Privacy Policy

Effective date: April 6, 2026  ·  Last updated: April 6, 2026

ShopAIflex (“we”, “our”, or “us”) operates the ShopAIflex merchant platform (“the Service”) available via the Shopify App Store. This Privacy Policy explains what personal data we collect, how we use it, and your rights. By installing or using the Service you acknowledge this policy.

1. Data Controller

ShopAIflex is the data controller for personal data processed through the Service. For privacy-related enquiries, contact us at privacy@shopaiflex.com.

2. Information We Collect

Information you provide directly:

  • Account details: name, email address, and password when you register
  • Support communications: messages you send to our support team

Information received via Shopify API (on app install):

  • Store identity: store name, domain, and Shopify store ID
  • Shop owner name and email address
  • Product catalogue: product titles, descriptions, prices, and images
  • Shopify plan name (e.g. Basic, Shopify, Advanced)

Usage data collected automatically:

  • Features used, pages visited, and actions taken within the dashboard
  • IP address, browser type, and device information
  • Log data and error reports

3. Legal Basis for Processing (GDPR)

We process your personal data on the following legal bases:

  • Contract performance — to deliver the Service you have subscribed to
  • Legitimate interests — to improve the Service, prevent fraud, and ensure security
  • Legal obligation — to comply with applicable laws and regulations
  • Consent — where you have opted in to analytics or marketing communications

4. How We Use Your Information

  • Provide, operate, and improve the Service
  • Power AI features such as product optimisation, market research, and competitor analysis
  • Manage your account and process billing via Shopify
  • Send transactional emails (account setup, billing confirmations, password reset)
  • Respond to support requests
  • Monitor and prevent fraud or abuse
  • Comply with legal obligations, including Shopify's Partner Programme requirements

We do not sell your personal data to third parties.

5. AI-Powered Features

Some features use artificial intelligence to analyse product data, generate content, and provide market insights. Product data (titles, descriptions, images) may be sent to AI service providers solely to deliver the requested functionality. This data is not used to train third-party AI models, and we minimise the personal information included in AI requests.

6. Data Sharing

We share data only as necessary to operate the Service:

  • Shopify — to authenticate and sync your store data
  • Cloud infrastructure providers — for hosting, database, and storage services
  • AI service providers — to power intelligent product and market analysis
  • Email service providers — to deliver transactional emails
  • Payment processors — billing is handled entirely by Shopify Payments

All third-party providers are contractually required to handle your data securely and only for the purposes we specify. We do not share data for advertising purposes.

7. International Data Transfers

Our servers are located in the United States. If you are accessing the Service from the European Economic Area (EEA), United Kingdom, or other regions with data protection laws, your data may be transferred to and processed in the United States. We rely on Standard Contractual Clauses (SCCs) and equivalent safeguards to ensure adequate protection for such transfers.

8. Cookies and Tracking

We use cookies and similar technologies to keep you signed in and to understand how the Service is used. We may use analytics tools to measure performance and improve the Service. You can manage cookie preferences in your browser settings; however, disabling certain cookies may affect Service functionality.

9. Data Retention

We retain your personal data for as long as your account is active or as needed to provide the Service. When you uninstall the app, we delete your personal data (account, activity logs, and store-linked records) immediately. Shopify may separately request deletion of remaining data within 48 hours of uninstall via a GDPR shop/redact webhook, which we honour. We may retain anonymised or aggregated data for longer periods for legitimate business purposes such as fraud prevention and service improvement.

10. Security

We implement industry-standard security measures including encryption in transit (TLS/HTTPS), hashed passwords (bcrypt), and strict access controls. No method of internet transmission is 100% secure, and we cannot guarantee absolute security. We notify affected users promptly in the event of a data breach where required by law.

11. Your Rights

Depending on your location (including under GDPR, UK GDPR, and CCPA), you may have the right to:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your personal data (“right to be forgotten”)
  • Restriction — request that we limit how we process your data
  • Portability — receive your data in a structured, machine-readable format
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — where processing is based on consent, withdraw it at any time

To exercise any of these rights, contact us at privacy@shopaiflex.com. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority (e.g. the ICO in the UK, or your EU supervisory authority).

12. Shopify-Specific Disclosures

As a Shopify App, we comply with the Shopify API Terms of Service and the Shopify App Store Requirements. Specifically:

  • We only request Shopify API scopes required to deliver the Service
  • We handle GDPR webhooks: customers/data_request, customers/redact, and shop/redact
  • Store and merchant data received via the Shopify API is used solely to power the Service
  • We do not use merchant or customer data for advertising or resale

13. Children's Privacy

The Service is intended for merchants and business users aged 18 and over. We do not knowingly collect personal data from anyone under 18.

14. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the effective date above and notify you by email or via an in-app notice. Continued use of the Service after changes constitutes acceptance of the updated policy.

15. Contact Us

© 2026 ShopAIflex  · Merchant Login