Privacy Policy
Last Updated:
1. Who We Are
StorePilot AI (“StorePilot”, “we”, “us”, or “our”) is a commerce intelligence application operated by Erhan Zorlu and made available at https://storepilotai.pro. StorePilot AI connects to a merchant’s Shopify store and, optionally, to their Google Ads, Google Analytics 4 (“GA4”), and Meta Ads accounts in order to analyze store and advertising performance and to generate recommendations. StorePilot AI analyzes and recommends only — it never takes automated actions on your store or advertising accounts without your explicit approval.
For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, the data controller for personal data processed through StorePilot AI is Erhan Zorlu, reachable at support@storepilotai.pro. Where we process store data on behalf of a merchant (for example, customer records contained in Shopify order data), we act as a data processor and the merchant is the controller of that data.
2. Information We Collect
We collect only the information needed to provide the service:
- Account and installation data: your Shopify store domain (myshopify.com address), store name, and the OAuth access tokens issued when you install the app or connect an integration.
- Shopify store data: products, orders, inventory levels, collections, discounts, and aggregate customer metrics, as authorized by the access scopes you approve during installation.
- Advertising and analytics data: campaign, ad set, spend, impression, click, conversion, and return-on-ad-spend metrics from Google Ads and Meta Ads, and session, traffic-source, landing-page, and conversion metrics from GA4 — only for the accounts and properties you explicitly connect.
- Connected identity data: when you connect Google or Meta, we receive the basic profile of the connecting user (a user ID, and for Google an email address and name) so we can label which account is connected.
- Technical data: server logs (IP address, request path, timestamp, user agent) generated when you use the app, retained for security and debugging.
We do not collect payment card numbers, government identifiers, or any special categories of personal data. We do not sell personal information to anyone.
3. Shopify Data Usage
When you install StorePilot AI from the Shopify App Store, Shopify grants us API access under the scopes shown on the installation screen. We use this access to build store performance snapshots (revenue, orders, product performance, inventory health) and to generate merchandising and profitability recommendations. Customer personal data contained in orders is processed only to compute aggregate metrics; we do not use it for advertising, profiling of individual shoppers, or any purpose unrelated to serving you.
We comply with Shopify’s privacy law compliance requirements, including the mandatory compliance webhooks. When Shopify sends us a customers/data_request, customers/redact, or shop/redact webhook, we respond by exporting or deleting the relevant data within the required timeframe. Uninstalling the app triggers deletion of your store’s access token immediately and deletion of stored store data as described in Section 9.
4. Google Ads Data Usage
If you connect Google Ads, we use the Google Ads API with read-only intent to retrieve campaign structure and performance metrics for the customer accounts you select. This data is used solely to display performance dashboards and to generate budget, scaling, and pause recommendations inside StorePilot AI. We never create, edit, or pause campaigns in your Google Ads account.
StorePilot AI’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the user-facing features described in this policy, is never sold, is never used for advertising, and is never transferred to third parties except as necessary to provide the service, comply with law, or as part of a merger or acquisition with prior notice. Humans do not read this data except with your consent, for security purposes, to comply with law, or when aggregated and anonymized.
5. Google Analytics 4 (GA4) Data Usage
If you connect GA4, we use the Google Analytics Data API with the read-only analytics scope to retrieve aggregate metrics — sessions, users, traffic sources, landing pages, and conversion events — for the GA4 properties you select. We use these metrics to correlate site traffic with store revenue and advertising performance. We do not access individual visitor-level identifiers, and the same Google Limited Use commitments in Section 4 apply to all GA4 data.
6. Meta Ads Data Usage
If you connect Meta Ads, we use the Meta Marketing API with the ads_read and business_management permissions to retrieve campaign, ad set, spend, reach, frequency, and conversion metrics for the ad accounts you select. This data is used only to display performance dashboards and generate recommendations. We never create, modify, publish, or pause ads, and we never access your Facebook or Instagram profile content, friends, messages, or audience lists.
Our processing of Meta Platform Data complies with the Meta Platform Terms and Developer Policies. Platform Data is retained only while your Meta connection is active and is deleted as described in Sections 9 and 10.
7. Cookies
StorePilot AI uses only strictly necessary, first-party cookies. We do not use advertising, tracking, or third-party analytics cookies, and we do not respond to cross-site tracking. The cookies we set are:
- Session and store-context cookies — identify your connected store during a browsing session (HttpOnly, Secure).
- OAuth state cookies — short-lived (10 minutes) anti-forgery tokens set while you authorize a Google, GA4, or Meta connection (HttpOnly, Secure, SameSite=Lax). These protect you against cross-site request forgery during sign-in and are deleted as soon as the authorization completes.
Because these cookies are essential for the service to function, they do not require consent under the ePrivacy rules; the app cannot operate without them.
8. OAuth Authentication
All integrations use the industry-standard OAuth 2.0 authorization flow. You authenticate directly with Shopify, Google, or Meta on their own domains; StorePilot AI never sees or stores your passwords. We store only the access and refresh tokens those providers issue, encrypted at rest with AES-256-GCM. You can revoke our access at any time from your Shopify admin, your Google Account permissions page, or your Facebook Business Integrations settings. Revoking access immediately invalidates the stored tokens.
9. Data Retention
- Access tokens: deleted immediately when you disconnect an integration, uninstall the app, or revoke access from the provider.
- Store and advertising snapshots: retained while your account is active and deleted within 30 days of app uninstallation or a
shop/redactwebhook. - Customer personal data in Shopify order records: deleted or anonymized within 30 days of a
customers/redactrequest. - Server logs: retained for a maximum of 90 days for security and troubleshooting, then deleted.
10. Data Deletion Requests
You can request deletion of all data StorePilot AI holds about you or your store at any time. Full step-by-step instructions — including Shopify, Google Ads, GA4, Meta Ads, OAuth tokens, and stored analytics — are on our dedicated User Data Deletion page (https://storepilotai.pro/data-deletion). In short, you can:
- Uninstall the app from your Shopify admin (triggers automatic deletion).
- Disconnect an individual integration from the Connections page in the app.
- Email support@storepilotai.pro with the subject “Data Deletion Request” and your store domain. We will confirm deletion within 30 days.
11. Your Rights (GDPR, UK GDPR, and CCPA)
If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict, or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time. Our legal bases for processing are the performance of our contract with you (providing the service), our legitimate interests (security and service improvement), and your consent (optional integrations). You also have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act (CCPA/CPRA) gives you the right to know what personal information we collect (described in Section 2), the right to request deletion, the right to correct inaccurate information, and the right to non-discrimination for exercising these rights. We do not sell or share personal information as those terms are defined in the CCPA, so no opt-out is required.
To exercise any of these rights, email support@storepilotai.pro. We respond to verified requests within 30 days.
12. Security
We protect your data with industry-standard measures: all traffic is encrypted in transit with TLS (HTTPS); OAuth tokens are encrypted at rest with AES-256-GCM; protected API routes require verified Shopify session tokens so one merchant can never access another merchant’s data; and access to production systems is restricted and logged. No method of transmission or storage is 100% secure, but if we become aware of a breach affecting your personal data we will notify you and the relevant authorities as required by applicable law (including within 72 hours where GDPR applies).
13. Third-Party Services
We rely on the following processors and platforms to operate the service:
- Shopify — commerce platform and app distribution (privacy policy).
- Google — Google Ads API, Google Analytics Data API, and Google OAuth (privacy policy).
- Meta Platforms — Meta Marketing API and Meta OAuth (privacy policy).
- Railway — application hosting and database infrastructure (privacy policy).
Hosting infrastructure may store data outside your country of residence. Where data is transferred out of the EEA or UK, we rely on providers that offer appropriate safeguards such as Standard Contractual Clauses.
14. Children’s Privacy
StorePilot AI is a business tool intended for merchants and is not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last Updated” date above, and where required by law we will notify you through the app or by email. Continued use of the service after an update constitutes acceptance of the revised policy.
16. Contact
For any privacy question, request, or complaint, contact:
Erhan Zorlu — StorePilot AI
Email: support@storepilotai.pro
Website: https://storepilotai.pro