Privacy Policy
What we collect, what we deliberately do not, and what you can ask us to do about it.
Last updated: 13 July 2026
Summary in plain English
- We read your store content (products, collections, pages, theme markup) so we can improve it. We never read your customers, your orders or your payment data.
- Content is sent to AI model providers to be analysed and rewritten. It is never used to train their models, and provider-side retention is contractually minimised.
- We sell nothing to anyone. No data brokers, no advertising networks, no resale of your catalogue.
- You can ask for a copy of your data, or ask us to delete it, by emailing privacy@shoprise.ai. We answer within 30 days.
This policy is a pre-launch draft. It describes how ShopRise actually operates, but it has not yet been reviewed by external counsel. Have it checked by a lawyer before relying on it.
Who we are and what this covers
ShopRise is an SEO, GEO and agentic-commerce platform for Shopify stores. It is an initiative by Nodefy and Webfluencer, both based in the Netherlands, and it is operated from the Netherlands under EU law.
This policy covers two different situations, and the difference matters more than the legal words suggest.
- We are the controller for the data we collect for ourselves: visitors to shoprise.ai, people who request a free scan, account holders, and billing contacts. We decide why and how that data is used, and this policy is the notice for it.
- We are a processor for the store data our customers connect. When you install ShopRise on your Shopify store, you remain the controller of that store's data. We act on your documented instructions, under our Data Processing Agreement, which is referenced in the Terms of Service.
In short: your merchants' data is yours. Our own visitor and customer data is ours to answer for, and this page is where we answer for it.
What we collect
Account data
Your name, work email address, company name, the Shopify store domain you connect, your role and seat, and the billing contact details needed to invoice you. If you pay through Shopify, Shopify handles the card details and we never see them.
Store data, pulled through the Shopify Admin API
With the scopes you grant at install, we read the content layer of your store so we can analyse and improve it:
- Products, variants, descriptions, images and metafields.
- Collections and their descriptions.
- Pages, blog articles and navigation.
- Theme files and rendered markup, so we can see what a crawler or model sees.
- Store-level settings that affect indexing, such as the
robots.txttemplate and redirects.
This is catalogue and content data. It is commercial information about what you sell, not personal information about who buys it.
Usage and product analytics
Which modules you open, which suggestions you approve or reject, job runs, errors, and the timing of requests. We use this to find what is broken and what is slow. It is tied to your account, not to an advertising profile.
Marketing site data
The free scan form on shoprise.ai collects your store URL, your email address, your name, an indication of store size, and what you are trying to achieve. We use it to run the scan, send you the report and follow up once. If you do not want the follow-up, say so in the form or reply to the email and we stop.
What we never collect
This is the part most privacy policies leave vague, so we will be blunt. ShopRise does not request, read or store:
- Customer personal data from your store. No names, no email addresses, no shipping addresses, no customer accounts.
- Orders. No order history, no line items, no fulfilment data.
- Payment data. No card numbers, no payment tokens, no bank details of your customers.
- Special category data. Nothing about health, beliefs, biometrics or anything else in Article 9 of the GDPR.
We do not ask Shopify for the scopes that would give us access to those objects. If you audit the permissions we request at install, you can verify it yourself, which is the point.
How we use it, and why we are allowed to
Every purpose below is tied to a legal basis under Article 6 of the GDPR.
- Providing the service (analysing your store, generating suggestions, publishing approved changes, tracking rankings and citations). Legal basis: performance of a contract.
- Billing and administration. Legal basis: performance of a contract and compliance with tax law.
- Support, including looking at your account when you ask us to. Legal basis: performance of a contract.
- Product improvement, security and abuse prevention, using aggregated usage and log data. Legal basis: legitimate interest in running a stable, secure product, balanced against the low privacy impact of aggregate telemetry.
- Marketing emails and product updates to people who asked for them. Legal basis: consent, withdrawable in one click, or legitimate interest for existing customers about the product they already use.
- Analytics on the marketing site. Legal basis: consent, as described under Cookies and tracking.
We do not sell personal data, we do not share it with data brokers, and we do not use your store content to build a product for someone else.
AI processing
ShopRise sends store content to large language model APIs to analyse it, score it and rewrite it. Today the primary provider is Anthropic (Claude). What gets sent is product copy, collection copy, page content, structured data and the SEO context around it.
- Your data is never used to train models. Our agreements with model providers exclude training on API inputs and outputs. This is a contractual commitment, not a setting we hope stays switched off.
- Provider-side retention is minimised. Zero or minimal retention is agreed contractually, so prompts and completions are not kept for provider purposes beyond what is needed to return the response and meet abuse-monitoring obligations.
- No customer personal data is in the prompt, because we never pulled any in the first place. See What we never collect.
- Outputs are suggestions. Nothing generated by a model reaches your live store until a human approves it in the Change Queue, unless you explicitly enable auto-optimize.
- Providers can change. If we add or replace a model provider, it appears in the sub-processor table below and we notify customers before it starts processing.
Sub-processors
These are the third parties that process data on our behalf. We stay responsible for what they do with it.
| Sub-processor | Purpose | Region |
|---|---|---|
| Anthropic (Claude) | Content generation, semantic analysis and scoring of store content | United States, under a data processing agreement with EU terms |
| Vercel | Hosting and delivery of the marketing site and the app front end | Global edge network, EU and United States |
| Supabase (on AWS) | Application database, authentication and file storage | European Union (Frankfurt) |
| SEMrush | Keyword volume, difficulty, ranking and competitor data | European Union and United States |
| Shopify | Source of store data through the Admin API, and the app platform itself | Canada and United States |
| Google Analytics 4 | Marketing site analytics, loaded through Google Tag Manager | European Union and United States |
| Transactional email | Account emails, scan reports, invoices and product notifications | European Union |
Customers on a signed Data Processing Agreement are notified before a new sub-processor starts processing, and can object on reasonable grounds.
How long we keep things
- Free scan requests: 12 months after our last contact with you, then deleted.
- Account and store content data: for as long as your subscription is active. Deleted or irreversibly anonymised within 60 days of termination, unless you ask us to delete it sooner.
- AI answer snapshots and citation history: a rolling 90 days.
- Application and access logs: 30 days, then rotated out.
- Invoices and accounting records: 7 years, because Dutch tax law requires it.
- Marketing site analytics: 14 months, the default GA4 window.
Backups follow their own cycle and are overwritten within 35 days. A deletion request is honoured in the live systems immediately and works its way out of backups on that cycle.
Your rights
Under the GDPR you can ask us to do all of the following, free of charge.
- Access. Get a copy of the personal data we hold about you.
- Rectification. Correct anything that is wrong.
- Erasure. Have your data deleted, unless we are legally required to keep it (invoices, mostly).
- Portability. Receive your data in a structured, machine-readable format, or have it sent to another provider.
- Objection. Object to processing based on legitimate interest, including direct marketing. For direct marketing there is no balancing test: we stop.
- Restriction. Ask us to freeze processing while a dispute about accuracy or lawfulness is resolved.
- Withdraw consent at any time, without affecting processing that already happened.
Email privacy@shoprise.ai and tell us what you want. We respond within 30 days, and we do not require a form, a portal or a phone call. If you are not happy with how we handled it, you can complain to the Dutch data protection authority, the Autoriteit Persoonsgegevens, or to the supervisory authority in your own country.
If your request is about data inside a merchant's store rather than about ShopRise itself, the merchant is the controller. Send the request to them, and we will support them in answering it.
Cookies and tracking
We keep this deliberately small. There is no advertising network on this site and no cross-site tracking.
Functional storage
The app uses a session cookie to keep you logged in and to remember basic preferences such as your active store. These are strictly necessary: without them the product does not work, so they do not require consent.
The cookie notice itself
When you dismiss the cookie notice, we store a single flag in your browser's
localStorage under the key shoprise_cookie_ack. It is not a
cookie, it is not sent to our servers, and it exists only so the notice does not follow
you around. Clearing your site data brings the notice back.
Analytics
The marketing site loads Google Tag Manager, which in turn loads
Google Analytics 4. GA4 sets first-party cookies (typically
_ga and _ga_<container>) to count visits and understand
which pages are useful. IP addresses are truncated by GA4 before storage, and we do not
use GA4 audiences for advertising.
How to opt out
- Block or delete cookies for shoprise.ai in your browser settings. Nothing on the marketing site breaks.
- Install the Google Analytics opt-out browser add-on, which blocks GA4 across every site.
- Use any content blocker. We do not detect, penalise or work around them.
- Email privacy@shoprise.ai and we will confirm what is set on your visit.
If we ever add advertising or remarketing tags, we will ask for consent first and update this section before they load.
International transfers
Our primary data store sits in the European Union. Some sub-processors are established in the United States, as listed in the table above. Where personal data is transferred outside the EEA, we rely on the European Commission's Standard Contractual Clauses, supplemented by technical measures such as encryption in transit and at rest, and, where the provider is certified, the EU-US Data Privacy Framework.
We keep a transfer impact assessment for each of these providers and we will share it with enterprise customers on request.
Security
Encryption in transit and at rest, least-privilege access, scoped Shopify tokens, no standing access to production data, and an approval step before anything is published to your store. The detail, including our sub-processor posture and how we handle incidents, lives on the security page.
If you believe you have found a vulnerability, email security@shoprise.ai. We will acknowledge within one business day and we will not take legal action against good-faith research.
Changes to this policy
When we change something material, such as adding a sub-processor or a new purpose, we update the date at the top of this page and notify account holders by email before the change takes effect. Minor edits for clarity are made without notice, and the date still changes.
Contact
ShopRise is an initiative by Nodefy and Webfluencer, established in the Netherlands. Our registered address, Chamber of Commerce number and VAT number are stated in our contracts and are available on request.
- Privacy and data requests: privacy@shoprise.ai
- Security reports: security@shoprise.ai
- Everything else: hi@shoprise.ai
We have not appointed a Data Protection Officer, because we are not required to. Privacy requests go to the address above and are handled by a human on the team.
Questions we did not answer here?
Ask us directly. We would rather have the conversation than hide behind a policy page.
Response within one business day