ShopSense AI Data Analyst – Privacy Policy
Effective Date: May 2025
1. Introduction
ShopSense AI Data Analyst (“we,” “our,” or “us”) is committed to protecting your privacy and handling your personal information responsibly. This Privacy Policy explains how we collect, use, store, and protect information when you use our Shopify application.
2. Information We Collect
2.1 Store Data
– **Store Analytics:** Sales data, revenue metrics, order information, product performance
– **Performance Metrics:** Conversion rates, average order values, customer acquisition data
– **Product Information:** Product details, inventory levels, pricing data
– **Order Data:** Transaction details, order patterns, seasonal trends
2.2 Protected Customer Data (Level 1)
We process the following protected customer data to provide analytics functionality:
– **Customer Analytics:** Aggregated customer behavior patterns
– **Purchase History:** Order patterns and buying behavior (anonymized)
– **Geographic Data:** Regional sales performance (without personal identifiers)
– **Demographic Insights:** Age groups, customer segments (anonymized)
2.3 Protected Customer Fields (Level 2) – If Applicable
When explicitly required for advanced analytics features:
– **Name Fields:** First and last names (only when necessary for personalized insights)
– **Email Addresses:** For customer segmentation analysis
– **Phone Numbers:** For communication preference analytics
– **Addresses:** For geographic and shipping analysis
2.4 Technical Data
– **Usage Analytics:** App interaction patterns, feature usage
– **System Logs:** Error logs, performance metrics
– **Authentication Data:** Shopify store tokens, session information
3. How We Use Your Information
3.1 Primary Purposes
– **Analytics Generation:** Creating sales reports, performance dashboards
– **Forecasting:** Predictive analytics for sales and inventory planning
– **Insights Delivery:** AI-powered recommendations and business insights
– **Trend Analysis:** Identifying patterns in sales and customer behavior
3.2 Data Minimization
We process only the minimum personal data required to provide app functionality. We do not collect or process personal data beyond what is necessary for our stated purposes.
3.3 Automated Decision-Making
Our AI algorithms may make automated recommendations about:
– Inventory management
– Sales forecasts
– Marketing opportunities
– Product performance
**Customer Rights:** If our automated processing significantly affects customers, they may request manual review of decisions.
4. Data Sharing and Disclosure
4.1 Third-Party Services
We may share data with:
– **OpenAI:** For AI-powered analytics generation (anonymized data only)
– **Database Providers:** For secure data storage (encrypted)
– **Hosting Services:** For app infrastructure (Render.com)
4.2 No Data Sales
We do not sell, rent, or trade your personal data or customer data to third parties for marketing purposes.
4.3 Legal Requirements
We may disclose information when required by law, court order, or to protect our rights and safety.
5. Data Security
5.1 Encryption
– **Data in Transit:** All data transmissions use TLS 1.2+ encryption
– **Data at Rest:** Database storage encrypted using AES-256 encryption
– **Backup Encryption:** All data backups are encrypted and stored securely
5.2 Access Controls
– **Staff Access:** Limited to authorized personnel only
– **Strong Authentication:** Multi-factor authentication required
– **Access Logging:** All data access is logged and monitored
– **Regular Audits:** Periodic security assessments and reviews
5.3 Data Loss Prevention
– **Network Security:** Firewall protection and intrusion detection
– **Regular Monitoring:** Continuous security monitoring
– **Incident Response:** Documented security incident response procedures
6. Data Retention
6.1 Retention Periods
– **Analytics Data:** Retained for 3 years for trend analysis
– **Personal Data:** Deleted within 30 days of app uninstallation
– **Logs:** System logs retained for 1 year for security purposes
– **Aggregated Data:** Anonymous statistical data may be retained indefinitely
6.2 Deletion Procedures
– Automatic deletion upon app uninstallation
– Manual deletion available upon merchant request
– Secure data wiping procedures for all deletions
7. Your Rights
7.1 Merchant Rights
– **Access:** Request access to your data and processing activities
– **Rectification:** Correct inaccurate or incomplete data
– **Erasure:** Request deletion of your data
– **Portability:** Receive your data in a structured format
– **Restriction:** Limit processing of your data
– **Objection:** Object to certain processing activities
7.2 Customer Rights (End Users)
– **Consent Management:** Respect customer consent preferences
– **Opt-Out Rights:** Honor opt-out requests for data sharing
– **Access Requests:** Facilitate customer data access requests
– **Deletion Requests:** Process customer data deletion requests
8. Privacy Law Compliance
8.1 GDPR Compliance (EU)
– Legal basis for processing: Legitimate interest and consent
– Data Protection Officer contact: info@cettechventure.com
8.2 CCPA Compliance (California)
– **Categories of Data:** Business and commercial information
– **Business Purpose:** Analytics and business insights
– **No Sale:** We do not sell personal information
– **Consumer Rights:** Access, deletion, and opt-out rights
8.3 Other Jurisdictions
We comply with applicable privacy laws in all jurisdictions where we operate.
9. Shopify-Specific Provisions
9.1 Protected Customer Data
– We process protected customer data in accordance with Shopify’s requirements
– Data processing limited to approved purposes only
– Unapproved fields are not accessed or stored
– Regular compliance reviews and audits
9.2 Webhooks Compliance
We have implemented mandatory compliance webhooks:
– **customers/data_request:** Customer data access requests
– **customers/redact:** Customer data deletion requests
– **shop/redact:** Shop data deletion requests
9.3 Data Protection Agreement
This Privacy Policy serves as our Data Protection Agreement with merchants using our app.
10. Children’s Privacy
Our service is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
11. International Transfers
Data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place for such transfers.
12. Contact Information
12.1 Privacy Inquiries
**Email:** info@cettechventure.com
**Address:** 3 Germay Dr Unit 1430 Wilmington DE USA
12.2 Data Protection Officer
**Email:** info@cettechventure.com
12.3 Support Contact
**Email:** info@cettechventure.com
13. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via:
– Email notification to registered merchants
– In-app notifications
– Updates on our website
14. Effective Date and Acceptance
This Privacy Policy is effective as of 23 May 2025. By installing and using ShopSense AI Data Analyst, you acknowledge that you have read, understood, and agree to this Privacy Policy.
15. Additional Resources
– **Shopify Privacy Policy:** https://www.shopify.com/legal/privacy
– **OpenAI Privacy Policy:** https://openai.com/privacy/
– **GDPR Information:** https://gdpr.eu/
– **CCPA Information:** https://oag.ca.gov/privacy/ccpa
—
**Document Version:** 1.0
**Classification:** Public
**Review Cycle:** Annual
For questions about this Privacy Policy or our privacy practices, please contact us using the information provided above.