Privacy Policy

Sauce - SupaDupa Me Limited  |  Last updated: March 2026

Summary: Sauce (SupaDupa Me Limited) is a visual commerce platform. We collect and process personal data to provide our services, to communicate with you, and to improve our platform. We act as a data controller for account and website data, and as a data processor for content our customers process through the platform. We are based in the United Kingdom and comply with the UK GDPR and the Data Protection Act 2018. Where we transfer data internationally we do so using lawful safeguards. You have rights over your personal data and can exercise them by contacting privacy@addsauce.com.

‍

1. Who We Are

Sauce is a visual commerce platform operated by SupaDupa Me Limited, a company incorporated in England and Wales. Our registered office is in London, United Kingdom. When this Privacy Policy refers to “Sauce”, “we”, “us” or “our”, it refers to SupaDupa Me Limited and the services it provides.

This Privacy Policy applies to all individuals who:

  • visit any website or mobile site operated by Sauce, including addsauce.com and all its subdomains, present and future (the “Website”); or
  • use any Sauce service, including Sauce Visual Shopping, Video Shopping, Shoppable Galleries, Campaigns, Discover, Advanced Search, and any other Sauce products and services (the “Platform”).

Together, the Website and the Platform are referred to as the “Services”. When we refer to “Personal Information” or “personal data”, we mean any information relating to you or another identifiable individual.

We are committed to protecting your privacy. This Privacy Policy explains what data we collect, why we collect it, how we use it, and what rights you have. By using the Services, you acknowledge that you have read and understood this Privacy Policy.

The most recent version of this Privacy Policy is available at addsauce.com/privacy-policy. We may update it from time to time. We will notify you by email or within the platform of any material changes. Your continued use of the Services after any update constitutes acceptance of the revised policy.

‍

2. Legal Framework and Data Roles

Sauce operates under the UK General Data Protection Regulation (“UK GDPR”) and the Data Protection Act 2018. Where we also serve customers and individuals in the European Economic Area (“EEA”), we also comply with the EU GDPR (Regulation 2016/679) to the extent applicable.

We act in two distinct capacities depending on the type of data involved:

Data Controller - Sauce Data: We collect and process certain Personal Information directly from customers, users, and visitors for our own business purposes - for example, account registration data, billing information, and website analytics. We are the data controller of this information (“Sauce Data”).

Data Processor - Customer Content: We also process Personal Information on behalf of our customers, in accordance with their instructions, as part of the Services we provide - for example, content generated through or published via the Platform, or data our customers connect to the Platform via third-party integrations such as Shopify or Instagram (“Customer Content”). In this capacity, our customers are the data controllers and we are the data processor. Customers are responsible for ensuring they have a lawful basis for the Personal Information they process through the Platform and for complying with applicable data protection law in relation to their Customer Content.

‍

‍

3. Data We Collect and Our Lawful Bases

The following table summarises the categories of Sauce Data we collect, the purposes for which we use it, and the lawful bases under UK GDPR on which that processing relies.


Category of data Examples Purpose Lawful basis
Account and registration data Name, email address, username, password (hashed), organisation name, billing address Account creation and management; delivery of the Services; billing and invoicing Performance of a contract
Payment data Billing address; payment method identifiers passed to our PCI-DSS compliant payment processor Processing subscription payments; fraud prevention Performance of a contract; legal obligation
Usage and analytics data IP address; device type; browser; operating system; pages visited; access times; referring URLs; session duration; feature interactions Service operation and security; product improvement; understanding user behaviour; bug detection Legitimate interests (improving and securing the Services)
Communications data Email content; support ticket content; survey responses; in-app messages Customer support; responding to queries; product feedback Performance of a contract; legitimate interests
Marketing preferences Email opt-in status; communication preferences Sending product news, updates, and marketing communications where you have opted in Consent; legitimate interests (existing customer communications)
Integration and authentication tokens OAuth tokens for connected platforms (e.g. Shopify, Instagram); API credentials Enabling third-party integrations that form part of the Services; authentication Performance of a contract
Location data Country or region inferred from IP address Localisation of the Services; compliance with jurisdiction-specific requirements Legitimate interests

We do not collect special category personal data (such as health, racial or ethnic origin, religious beliefs, or biometric data) through the Services and we ask that our customers do not process such data through the Platform without first entering into an appropriate data processing agreement with us.

‍

‍

4. Shopify and eCommerce Platform Integrations

Sauce integrates with Shopify and other eCommerce platforms to deliver its Visual Shopping and Video Shopping capabilities. This section describes the specific data flows associated with those integrations.

Access granted on installation: When you install the Sauce application on your Shopify store, you grant us the following permissions for the purposes described:

  • Customer and store owner information (names, email addresses, phone numbers, physical addresses, IP addresses, browser and operating system data, client identifiers and cookies) - used to deliver personalised shopping experiences, provide support, and improve the application.
  • Customer browsing behaviour and account tags - used to personalise the user experience and support analytics on shoppable content performance.
  • Product catalogue data (individual products, collections, metadata) - used to power Visual Shopping and Video Shopping features, enabling products to be tagged and made shoppable within your content.
  • Store analytics and pixel management - used to measure the performance of shoppable content and to support conversion attribution.
  • Online store page editing - used to integrate Sauce components (shoppable galleries, video widgets) seamlessly into your storefront.

Data sovereignty: You retain control over your data at all times. If you uninstall the Sauce application, our access to your store data is revoked immediately and any data held by us in connection with your Shopify integration will be securely deleted within 30 days, except where retention is required by applicable law or for the resolution of any ongoing disputes.

Purposes of eCommerce data access: The data accessed through Shopify and similar integrations is used for the following purposes specific to Sauce's eCommerce functionality:

  • Analysing the performance of shoppable and video content, including engagement rates, click-through rates, and conversion attribution.
  • Determining the commercial value generated by individual pieces of media to support content strategy decisions.
  • Understanding basket composition and average order values resulting from Visual Shopping interactions.
  • Supporting user-generated content (UGC) campaigns, including identifying customers who may be suitable brand advocates based on their purchase history and engagement.
  • Enabling personalised product recommendations within shoppable content.

All data accessed through eCommerce platform integrations is managed in strict compliance with applicable data protection law and with the terms of the relevant platform's data use policies.

‍

5. Cookies and Tracking Technologies

We use cookies and similar technologies on the Website and within the Platform. You can manage your cookie preferences through the cookie settings banner displayed on first visit. Your consent to non-essential cookies is recorded and can be withdrawn at any time through your account settings or browser controls.

Essential cookies: These are strictly necessary for the Services to function. They include session cookies that maintain your logged-in state and enable navigation between pages. These cookies cannot be disabled without preventing use of the Services.

Analytics cookies: We use Google Analytics to understand how users interact with the Website and Platform. If you are a logged-in user, we may associate your Sauce user ID with analytics data to understand your use of the Services and to improve them. You can opt out of Google Analytics tracking by installing the Google Analytics Opt-out Browser Add-on.

Marketing and remarketing cookies: Subject to your consent, we and our advertising partners may set cookies to enable targeted advertising on and off the Website. This may include Google Display Advertising features such as Remarketing and Google Analytics Demographics and Interest Reporting. You can manage interest-based advertising preferences at Google Ads Settings or via the Network Advertising Initiative opt-out tool.

Third-party and integration tokens: The Services use software tokens (stored securely on Sauce servers) to authenticate connected platforms and third-party applications. These are functional rather than tracking in nature and are essential to the operation of the Services.

You can configure your browser to block or delete cookies. However, blocking essential cookies may prevent you from using parts of the Services. Further information about cookies and how to manage them is available at allaboutcookies.org.

‍

6. How We Use Sauce Data

We use Sauce Data for the following purposes:

  • to create, maintain, and administer your account and to authenticate you when you log in;
  • to provide, operate, and improve the Services, including Visual Shopping, Video Shopping, and all related platform features;
  • to process payments, issue invoices, and manage billing;
  • to provide customer support and respond to your queries and requests;
  • to send you transactional communications (such as account confirmations, billing notices, and service updates) which are necessary for the operation of the Services;
  • to send you marketing communications about Sauce products and features where you have consented or where we have a legitimate interest in doing so as an existing customer - you can opt out at any time;
  • to monitor and analyse usage of the Services to diagnose issues, understand trends, and improve features and usability;
  • to share aggregated, non-identifiable statistical data with partners and prospective partners for the purposes of demonstrating platform performance;
  • to maintain the security of the Services and to prevent fraud, abuse, or unauthorised access;
  • to comply with our legal obligations under applicable law.

Where we rely on legitimate interests as a lawful basis for processing, we have assessed that our interests do not override your fundamental rights and freedoms. You may request details of our legitimate interests balancing assessment by contacting us at privacy@addsauce.com.

‍

7. Customer Content

Our customers use Sauce to enrich their product and brand content - connecting their eCommerce stores, social media accounts (including Instagram), and other third-party platforms to enable shoppable experiences. When they do so, they may direct us to access, collect, store, or process Personal Information belonging to their own customers and followers as part of delivering the Services.

In this context, our customers are the data controllers of that Customer Content and are responsible for: ensuring they have a valid lawful basis for directing us to process it; providing appropriate notices to their own customers; and responding to any data subject rights requests relating to it. Sauce processes Customer Content solely in accordance with the instructions our customers give us through the Services and does not use it for any independent purpose.

Customers who require a formal Data Processing Agreement (“DPA”) - for example to satisfy their own GDPR or UK GDPR compliance obligations - should contact us at privacy@addsauce.com to request one.

‍

8. When We Share Personal Information

We do not sell your Personal Information to third parties. We may share Personal Information in the following circumstances only:

  1. Service providers and sub-processors: We share data with carefully selected third-party vendors who help us operate the Services, including cloud infrastructure providers (such as Amazon Web Services), payment processors (PCI-DSS compliant), CRM and support platforms, and analytics providers. These parties are contractually obliged to process data only on our instructions and in accordance with applicable data protection law.
  2. Third-party platform integrations: Where you or your customers have connected a third-party platform (such as Shopify or Instagram) to the Services, data may flow to and from that platform to the extent necessary for the integration to function. Such transfers are subject to the relevant platform's own privacy policies and terms.
  3. Legal requirements: We may disclose Personal Information where required to do so by law, court order, or regulatory authority, or where necessary to establish, protect, or exercise our legal rights or to defend legal claims.
  4. Safety and security: We may disclose Personal Information where we reasonably believe it is necessary to prevent or investigate illegal activity, fraud, or threats to the safety, rights, or property of any person or of Sauce's infrastructure.
  5. Business transfers: If Sauce or SupaDupa Me Limited is involved in a merger, acquisition, or sale of assets, Personal Information may be transferred to the acquiring entity. We will notify you in advance of any such transfer and require the acquiring entity to honour the commitments made in this Privacy Policy or to notify you of a new policy.
  6. Group companies: We may share data with any parent company, subsidiary, or affiliate of SupaDupa Me Limited, subject to the same data protection obligations.
  7. Aggregated or anonymised data: We may share aggregated or anonymised information that cannot reasonably identify you with partners, advertisers, or the public.
  8. With your consent: We may share your data with third parties where you have given us your explicit consent to do so.

‍

9. International Data Transfers

Sauce is a UK company and the Services are principally operated from our offices in London. However, some of the third-party service providers and sub-processors we work with are located outside the United Kingdom and the European Economic Area, including in the United States and Canada. As a result, your Personal Information may be transferred to and processed in those countries.

Where we transfer Personal Information outside the UK, we ensure that appropriate safeguards are in place, including one or more of the following:

  • an adequacy decision or adequacy regulations made by the UK Secretary of State confirming that the recipient country provides an adequate level of protection;
  • an International Data Transfer Agreement (“IDTA”) or the UK Addendum to the European Commission's Standard Contractual Clauses, as applicable; or
  • binding corporate rules or another legally recognised transfer mechanism.

Where we transfer Personal Information outside the EEA on behalf of EU-based customers (in our capacity as data processor), we do so in accordance with Standard Contractual Clauses adopted by the European Commission or another valid transfer mechanism, as agreed in the applicable Data Processing Agreement.

You may request a copy of the transfer safeguards we rely on for any specific transfer by contacting us at privacy@addsauce.com.

‍

10. Data Retention

We retain Sauce Data for as long as is necessary for the purposes set out in this Privacy Policy, or as required by applicable law. In practice, this means:

  • Account data is retained for the duration of your Sauce account and for up to 3 years after account closure, to support any warranty claims, dispute resolution, or regulatory requirements.
  • Billing and transaction records are retained for a minimum of 6 years from the date of the relevant transaction, to comply with UK tax and accounting law.
  • Usage and analytics data is typically retained in identifiable form for up to 26 months and then aggregated or deleted.
  • Support communications are retained for up to 3 years from the date of the interaction.
  • Shopify integration data is deleted within 30 days of uninstallation, unless required for the resolution of any outstanding matter.

After the applicable retention period, data is securely deleted or anonymised. You may request early deletion of your data in accordance with your rights set out in Section 12 below.

‍

11. Security

We take the security of your Personal Information seriously and maintain appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction. These measures include:

  • encrypted data transmission using HTTPS and TLS (Transport Layer Security);
  • OAuth 2.0 protocols for third-party platform authentication;
  • storage of data on secured servers with access limited to authorised personnel;
  • use of cloud infrastructure providers (including Amazon Web Services) that hold industry-standard certifications including ISO 27001 and SOC 2;
  • PCI-DSS compliant payment processing - Sauce does not store, transmit, or process payment card data directly; and
  • hashing of passwords; login credentials are not stored in recoverable form.

Despite these measures, no transmission of data over the internet is entirely secure. You submit Personal Information at your own risk. You are responsible for maintaining the confidentiality of your account credentials. We recommend that you log out at the end of each session, particularly on shared devices.

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the UK Information Commissioner’s Office (“ICO”) within 72 hours and will notify you without undue delay if the breach is likely to result in a high risk to your rights.

‍

12. Your Rights

Under UK GDPR and the Data Protection Act 2018, you have the following rights in relation to your Personal Information held by Sauce in its capacity as data controller. These rights apply to Sauce Data. For Customer Content processed on behalf of our customers, rights requests should be directed to the relevant customer (the data controller), though we will assist our customers in fulfilling any such requests.

  1. Right of access: You have the right to request a copy of the Personal Information we hold about you and to receive information about how we process it (a “subject access request”).
  2. Right to rectification: You have the right to ask us to correct inaccurate or incomplete Personal Information we hold about you.
  3. Right to erasure (“right to be forgotten”): You may request that we delete your Personal Information where there is no longer a lawful basis for us to retain it, or where you withdraw your consent (where consent is the lawful basis). We may not always be able to comply fully - for example, where we are required to retain data for legal or regulatory reasons - and we will inform you if this is the case.
  4. Right to restriction of processing: You may ask us to pause the processing of your Personal Information in certain circumstances, for example while the accuracy of data is being contested.
  5. Right to data portability: Where processing is based on your consent or on the performance of a contract and is carried out by automated means, you have the right to receive your Personal Information in a structured, commonly used, machine-readable format and to have it transmitted to another controller.
  6. Right to object: You have the right to object to processing based on legitimate interests, including profiling. You also have an absolute right to object to processing for direct marketing purposes, including profiling for direct marketing.
  7. Rights in relation to automated decision-making: You have the right not to be subject to a decision based solely on automated processing (including profiling) that produces legal or similarly significant effects on you. We do not currently make such decisions about individuals, but you may contact us if you have concerns.
  8. Right to withdraw consent: Where we rely on consent as the lawful basis for processing, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, please contact us at privacy@addsauce.com. We will respond within one calendar month of receiving your request. We may need to verify your identity before processing your request. There is no charge for exercising your rights unless requests are manifestly unfounded, excessive, or repetitive.

You also have the right to lodge a complaint with the UK Information Commissioner’s Office (“ICO”) if you believe your data protection rights have not been respected. The ICO can be contacted at ico.org.uk or by telephone on 0303 123 1113. If you are in the EEA, you may contact your local data protection authority instead.

Deleting your account: You can request deletion of your Sauce account and associated Personal Information by submitting a request through our support centre at help.addsauce.com or by sending a direct message when logged into your account at app.addsauce.com. Please note that deleting your account will affect your ability to access the Sauce platform and any associated services.

‍

13. Email and Marketing Preferences

We may send you marketing and product communications by email where you have opted in, or where we have a legitimate interest in doing so as an existing customer and you have not opted out. Every marketing email we send includes an unsubscribe link. You may also manage your email preferences at any time through your Account Management page or by contacting us at privacy@addsauce.com.

Opting out of marketing communications will not affect transactional emails that are necessary for the operation of your account or the Services.

‍

14. Third-Party Platforms and Links

The Services allow customers to connect to and interact with third-party platforms and applications, including Shopify, WooCommerce, Instagram, and other social media and eCommerce services (“Supported Platforms”). This Privacy Policy does not apply to content or Personal Information that you provide to, or that is collected by, any Supported Platform or third-party application directly. We encourage you to review the privacy policies of any Supported Platform or third-party application you use in connection with the Services.

The Services may also include links to third-party websites. We are not responsible for the privacy practices of those websites and we recommend you review their privacy policies before providing any Personal Information.

‍

15. Children

The Services are not directed at children. We define “children” as individuals under the age of 13 (or such higher age as applicable law requires in your jurisdiction). We do not knowingly collect Personal Information from children. If you believe that a child has provided us with Personal Information without appropriate consent, please contact us at privacy@addsauce.com and we will take steps to delete that information. The Services should only be accessed by individuals who have reached the minimum legal age to form a binding contract in their jurisdiction.

‍

16. Governing Law

This Privacy Policy and any disputes arising in connection with it are governed by the laws of England and Wales. Any disputes shall be subject to the exclusive jurisdiction of the courts of England and Wales, except where applicable data protection law provides otherwise (including with respect to complaints made to data protection authorities).

‍

17. Contact Us

If you have any questions, concerns, or requests relating to this Privacy Policy or to your Personal Information, please contact us:

SupaDupa Me Limited (trading as Sauce)
London, United Kingdom
Email: privacy@addsauce.com
Website: addsauce.com

For general support enquiries, please use our support centre at help.addsauce.com.

‍

18. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our Services, legal requirements, or industry practices. We will post the updated policy at addsauce.com/privacy-policy and update the “Last updated” date at the top of this page. Where changes are material, we will notify you by email or through a prominent notice within the Services at least 14 days before the changes take effect. Your continued use of the Services after the effective date of any update constitutes acceptance of the revised Privacy Policy.

‍

This Privacy Policy is issued by SupaDupa Me Limited, trading as Sauce. It applies to all users of the Sauce Services. SupaDupa Me Limited is registered in England and Wales. Nothing in this Privacy Policy creates any contractual rights not set out in the Sauce Terms of Service or any applicable data processing agreement.

Explore

Explore

Visual Shopping
Shop directly from your social media on your site
User Generated Content
Collect & showcase content created by your customers
Influencer Marketing
Find, promote & track your brand through influencers
Video Commerce
Shop through curated video content
Sauce TV
Popular!
Netflix-inspired video shopping experience
Hero Video
Popular!
Unlock product discovery on your homepage & PDPs
New!
Connect with new customers on Shopify's Shop App

Connect

Shopify
Shopify Plus
Shopify Shop
Adobe Commerce
Big Commerce
Woo Commerce
Squarespace
SupaDupa Me
Klaviyo
Instagram
Facebook Catalogue
TikTok
Chrome - Lens

Learn

Simple steps to increasing average order value using social shopping
Watch video
Transform Product Pages into Conversion Hubs
Watch video
7 Rules of Social Commerce
Sauce Help Centre
Use CasesSauce StudiosIntegrationsBlogUpdates
Book a Call
Log in
Log in
Start free trial
Getting Started
Getting startedPricingSauce help docs
Solutions
Influencer MarketingInfluencer ProfilingLens: Instagram Influencer ProfilingVisual ShoppingVideo CommerceSauce TVUser Generated ContentBrand Partnerships
Resources
The Digital Dish - BlogHelp CenterUpdates change logThe 7 rules of Social CommerceBook a Zoom with an ExpertBook a Website Audit
Company
About SauceCareersCustomer StoriesInstagramTwitterYouTubeLinkedInPartner with us - Web AgenciesPartner with us - InfluencersContact Us
Made for
Fashion & JewelleryBeauty & WellnessHome & GardenSwimwearAthleisureHotels & Travel
Integrations
ShopifyShopify PlusAdobe CommerceBig CommerceWoo CommerceSquarespaceSupaDupa MeKlaviyoInstagramTikTokChrome - Lens
More ways to get started: Book an in person chat with one of our experts - Book a Sauce Zoom.
Copyright © 2025 SupaDupa Me Limited Trading as Sauce. All rights reserved.
Privacy PolicyTerms of Service