Skip to main content
    Legal

    Privacy Policy

    Last updated: 28 August 2026

    This privacy policy describes how Normenn AS (org. no. 835 583 422), Lienga 6, 1414 Trollåsen ("we", "us", "our"), collects, uses, stores and shares personal data when you use the service Veiser at veiser.no (the "Service"). We are committed to protecting your privacy in accordance with the EU General Data Protection Regulation (GDPR) and the Norwegian Personal Data Act.

    1. Data Controller

    Normenn AS is the data controller for personal data related to your account and use of the Service. For data retrieved from or exported to us from your connected services (e.g. Google Analytics), and for data about visitors to your website when you use A/B testing, we act as data processor on your behalf. That relationship is governed by a separate data processing agreement.

    Contact information: Normenn AS, org. no. 835 583 422, Lienga 6, 1414 Trollåsen, Email: post@normenn.no

    2. Personal data we process

    2.1 Account information

    • Upon registration: Name, email address and password (for email registration), or name, email address and profile picture (for Google sign-in)
    • Organisation data: Organisation name, team memberships and role assignments
    • Payment information: Billing information is handled by our payment provider. We do not store card numbers or bank details directly.

    2.2 Data from Google Analytics 4

    When you connect your Google Analytics 4 account to Veiser and authorise access, we receive read-only access to the following data:

    • GA4 events: Page views, session start, product views, cart events, checkout and purchase events
    • Aggregated metrics: Number of sessions, unique users, event counts and drop-off rates per step in the customer journey
    • Account information: GA4 account name and property name (to let you select the correct property)

    Through this connection we retrieve only aggregated data – we do not collect individual user identities, IP addresses or personally identifiable information from your GA4 account. You choose whether to connect Google Analytics, and you may disconnect at any time.

    If you additionally choose to enable the export of analytics data (Google Analytics' BigQuery export) to our data warehouse, we receive individual-level event data about visitors to your website. For that data you are the data controller and we are the data processor, and which data this concerns, how long it is processed and how it is deleted is governed by the data processing agreement. The export is optional and is enabled only by agreement with you.

    2.3 Data from Shopify

    When you connect your Shopify store to Veiser and authorise access, we receive read-only access to the following data:

    • Order data: number of orders, revenue, average order value and products sold, compared with the same period the previous year
    • Product data: product names and categories

    We retrieve only aggregated figures, and do not collect personal data about your customers from the orders. You choose whether to connect, and you may disconnect at any time.

    2.4 Data from WooCommerce

    When you connect your WooCommerce store to Veiser and authorise access, we receive read-only access to the following data:

    • Order data: number of orders broken down by order status, revenue, average order value, discounts and refunds, compared with the same period the previous year
    • Product data: product names, categories and bestsellers
    • Customer figures: number of customers and average purchase amount per customer, only as aggregate totals for the store

    We retrieve only aggregated figures, and do not collect personal data about your customers from the orders. The WooCommerce connection technically grants broad read access, including to customer data, because WooCommerce does not offer a narrower permission. We deliberately retrieve only aggregated figures, and never extract customer data. You choose whether to connect, and you may disconnect at any time.

    2.5 Website data from collection

    When you start a customer journey analysis, we collect content from your website and gather:

    • Screenshots of pages
    • Page metadata (titles, URLs, forms, videos)
    • Page structure and navigation links

    2.6 Usage data

    When you use the Service, we record which actions you take (for example that you open a recommendation), which account and user it concerns, and the time. Your content, such as what you write in the chat, is not logged as usage measurement.

    The measurement takes place on the server side, and we set no analytics cookies in the app.

    We use this to operate and improve the Service. The basis is our legitimate interest, and you can object to the processing, see section 12. The information is stored with our database provider in the EU/EEA and is deleted no later than 24 months after the action was performed. Everything is deleted with the customer relationship.

    In addition we record technical information (browser type, operating system).

    3. Purposes and legal basis

    PurposeData typeLegal basis
    Create and administer your accountAccount informationPerformance of contract
    Deliver AI analysis and recommendationsGA4 data, website data, screenshotsPerformance of contract
    Collect content from your website for customer journey mappingWebsite data, screenshotsPerformance of contract
    Synchronise GA4 dataGA4 events and metricsPerformance of contract
    Retrieve sales figures from Shopify or WooCommerceAggregated order and product dataPerformance of contract
    Receive and analyse exported analytics data (optional)Individual-level event data about visitors to your websiteWe are the data processor on your behalf, see the data processing agreement
    Process paymentsPayment informationPerformance of contract
    Improve and further develop the ServiceUsage measurements (action, account, user, time)Legitimate interest
    Customer supportContact informationLegitimate interest
    Send relevant information and updates by emailEmail addressLegitimate interest (existing customers) or consent
    Understand how the website is usedAnalytics cookies (anonymised usage statistics)Consent

    You may unsubscribe from marketing at any time via the unsubscribe link in the email.

    4. Use of Google API data

    Veiser uses Google API services for sign-in (Google Sign-In), access to Google Analytics 4 data and page speed measurement (PageSpeed Insights). Our use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

    4.1 Google Sign-In (openid, email, profile)

    We use Google Sign-In solely to authenticate you and create your account. We retrieve name, email address and profile picture. These are used only for account administration and are displayed in the user interface.

    4.2 Google Analytics 4 Data API (analytics.readonly)

    Our use of GA4 data is subject to the following limitations:

    • GA4 data is used to deliver and improve the Service's conversion optimisation functionality
    • We never sell GA4 data to third parties
    • We do not use GA4 data to show you ads, build profiles for retargeting, or share data with ad networks or data brokers.
    • We only have read-only access – we never write data back to your GA4 account
    • GA4 data is transferred to our AI analysis models solely to generate conversion recommendations
    • Human access to GA4 data is limited to personnel who require it to deliver the Service, including quality assurance of recommendations, technical troubleshooting and support

    4.3 Google PageSpeed Insights API

    Veiser also uses Google PageSpeed Insights to measure how quickly the pages in your online store load. The only thing we send to Google is the public web address of the page being measured. In return we receive two types of figures: the result of an automated test load performed by Google's own robot, and pre-aggregated, anonymous speed measurements from Google's public statistics on real Chrome users. We receive no information about individual users, IP addresses or cookies.

    4.4 Compliance with Limited Use requirements

    Veiser's use and transfer of information received from Google APIs to any other app complies with the Google API Services User Data Policy, including the Limited Use requirements.

    5. Sharing and sub-processors

    We share personal data with sub-processors that are necessary to deliver the Service. All sub-processors are subject to data processing agreements.

    We use sub-processors within the following categories:

    • Infrastructure, hosting and database services
    • AI analysis and language models
    • Background processing and job execution
    • Payment processing

    Contact us if you would like more information about our sub-processors.

    6. Artificial intelligence (AI)

    6.1 How we use AI

    The Service uses AI models from external providers to analyse screenshots and metrics from your online store. The AI models are used to:

    • Identify conversion issues based on visual analysis of screenshots
    • Generate improvement suggestions and prioritise opportunities
    • Classify pages and segments in the customer journey
    • Generate insights based on aggregated metrics
    • Respond to questions through a conversational AI assistant

    The results are presented to you as advisory suggestions. You always make the final decision on what to implement. AI-generated results are advisory and may be incomplete or inaccurate. See our terms of service for further information on liability.

    6.2 Data sent to AI

    The following data may be sent to the AI models for analysis:

    • Screenshots of web pages (visual analysis)
    • Aggregated GA4 metrics (no individual user data)
    • Page structure and navigation information
    • Content you enter into the AI chat yourself (your questions and messages)

    6.3 AI and training data

    We do not use your data to train AI models. Your data is processed solely to deliver the Service's analysis functionality. Our AI providers may retain logs for a limited period in accordance with their terms. See Section 5 for an overview of sub-processors.

    We may use anonymised and aggregated data internally to improve our own systems and the Service.

    7. Data transfers outside the EEA

    Some of our sub-processors process data in the USA. These transfers are secured through:

    • EU-US Data Privacy Framework (DPF) where the provider is certified
    • Standard Contractual Clauses (SCCs) approved by the European Commission, with necessary supplementary measures
    • Data processing agreements with each provider

    Contact us for a complete overview of sub-processors and their locations.

    8. Storage and deletion

    Data typeRetention period
    Account informationAs long as the account is active
    GA4 metricsAs long as the GA4 account is connected, including any reactivation periods
    Shopify/WooCommerce sales dataAs long as the store is connected, including any reactivation periods
    Exported analytics data (BigQuery)As long as the subscription is active, deleted upon termination in accordance with the data processing agreement
    ScreenshotsAs long as the customer journey exists, or until you delete it
    AI analysis resultsLinked to the customer journey – deleted when the journey is deleted
    Usage measurements in the Service24 months from the event (rolling). Deleted in full when the customer relationship is deleted
    Payment dataIn accordance with the requirements of the Norwegian Accounting Act
    Server logsA limited period in accordance with the hosting provider's policies

    Upon termination of the subscription, your account information is retained for a limited period to enable reactivation. You may at any time request deletion of all your data by contacting us. After the retention period, your personal data is deleted. Data required for accounting purposes may be retained longer in accordance with Norwegian law.

    9. Security

    We employ appropriate technical and organisational measures to protect your data, including:

    • Encrypted communication between your browser and our services
    • Passwords are never stored in plain text
    • Access controls ensuring that users can only see data belonging to their own organisation
    • Secure authentication via a third-party provider – we never have access to your Google passwords
    • Encryption of data at rest
    • The Service runs on secure, managed infrastructure with automatic security updates

    For more information about our security measures, contact us.

    10. Human access to your data

    Our personnel may have access to your data where necessary to deliver the Service, including quality assurance, correction and adjustment of suggestions, customer support and troubleshooting. This may involve authorised personnel viewing your customer journeys, suggestions and results directly in the Service in order to quality-assure deliveries, measure the effect of the recommendations and verify that they are relevant to your business. All such access is limited to what is operationally necessary and takes place under confidentiality.

    11. Cookies

    We use the following cookies:

    • Necessary cookies: Authentication (login) and security (OAuth verification). Do not require consent.
    • Analytics cookies: To understand how the website is used and improve the Service. Set only after your consent.

    We do not use advertising cookies. You can change your cookie preferences at any time.

    11.1 Overview of cookies

    • _ga (Analytics) – Distinguishes unique visitors for visit statistics. Provider: Google. Duration: up to 2 years (browsers may shorten it)
    • _ga_<container-id> (Analytics) – Maintains session state in Google Analytics 4. Provider: Google. Duration: up to 2 years (browsers may shorten it)
    • silktideCookieChoice_* (Necessary) – Stores your cookie preferences. Provider: Veiser (first party). Duration: Permanent (localStorage)
    • silktideCookieBanner_InitialChoice (Necessary) – Remembers that you have made a choice in the cookie banner. Provider: Veiser (first party). Duration: Permanent (localStorage)
    • veiser-lang (Necessary) – Remembers your language choice. Provider: Veiser (first party). Duration: Permanent (localStorage)

    Analytics cookies are set only after you have given consent via the cookie banner. You can change your preferences at any time via the cookie icon in the footer of the website.

    12. Your rights

    You have the following rights:

    • Access: You may request a copy of all personal data we hold about you
    • Rectification: You may ask us to correct inaccurate data
    • Erasure: You may ask us to delete your personal data
    • Data portability: You may request to receive your data in a machine-readable format
    • Object: You may object to processing based on legitimate interest
    • Restriction: You may request that processing be restricted in certain cases
    • Withdraw consent: You may at any time withdraw consent you have given us

    To exercise your rights, contact us at post@normenn.no. We normally respond within 30 days. For particularly complex or numerous requests, the deadline may be extended in accordance with data protection law, and we will inform you accordingly.

    You also have the right to complain to the Norwegian Data Protection Authority (datatilsynet.no) if you believe we are not processing your personal data correctly. We would appreciate it if you contact us first, so that we can try to resolve the matter.

    13. Language

    This privacy policy has been drawn up in Norwegian. Any translations into other languages are provided solely for convenience. In the event of any conflict or interpretive doubt between the Norwegian version and a translation, the Norwegian version shall prevail.

    14. Contact us

    Have questions about this privacy policy or the processing of your data?

    Normenn AS, Email: post@normenn.no, Address: Lienga 6, 1414 Trollåsen