Legal

Privacy Policy

Effective and last updated: 5 September 2026

This policy explains how Hypus Ltd, trading as CM6, collects, uses, shares and protects personal data when you visit cm-six.com, request a demo, or use the CM6 application (the Shopify app and the dashboard at app.cm-six.com). It also explains the rights you have. It is written to meet the UK GDPR, the Data Protection Act 2018, the EU GDPR where it applies, and Shopify’s requirements for apps that access protected customer data.

1. Who we are

CM6 is a trading name of Hypus Ltd (“CM6”, “we”, “us”), a company registered in England and Wales under company number 09256123, with its registered office at Fourth Floor, 33 Cavendish Square, London, England, W1G 0PW. We provide contribution-profit analytics for e-commerce businesses.

We have not appointed a statutory data protection officer. All privacy enquiries, including requests to exercise your rights, should be sent to info@cm-six.com or to the postal address above, marked “Data Protection”.

2. Our roles: controller and processor

We act in two different capacities, and this matters for which rules apply:

  • Controller. For website visitors, people who contact us or request a demo, and the people who sign in to and use the CM6 application (merchant users), we decide how and why personal data is used. Sections 3 to 14 apply.
  • Processor. For the store data we receive from a merchant’s Shopify store (which includes personal data about the merchant’s own customers), the merchant is the controller and we process that data only on the merchant’s instructions under our Data Processing Addendum. Section 5 describes that processing.

If you are a customer of an online store that uses CM6 and you want to exercise your rights over your data, please contact that store. It is the controller of your data, and we will act on its instructions. Shopify Inc. is an independent controller of the data it holds and its privacy policy applies to your use of Shopify.

3. Personal data we collect as a controller

Website visitors

  • Aggregated, cookieless analytics — page views, referring site, approximate country, browser and device type, collected through Vercel Web Analytics without cookies or persistent identifiers.
  • Server and security logs — IP address, user agent, requested URL and timestamp, retained briefly to run and protect the website.

Demo requests and other enquiries

  • Name, work email address, company, role, store URL, approximate order volume and the message you send us, together with our correspondence with you.

Merchant users of the CM6 application

  • Sign-in and identity — when you sign in with Google we receive your email address, name and profile picture from Google. When you open CM6 from the Shopify admin we receive your store domain and the identity of the Shopify staff member opening the app. We also hold your session, the stores you have access to and your role within each store.
  • Team and recipients — the email addresses of colleagues you invite and of the people you choose to receive alerts, digests and reports. You are responsible for having the right to give us these addresses.
  • Configuration and business inputs — the cost, fee, tax, fulfilment and allocation settings you enter, any brand or product notes you give the AI features, and files you upload such as cost spreadsheets, carrier invoices and accounting exports. These files may incidentally contain personal data about your staff, suppliers or customers.
  • Usage and audit records — actions taken in the application (sign-ins, settings changes, syncs, exports, sharing), timestamps, IP address and browser, kept to secure the service and support you.
  • Billing status — your subscription plan, status and monthly order counts, received from Shopify. Shopify handles payment; we never receive or store card or bank details.
  • Communications — a record of the emails we send you and your replies, and support conversations.

4. Why we use it and our legal bases

PurposeLegal basis (UK/EU GDPR Article 6)
Providing the CM6 application, onboarding, support and the demo you requestedPerformance of a contract, or steps taken at your request before entering one
Securing the service, preventing fraud and abuse, keeping audit recordsOur legitimate interests in running a secure service, and legal obligations
Billing through Shopify and keeping financial recordsPerformance of a contract; legal obligations
Service messages: onboarding, alerts you configured, export and report notifications, billing and important changesPerformance of a contract
Product news and optional insight digestsOur legitimate interest in keeping business customers informed; you can opt out at any time
Improving the service using aggregated, de-identified usage statisticsOur legitimate interests in developing the product
Responding to legal requests and establishing or defending legal claimsLegal obligations; legitimate interests

Where we rely on legitimate interests we have balanced them against your interests and rights. You can object at any time (section 10).

5. Store data we process for merchants

When a merchant installs CM6, Shopify grants us read-only access under the scopes shown on the install screen: orders, customers, products, and Shopify Payments payouts. We copy the relevant records from the store into a Google BigQuery dataset dedicated to that store and enrich them with the merchant’s cost configuration. The records include:

  • Orders — order and line-item details, prices, discounts, taxes, refunds and returns, shipping address, fulfilment and shipment details, payment gateway and method, and the Shopify customer identifier.
  • Customers — name, email address, phone number, addresses, tags and order history.
  • Products — products, variants, SKUs and unit costs.
  • Payouts and fees — Shopify Payments payout, fee and balance records.
  • Advertising spend — campaign-level cost and performance data from Meta, Google and Microsoft advertising accounts the merchant connects through Fivetran. This is aggregate campaign data and does not identify individual shoppers.

We process store data only to provide the CM6 service to that merchant: calculating order-level contribution profit, building dashboards, breakdowns, cohorts, simulations, alerts, exports and AI-generated insights, and for the security and support of the service. We do not sell it, use it for advertising, or use it to build profiles of the merchant’s customers, and we do not combine one merchant’s data with another’s. Each store’s data is held in its own dataset and access is authorised per store.

We honour Shopify’s mandatory privacy webhooks: when a merchant asks Shopify for a customer’s data we provide it to the merchant within 30 days; when a merchant asks for a customer to be erased we delete that customer’s record from the customer tables promptly, retaining order records only in pseudonymised form (an internal customer reference and coarse shipping geography, without name or contact details) because they are needed for the integrity of the merchant’s financial reporting; and when a store uninstalls CM6 we delete its dataset and stored configuration when Shopify sends the shop-redaction notice, which Shopify issues 48 hours after uninstallation.

6. AI features

Some features use large language models provided by OpenAI and Anthropic to generate insights, read uploaded documents and answer questions about a store’s economics. For these features we send the provider order-level cost and profitability figures, pseudonymous customer references, coarse geography (country and region), the merchant’s configuration and brand notes, and the content of documents the merchant uploads for extraction, such as carrier invoices or accounting exports. We do not send customer names, email addresses, phone numbers or street addresses from customer records. We use these providers under business API terms that prohibit them from using the data to train their models. AI outputs are suggestions for a human to review; CM6 does not make automated decisions with legal or similarly significant effects on any individual.

7. Who we share data with

We share personal data only as described here. We do not sell personal data.

  • Service providers (sub-processors) acting on our instructions: Google Cloud (hosting, data warehouse, database, key management and sign-in), Fivetran (advertising-platform data connectors), Brevo (email delivery), OpenAI and Anthropic (AI features), and Vercel (website hosting and cookieless analytics). The current list, with locations, is in Annex 3 of the Data Processing Addendum.
  • Shopify, which operates the app platform, billing and the webhooks that connect a store to CM6, as an independent controller.
  • People you choose — your team members, the alert and report recipients you configure, and anyone you send a report share link to. A share link is a public snapshot accessible to anyone who has the link for 30 days, after which it expires.
  • Professional advisers, insurers, regulators, courts and law enforcement where the law requires or permits it, or to protect our rights.
  • A buyer or successor if our business is sold or reorganised, on terms that respect this policy.

8. Where data is stored and international transfers

CM6 runs on Google Cloud. Application services and our operational database are hosted in Google’s London and European Union regions. Store data warehouses (Google BigQuery datasets) are hosted in Google’s United States multi-region, and may be hosted in the United Kingdom or European Union where we have agreed that with a merchant. Our AI providers process data in the United States. Fivetran processes data in the United States and the European Union, Brevo in the European Union, and Vercel in the United States.

Where personal data leaves the United Kingdom or the European Economic Area we ensure it is protected by an appropriate safeguard: the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses, the EU Standard Contractual Clauses, or, where the recipient is certified under the EU-US Data Privacy Framework and its UK Extension, that certification. You can ask us for details of the safeguard that applies to a particular transfer.

9. How long we keep data

DataRetention
Demo requests and enquiriesUp to 24 months after our last contact, unless you become a customer
Merchant user accounts, team and recipient listsWhile the account is active, then deleted within 12 months of the last store being removed
Store data and configurationWhile CM6 is installed; deleted on receipt of Shopify’s shop-redaction notice (48 hours after uninstall)
Customer records subject to an erasure requestDeleted promptly; orders retained pseudonymised
Report share linksExpire automatically 30 days after creation
Exports you generateAvailable for a short period through a link sent only to you, then deleted
Usage and audit records, email recordsLife of the account and up to 12 months after
Security and server logs, database backupsUp to 30 days
Records of data-protection requests and their handling3 years, as evidence of compliance
Billing and accounting records6 years after the end of the financial year, as required by UK law

10. Your rights

Under the UK GDPR and, where it applies, the EU GDPR you have the right to: access the personal data we hold about you; have inaccurate data corrected; have data erased; restrict or object to processing, including processing based on legitimate interests; receive the data you provided in a portable format; withdraw consent where we rely on it; and not be subject to solely automated decisions with legal or similarly significant effects. You can opt out of non-essential emails using the unsubscribe link in any such email or by contacting us.

To exercise a right, email info@cm-six.com. We may ask you to verify your identity. We respond within one month, extendable by two further months for complex requests, and we will tell you if that is the case. There is no fee unless a request is manifestly unfounded or excessive.

You also have the right to complain to a supervisory authority. In the United Kingdom that is the Information Commissioner’s Office (ico.org.uk). In the European Union you may complain to the authority in the member state where you live or work. We would appreciate the chance to address your concern first.

11. Security

We protect data using measures appropriate to the risk, including encryption in transit (TLS) and at rest, a dedicated dataset for each store with per-store authorisation, least-privilege access for our staff using individually identified accounts, management of secrets and encryption keys in Google Cloud Secret Manager and Cloud KMS, access and audit logging, read-only Shopify access, and single-use, time-limited links for sensitive actions. If a personal data breach is likely to result in a risk to individuals we will notify the affected merchants without undue delay and the relevant supervisory authority within 72 hours, as the law requires.

12. Cookies and analytics

Our website (cm-six.com) does not set cookies and does not use advertising or cross-site tracking technologies. We measure website traffic with Vercel Web Analytics, a cookieless, privacy-preserving service that records aggregated page views without storing an identifier on your device. If we introduce cookies that are not strictly necessary in future, we will ask for your consent first.

The CM6 application (app.cm-six.com) sets one strictly necessary session cookie to keep you signed in. It is not used for advertising or tracking. When you submit the demo request form, your details are delivered to us by email through our email provider and are used only to respond to your enquiry.

13. Children

CM6 is a business service. It is not directed at, and we do not knowingly collect personal data from, anyone under 18.

14. Changes to this policy

We may update this policy from time to time. We will post the new version here with a new effective date and, for material changes, notify merchant users by email or in the application before the change takes effect.

15. Contact

Hypus Ltd (trading as CM6), Fourth Floor, 33 Cavendish Square, London, England, W1G 0PW. Email: info@cm-six.com.

See also our Terms of Service and Data Processing Addendum.