will be directed to that third party's site.

We strongly advise you to review the Privacy Policy of every site you visit. We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

12. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

13. Contact Us

If you have any questions about this Privacy Policy, please contact us:

  • By email: support@thegptshop.online

Note to Business Owner:

  • The placeholders for date and company name have been updated in the main text. The contact email is also updated.
  • The placeholder for other analytics providers has been noted as not currently specified. If you add any, this section should be updated.
  • Ensure you have current links to the privacy policies of Stripe, MailerLite, Vercel, and any other significant third-party service providers handling user data.
  • This is a draft and should be reviewed by a legal professional familiar with Mexican law, GDPR, and other relevant international data protection regulations.