Sign inBook a demo

Sell

  • CatalogProducts, variants, and merchandising
  • Pricing & promotionsPrice lists, discounts, and campaigns
  • Checkout & ordersCarts, payments, and fulfilment

Build

  • Admin APIBack-office automation
  • Storefront APICart, checkout, and browsing

Integrations

  • StripePayment lifecycle connected to commerce

More

  • DocumentationGuides and reference

Get started

  • DocumentationEverything you need to build
  • Admin quickstartYour first admin query
  • Storefront quickstartYour first storefront query

APIs

  • Admin GraphQL APICatalog, orders, and operations
  • Storefront GraphQL APIBrowsing, cart, and checkout
  • Cart and checkoutBuild a checkout end to end

Concepts

  • Query languageFilter and search the graph
  • DiscountsHow discounts are evaluated
  • Image optimizationFast media at any scale

Learn

  • BlogProduct news and engineering
  • DocumentationGuides and API reference

Get in touch

  • Contact salesTalk through your setup
  • SupportHelp for existing customers
Sign inBook a demo

Privacy Policy

Last updated: 4 September 2026

This policy explains how Sublime IT ApS handles personal data in connection with the Thor Commerce platform, website, APIs and integrations, as well as business enquiries and account administration. Integration-specific information is identified separately below. It also explains how to contact us and exercise your rights.

On this page

  1. 1. Who is responsible for your data
  2. 2. Data we receive
  3. 3. Purposes and legal bases
  4. 4. Thor Commerce plugin for OpenAI
  5. 5. Sharing and service providers
  6. 6. International transfers
  7. 7. Retention and deletion
  8. 8. Website technologies and communications
  9. 9. Your rights and choices
  10. 10. Security and policy updates

1. Who is responsible for your data

Thor Commerce is operated by Sublime IT ApS, CVR 40355847, VAT DK40355847, Svanemøllevej 41, 2900 Hellerup, Denmark. Contact us at hello@thorcommerce.io for privacy questions and requests.

We act as a controller when deciding how to handle website enquiries, business relationships and our own account administration. When we process commerce data on a customer organisation’s instructions, we act as its processor under the applicable customer agreement and data processing agreement. The customer determines the purposes and legal basis for that processing.

If you are a shopper or another individual whose information a merchant stores in Thor Commerce, contact that merchant first about its use of your data. Its privacy notice applies to its activities. We assist the customer with requests concerning data we process on its behalf.

2. Data we receive

  • Enquiries and communications: name, work email, company, telephone number, demo-booking details and the content of messages you provide.
  • Account and access information: user identifier, email, organisation membership, roles, permissions and authentication information used to verify access.
  • Customer commerce data: information submitted to or retrieved from the platform on the customer’s instructions. Depending on the records involved, this may include customer contact details, addresses and order information, alongside non-personal catalogue and product data.
  • Integration requests: the selected project, requested operation, query or mutation, supplied values and the results or errors returned. Information from uploaded files can be included when your client submits it as part of an operation.
  • Technical information: request metadata, IP address, browser information, operational logs and error details generated when you use the website or services. Website technologies may also collect usage information.

We receive information directly from you, from your organisation and its authorised integrations, from our authentication provider and through operation of the services. Provide only information needed for your request.

3. Purposes and legal bases

  • Enquiries, demos and business contacts: to respond and manage the relationship. We rely on our legitimate interest in communicating with prospective and existing customers, or on taking steps towards a contract where you are personally a party to it (GDPR Article 6(1)(f) or (b)).
  • Account administration and security: to authenticate users, determine authorised access, operate the service and investigate faults or misuse. For processing as a controller, we rely on our legitimate interests in providing and protecting the service, or performance of a contract with you where applicable (Article 6(1)(f) or (b)).
  • Legal and accounting obligations: to maintain required records and respond to legally binding requests (Article 6(1)(c)). Information needed to establish or defend legal claims is processed on the basis of our legitimate interests (Article 6(1)(f)).
  • Consent-based activities: where consent is required for electronic marketing or non-essential tracking, consent is the applicable basis (Article 6(1)(a)). You may withdraw consent without affecting the lawfulness of earlier processing.
  • Customer commerce operations: to execute the customer’s instructions under the applicable data processing agreement. The customer is responsible for identifying its legal basis and giving notices to the individuals concerned.

Information needed to authenticate you or fulfil a request is necessary for that function; without it, we may be unable to provide access or respond. Reading this policy or connecting a plugin does not constitute consent to unrelated marketing.

4. Thor Commerce plugin for OpenAI

This section applies specifically to the Thor Commerce plugin for OpenAI, used through ChatGPT or Codex. When you connect this plugin, WorkOS handles the sign-in flow. Thor Commerce checks the authenticated user’s access to the connected organisation and requested project. The connection can support both reading data and making changes, subject to your permissions.

Your AI client sends individual tool requests to Thor Commerce. We process the operation and return the requested results or errors to that client. A result may contain personal data if the selected commerce records and fields contain it. The plugin does not retrieve your full conversation history; it receives the arguments and content the client includes in each request.

Using the plugin with ChatGPT or Codex sends the returned data to OpenAI. Before requesting customer data, check that your organisation permits sharing it with OpenAI. Request only the records and fields needed for the task.

The gateway serving this OpenAI integration does not maintain a separate conversation-history database. This does not mean that requests leave no records: operational logging, underlying commerce records and the AI provider’s storage are separate. The AI provider’s retention, training and deletion practices depend on its policies, your plan and your settings. See OpenAI’s Privacy Policy and any business agreement your organisation has with OpenAI.

Disconnect the plugin in your client to stop using that connection. Contact your organisation’s administrator or us to remove Thor Commerce access. Disconnecting does not delete existing commerce records, undo completed writes or remove data already stored by the AI provider. Use that provider’s own controls to manage its copies.

5. Sharing and service providers

We do not sell personal data. Access is shared as necessary to provide the requested service, support our operations or meet legal obligations. Recipients include:

  • Infrastructure and security providers, including Amazon Web Services for platform infrastructure and Cloudflare for website delivery and network services.
  • WorkOS for authentication and organisation access management.
  • Communication and scheduling providers, including Resend for email and contact management and Calendly when you use our booking integration.
  • Website technology providers, including Google where Google Tag Manager and configured tags are used.
  • Third-party clients and integrations chosen by the customer, including OpenAI when you use the Thor Commerce plugin for OpenAI through ChatGPT or Codex. These providers receive the data needed for the operations you request and handle it under their applicable terms.
  • Authorised personnel, professional advisers and public authorities where access is necessary for support, legal obligations or the protection of legal rights.

The providers relevant to a particular customer’s processing and the contractual arrangements for subprocessors are addressed through its data processing agreement. Contact us for information about the providers involved in your service.

6. International transfers

Using international service providers or an AI client can involve processing outside Denmark or the European Economic Area. The location of the primary platform database does not determine where all connected providers process information.

Where we transfer personal data outside the EEA, applicable data protection law requires a valid transfer mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses with any necessary supplementary measures. Contact us for details of the safeguards applicable to your data or to request a copy. Transfers made through a client selected by your organisation also depend on its arrangements with that provider.

7. Retention and deletion

Retention depends on the purpose of the record, the customer’s instructions and applicable legal obligations. There is no single deletion period that applies to all Thor Commerce data.

  • Enquiries and business correspondence: retained while needed to handle the enquiry, maintain the relevant business relationship or document an agreement or legal claim. The nature of the enquiry, ongoing relationship and applicable legal requirements determine the period.
  • Account and commerce records: retained to provide the customer’s service and in accordance with its instructions and applicable agreements. Account closure and return or deletion of customer data are handled under the customer agreement and data processing agreement; disconnecting a plugin does not start automatic deletion of these records.
  • Operational logs: the central operational log stream is currently configured for three-hour retention. This setting does not apply to commerce records, webhook or audit history, backups, or records held by authentication, network or AI providers.
  • Webhook and audit history: there is no universal automatic expiry period for these records. Retention is determined by the customer’s processing instructions and the need to investigate delivery, security and service issues, subject to applicable legal requirements.
  • Backups: the current managed database’s automated backup retention is seven days. This is a recovery window, not a promise that all copies are erased seven days after a request. Other stored files, snapshots and provider records are separate; the scope and timing of deletion are addressed when handling the request and the applicable customer agreement.
  • AI client records: data already returned to an AI provider follows that provider’s retention policy and the customer’s account settings and agreements. Thor Commerce’s log retention does not control these copies.

To request deletion or discuss retention for a particular category of data, contact hello@thorcommerce.io. We assess the request against the relevant purpose, customer instructions and legal obligations, including whether information must be retained for a legal claim. Where we are the processor, the customer directs the response.

8. Website technologies and communications

The website includes Google Tag Manager, which can load configured website tags, and a Calendly booking integration. These technologies can send technical information to their providers when loaded. Cookie and storage behaviour depends on the tags and integrations in use.

Browser controls can block or delete cookies and restrict third-party content, although some features may then be unavailable. Browser settings are separate from any consent that applicable law requires before non-essential technologies are used.

When you submit the contact form, your details and message are sent to our team and your contact details are added to our contact-management system. You can object to direct marketing at any time by contacting us or using an unsubscribe link in a marketing email. This does not prevent us from responding to an enquiry or sending necessary service communications.

9. Your rights and choices

Under the GDPR, and subject to its conditions and exceptions, you may request access, correction, erasure, restriction of processing and portability of your personal data. You may object to processing based on legitimate interests and object to direct marketing at any time. Where processing relies on consent, you may withdraw it.

Send requests to hello@thorcommerce.io. We may ask for information reasonably necessary to verify your identity or authority to act for a customer. We normally respond within one month; if a lawful extension is needed, we will explain why. Where a merchant controls the data, contact it directly or tell us which merchant is involved so we can direct the request appropriately.

You may complain to the Danish Data Protection Agency, Datatilsynet, or to the supervisory authority in the EEA country where you live, work or believe an infringement occurred.

10. Security and policy updates

We use authentication, access controls and operational monitoring to protect the service. No online system can guarantee absolute security. Keep credentials out of messages and AI conversations, and contact us promptly if you suspect unauthorised access.

We may update this policy as our services or legal obligations change. The revision date identifies the current version. Where a change requires additional notice or consent under applicable law, publishing this page alone does not replace that requirement.

Terms of ServicePrivacy PolicyContact us

Ready to build with Thor?

Start now, or book a demo to talk through your commerce setup with our team.

Start nowBook a demo

Site-wide links

Platform

  • Catalog
  • Pricing & promotions
  • Checkout & orders

Developers

  • Documentation
  • Admin GraphQL API
  • Storefront GraphQL API
  • Admin quickstart
  • Storefront quickstart
  • Query language

Resources

  • Stripe integration
  • Blog
  • Contact sales
  • Support

Compare

  • Thor vs Shopify
  • Thor vs Magento
  • Thor vs Adobe Commerce

Company

  • Sign in
  • © 2026 Thor Commerce
  • CVR DK40355847
  • Privacy
  • Terms