Privacy Policy
Effective Date: 1 May 2026
1. Introduction and Identity of the Data Controller
ShareShift ApS ("ShareShift", "we", "our", or "us") is committed to protecting the privacy and personal data of all individuals who interact with our services. This Privacy Policy describes how we collect, use, store, share, and protect personal data in connection with the ShareShift market intelligence platform ("Service"), our website (shareshift.io), and any related communications.
SHARESHIFT - FZCO acts as the data controller in respect of personal data collected from website visitors, account holders, Users, and prospective customers. Although incorporated in the UAE, SHARESHIFT - FZCO offers its services to customers in the EU/EEA and processes personal data of EU/EEA data subjects. SHARESHIFT - FZCO is therefore subject to the GDPR by virtue of its extra-territorial scope under Article 3(2) GDPR. SHARESHIFT - FZCO has appointed an EU representative as required under Article 27 GDPR; details are available upon request at [email protected].
Data Controller: SHARESHIFT - FZCO, IFZA Properties, Dubai Silicon Oasis, Dubai, UAE
Data Protection Contact: [email protected]
2. Scope of This Policy
This Policy applies to:
-
Visitors to shareshift.io and app.shareshift.io;
-
Individuals who register for or use the ShareShift platform;
-
Prospective customers who request access, demos, or contact us for information;
-
Business contacts of ShareShift.
This Policy does not apply to the data that ShareShift collects and processes as part of its market intelligence outputs (i.e., publicly available technical signals such as DNS, HTTP, and TLS data). ShareShift's platform data does not contain personally identifiable information and is processed in accordance with our Methodology, available at shareshift.io/methodology.
3. Personal Data We Collect
ShareShift collects and processes the following categories of personal data:
| Category | Data Elements | Purpose | Legal Basis |
|---|---|---|---|
| Account Data | Name, email, company, job title | Account creation and management | Contract performance (Art. 6(1)(b) GDPR) |
| Billing Data | Billing address, VAT number | Invoice generation, tax compliance | Legal obligation (Art. 6(1)(c) GDPR) |
| Usage Data | Platform activity, feature usage, logs | Service improvement, security, support | Legitimate interests (Art. 6(1)(f) GDPR) |
| Technical Data | IP address, browser, device info | Security, fraud prevention | Legitimate interests (Art. 6(1)(f) GDPR) |
| Communication Data | Emails, support tickets | Customer support, service communications | Contract performance / Legitimate interests |
ShareShift does not intentionally collect special categories of personal data (as defined under Article 9 GDPR), including health data, racial or ethnic origin, political opinions, religious beliefs, or biometric data. If you believe you have inadvertently provided such data, please contact us immediately at [email protected].
4. How We Collect Personal Data
4.1 Directly from You
-
When you register for an account or request access to the platform;
-
When you contact us by email, form, or live chat;
-
When you subscribe to our newsletter or Intelligence reports;
-
When you attend our webinars or events.
4.2 Automatically
-
Through cookies and similar tracking technologies when you visit our website (see Section 10 on Cookies);
-
Through platform usage logs when you use the Service;
-
Through security systems including IP logging.
4.3 From Third Parties
-
From payment processors (e.g., Stripe) in connection with billing;
-
From LinkedIn or other professional networks where you have made your information publicly available, for marketing outreach purposes.
5. Legal Bases for Processing
ShareShift processes personal data only where a valid legal basis under Article 6 GDPR exists. The applicable bases are:
-
Contract performance (Article 6(1)(b)): Processing necessary to fulfil our contractual obligations to you, including providing and administering the Service.
-
Legal obligation (Article 6(1)(c)): Processing required to comply with applicable legal and regulatory obligations, including tax, accounting, and anti-money laundering requirements.
-
Legitimate interests (Article 6(1)(f)): Processing necessary for our legitimate business interests, including improving the Service, fraud prevention, security monitoring, and direct marketing to business contacts, where such interests are not overridden by your rights and freedoms.
-
Consent (Article 6(1)(a)): Where we rely on consent (e.g., for non-essential cookies or direct marketing to individuals), you may withdraw consent at any time without affecting the lawfulness of prior processing.
6. How We Use Your Personal Data
We use personal data for the following purposes:
-
Providing, maintaining, and improving the Service;
-
Creating and managing your account;
-
Processing payments and issuing invoices;
-
Communicating with you regarding your account, subscription, and service updates;
-
Providing customer support and responding to enquiries;
-
Sending product updates, market intelligence newsletters, and promotional communications (where you have not opted out);
-
Conducting research and analytics to improve the platform experience;
-
Complying with legal and regulatory obligations;
-
Detecting, investigating, and preventing security threats, fraud, and abuse;
-
Enforcing our Terms and Conditions.
7. Data Sharing and Recipients
7.1 We Do Not Sell Your Data
ShareShift does not sell, rent, or trade your personal data to third parties for their own marketing purposes.
7.2 Authorised Recipients
We may share your personal data with:
-
Service Providers: Third-party vendors who process data on our behalf (e.g., cloud infrastructure, payment processors, email delivery, customer support tools). These parties are bound by data processing agreements and may only process data for the specified purpose.
-
Group Companies: Any affiliated entities of ShareShift, subject to equivalent data protection safeguards.
-
Professional Advisors: Legal, accounting, and auditing advisors, subject to professional confidentiality obligations.
-
Regulatory Authorities: Where required by applicable law, court order, or legitimate regulatory request.
-
Business Transfers: In the context of a merger, acquisition, restructuring, or asset sale, personal data may be transferred as part of the business assets, with notification to affected individuals.
7.3 No Third-Country Transfers Without Safeguards
ShareShift stores and processes all data entirely within the European Union. Where any transfer to a third country outside the EEA is required (e.g., to a service provider), ShareShift ensures appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or an adequacy decision.
8. Data Retention
ShareShift retains personal data only for as long as necessary to fulfil the purposes for which it was collected, or as required by applicable law. Our general retention periods are:
-
Account and contract data: For the duration of the customer relationship and for 5 years thereafter, for legal and audit purposes.
-
Billing and financial records: 7 years, as required under UAE accounting and tax law.
-
Usage logs and technical data: Up to 12 months for security and service improvement purposes.
-
Marketing communications: Until you opt out, then promptly deleted from active marketing lists (suppression records may be maintained to honour opt-outs).
Upon expiry of the applicable retention period, data is securely deleted or anonymised in a manner that prevents re-identification.
9. Your Rights as a Data Subject
You have the following rights in relation to your personal data under GDPR, which you may exercise by contacting us at [email protected]:
-
Right of Access (Article 15): You may request a copy of the personal data we hold about you and information about how it is processed.
-
Right to Rectification (Article 16): You may request correction of inaccurate or incomplete personal data.
-
Right to Erasure (Article 17): You may request deletion of your personal data in certain circumstances, such as where the data is no longer necessary for its original purpose or where you withdraw consent.
-
Right to Restriction of Processing (Article 18): You may request that we limit processing of your personal data in certain circumstances.
-
Right to Data Portability (Article 20): Where processing is based on consent or contract and carried out by automated means, you may request your data in a structured, machine-readable format.
-
Right to Object (Article 21): You may object to processing based on legitimate interests, including for direct marketing purposes, at any time.
-
Right Not to Be Subject to Automated Decision-Making (Article 22): We do not make solely automated decisions that produce significant legal or similarly significant effects.
-
Right to Lodge a Complaint: You have the right to lodge a complaint with your national supervisory authority. In Denmark, this is The UAE Data Office (dataoffice.gov.ae) and, where applicable, the relevant EU supervisory authority in the jurisdiction of the affected data subjects. If you are located in another EU/EEA Member State, you may contact your local supervisory authority.
We will respond to all valid requests within one calendar month. For complex or multiple requests, we may extend this period by a further two months with notification.
10. Cookies and Tracking Technologies
10.1 What We Use
ShareShift uses cookies and similar technologies on our website and platform. These include:
-
Strictly Necessary Cookies: Required for the operation of the website and platform (e.g., session management, authentication). These cannot be disabled.
-
Functional Cookies: Used to remember your preferences and settings.
-
Analytics Cookies: Used to understand how visitors use our website, allowing us to improve user experience. We use privacy-respecting analytics tools hosted within the EU.
-
Marketing Cookies: Used to deliver relevant communications. We obtain consent before placing non-essential cookies.
10.2 Your Choices
You can manage your cookie preferences via the cookie consent banner presented on your first visit to our website. You may also configure your browser to reject cookies, although this may affect certain functionality.
11. Security
ShareShift implements appropriate technical and organisational measures to protect personal data against unauthorised access, disclosure, alteration, or destruction. These measures include:
-
Encryption of data in transit (TLS) and at rest;
-
Access controls and role-based permissions;
-
Regular security assessments and vulnerability testing;
-
Employee training on data protection obligations;
-
Data processing entirely within EU borders.
In the event of a personal data breach that poses a risk to your rights and freedoms, ShareShift will notify the relevant supervisory authority within 72 hours and, where required, affected individuals without undue delay.
12. Platform Intelligence Data
ShareShift's core market intelligence product is built exclusively on publicly available technical signals derived from DNS zone files, HTTP responses, TLS certificates, and similar infrastructure metadata. This data does not constitute personal data as defined by GDPR. ShareShift does not process, store, or include any PII in its market intelligence outputs.
ShareShift's data collection methodology is fully documented and publicly available at shareshift.io/methodology. If you believe any data relating to you appears in our platform, please contact [email protected] and we will investigate promptly.
13. Children's Privacy
The Service is not directed at individuals under the age of 18. ShareShift does not knowingly collect personal data from children. If we become aware that we have inadvertently collected such data, we will delete it promptly.
14. Changes to This Privacy Policy
ShareShift reserves the right to update this Privacy Policy from time to time. Material changes will be communicated to registered users by email and/or by a prominent notice on the platform at least 30 days before the changes take effect. The "Effective Date" at the top of this document indicates when this version was last updated. We encourage you to review this Policy periodically.
15. Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or our data processing practices, please contact:
SHARESHIFT - FZCO — Data Protection
Email: [email protected]
Website: https://shareshift.io/legal/privacy
For formal written correspondence, please contact us via the email address above and we will provide a postal address upon request.
You also have the right to contact the Danish Data Protection Authority (Datatilsynet) at any time:
UAE Data Office | www.dataoffice.gov.ae | For EU data subjects: your local EU supervisory authority
Last updated: 1 May 2026