Legal
Privacy Policy
Last updated: July 13, 2026
AnswerShelf is a Shopify app that scans your product catalog, drafts merchant-reviewable improvements, and — only after you approve them — writes structured facts back to your store. This policy explains exactly what data the app accesses, how it is used, where it is stored, and how it is deleted.
1. Who this applies to
This policy covers merchants who install the AnswerShelf app on their Shopify store ("you") and describes the practices of AnswerShelf ("we", "us"). It applies to the app running in your Shopify admin and to the backend services that support it.
2. What we access and store
Store & account data
- Your store's myshopify.com domain and Shopify-issued identifiers.
- An OAuth access token granted at install, used to read and (with your approval) write product data through the Shopify Admin API. It is stored encrypted at rest and never shared.
- Your subscription/plan status and usage counters (for example, Fix Packs and prompt tests used this billing period) so we can enforce plan limits.
Product data
- We read your product catalog — titles, descriptions, product type, tags, images, and existing metafields — to compute readiness scores and detect evidence gaps.
- For an AI Shelf Score run, we store the included products’ IDs, titles, and score and visibility results so the app can show the run and its priority list.
- We store product IDs received in product-update webhooks to flag that a product changed after a scan.
- When the merchant explicitly enables the optional llms.txt feature in Settings, we store a compiled document made from the merchant-approved AnswerShelf fields and serve it through the merchant’s public Shopify app-proxy route. That route is a public storefront surface, so AI crawlers and storefront visitors can read it. The merchant can disable it at any time, which removes the public file.
- When you generate a Fix Pack or run prompt tests, relevant product text is sent to our AI provider (see Sub-processors) to draft suggestions and grade results. We do not send your product data to any AI provider for training.
- The Fix Pack fields you approve are written back to your store as structured metafields in the
answershelfnamespace. The same approval can update primary-image alt text and, when description publishing is enabled, a clearly-marked, reversible facts block. Nothing is written until you approve the product’s Fix Pack.
What we do not collect
- We do not access, request, or store your customers' names, emails, addresses, orders, or payment information.
- Prompt-test results are computed for your session and are not retained as a customer record.
3. How we use data
- To provide the app's core features: scoring your catalog, generating Fix Packs, running prompt tests, and publishing approved changes.
- To enforce your plan's limits and verify an active subscription before granting paid actions.
- To operate, secure, and troubleshoot the service. We do not sell your data or use it for advertising.
4. Sub-processors
We rely on a small set of trusted providers to run the app:
- Shopify — the platform your store and product data live on; source of the data we read and the destination we write to.
- Google Cloud / Firebase — hosting, backend functions, and storage of your store session, entitlement, usage, score-run, llms.txt, and product-drift records.
- OpenAI — processes product text you submit for Fix Pack generation and prompt-test grading. Data sent for these features is not used to train their models.
5. Data retention & deletion
- Store session, entitlement, usage, score-run, llms.txt, and product-drift records are retained only while the app is installed.
- When you uninstall AnswerShelf (or when Shopify sends a
shop/redactrequest), we delete your store’s session, entitlement, usage, score-run, llms.txt, and product-drift records. - We honor Shopify's mandatory
customers/data_requestandcustomers/redactrequests. Because AnswerShelf does not store customer personal data, these requests do not return or delete any customer records — there are none to return. - You may also request deletion at any time by emailing us (see Contact).
6. Security
Data is transmitted over HTTPS and stored on Google Cloud infrastructure, encrypted at rest. Access tokens are kept in access-restricted database records, and application secrets in the platform’s protected environment configuration. Webhook requests are verified with HMAC signatures, and privileged API requests require a valid Shopify session token. Access to production systems is limited to what is necessary to operate the service.
7. Your rights
Depending on your region, you may have the right to access, correct, export, or delete the data we hold about your store, and to withdraw consent by uninstalling the app. To exercise any of these rights, contact us at the address below.
8. Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected here with a new "last updated" date. Continued use of the app after an update constitutes acceptance of the revised policy.
9. Contact
Questions, requests, or concerns about privacy? Email support@getanswershelf.com.