Legal
Privacy Policy
How Aeomatic collects, uses, shares, and protects information when merchants use our Shopify app.
Last updated: August 17, 2026
This Privacy Policy explains how Aeomatic ("Aeomatic," "we," "us," or "our") processes information when a Shopify merchant installs or uses the Aeomatic application and related services (the "Service"). It also explains the choices available to merchants and their customers.
Information we process
Depending on how a merchant configures and uses the Service, we may process:
- Shop and account information: shop domain, store settings, markets, locales, themes, app installation state, granted permissions, subscription state, and merchant contact details.
- Catalog information: products, variants, descriptions, media references, categories, identifiers, prices, inventory-related fields, metafields, and other product attributes needed to diagnose and publish approved changes.
- AI visibility evidence: merchant-approved prompts, provider responses, citations, search results, provider metadata, regions, timestamps, extracted mentions, and confidence calculations.
- Storefront analytics: a session identifier, event type and time, page path, title, referrer, campaign parameters, product or variant references, checkout references, browser user agent, and related event attributes. Aeomatic's pixel is configured for analytics, not marketing, preference collection, or sale of data.
- Order and attribution information: orders, line items, product references, amounts, currencies, and customer or checkout identifiers when needed to measure whether AI-referred sessions led to commerce outcomes.
- Support and technical information: messages sent to us, diagnostic logs, request metadata, errors, and security events.
How we use information
We use this information to:
- install, authenticate, operate, secure, and support the Service;
- sync the merchant's Shopify catalog and diagnose product-information gaps;
- run repeated AI-provider observations across configured prompts, regions, and times;
- connect evidence to exact products and prepare merchant-reviewable changes;
- publish only merchant-approved changes and verify Shopify's authoritative state;
- measure before-and-after visibility, sessions, orders, and revenue attribution;
- administer Shopify-hosted subscriptions and enforce plan limits;
- detect abuse, investigate failures, comply with law, and improve reliability.
Sources of information
We receive information from the merchant, Shopify and its APIs, the merchant's storefront and app extensions, AI and search providers used for visibility observations, and the operation of the Service itself.
When we disclose information
We disclose information only as needed to operate the Service, comply with law, protect rights and safety, complete a business transaction, or at the merchant's direction. Service providers may include infrastructure and database hosting, Shopify, observability and support systems, and AI/search acquisition providers such as Bright Data and the upstream services selected for a visibility run. These providers process information for the relevant operational purpose and may process it in countries other than the merchant's own.
We do not sell personal information. We do not use Shopify customer data for independent advertising or to build advertising profiles.
Merchant instructions and customer requests
For information submitted by or obtained for a merchant, the merchant controls its use and is generally responsible for responding to its customers. Shopify sends Aeomatic mandatory data request and deletion webhooks. We use those requests to export or delete linked customer data, and to delete shop data when Shopify instructs us to do so, subject to narrow legal or security obligations.
Merchants and customers may also contact us to ask about access, correction, deletion, restriction, objection, or portability rights that apply under local law. We may need to verify the request or coordinate with the relevant merchant before acting.
Retention and security
We retain different categories for different periods based on operational, evidentiary, contractual, security, and legal needs. See our Data Retention and Deletion Policyfor details. We use technical and organizational safeguards intended to protect information, including access controls, encryption in transit, tenant-scoped application access, audit records, and backups. No system can guarantee absolute security.
Changes to this policy
We may update this policy as the Service or legal requirements change. We will update the date above and provide additional notice when required.
Contact
Questions or privacy requests can be sent to hello@aeomatic.io. Please identify the Shopify store involved so we can route and verify the request safely.