This Privacy Policy describes how Smart Shopping Assistant (“the App”, “we”, “us”, or “our”) collects, uses, stores, and protects information when you install and use our Shopify application, and when your store visitors interact with the shopping widget on your storefront.

By installing the App or using its features, you (the merchant) agree to the practices described in this policy. If you do not agree, please uninstall the App.

1. Who we are

Smart Shopping Assistant is a Shopify embedded app that helps merchants add a storefront shopping widget, configure branding and banner campaigns, manage popular search suggestions, and view search analytics.

Replace the contact email above before publishing this policy on your app listing or website.

2. Scope of this policy

This policy applies to:

  1. Merchants — Shopify store owners and staff who install and configure the App in the Shopify admin.
  2. Store visitors — People who use the shopping widget on a merchant’s online store (search, popular searches, product results).

We do not sell personal information. We do not use external language-model or third-party advertising services to process storefront searches.

3. Information we collect

3.1 Merchant and admin data

When you install the App, Shopify authenticates your store and may share information with us as part of the standard Shopify app authorization process, including:

DataPurpose
Store domain (e.g. your-store.myshopify.com)Identify your shop and associate settings and analytics
OAuth access token and session dataOperate the App and call Shopify APIs on your behalf
Granted API scopesProvide widget, search, file upload, and settings features
Staff user details from Shopify session (where applicable)Admin authentication — e.g. name, email, user ID, locale

We store session information in our application database to keep you signed in and to perform authorized Shopify Admin API requests.

3.2 Widget settings you provide

When you configure the App, we store settings you choose, such as:

  • Brand colors (primary, background, header)
  • Launcher position (four corners of the storefront)
  • Open behavior (on click or auto-open after a configurable delay, default 5 seconds)
  • Banner images and campaign schedules
  • Campaign links (URLs, collections, or pages)
  • Popular search terms and tag suggestions you enable

Banner images you upload are stored in Shopify Files via the Shopify Admin API, in your Shopify account.

3.3 Shopify store data accessed via API

To power search and admin features, the App accesses data from your Shopify store through permitted scopes, including:

  • Products — titles, descriptions, tags, product types, images, variants, and prices
  • Collections — titles and handles (for campaign links and suggestions)
  • Pages — titles and handles (for campaign links and suggestions)
  • Files — for banner image uploads

We use this data only to provide App functionality. We do not use your catalog data to train external models.

3.4 Storefront visitor / search analytics

When a visitor uses the shopping widget on your storefront, our servers may record:

DataPurpose
Your store domainAssociate the event with the correct merchant
Search query text (keyword)Display analytics and identify no-result searches
Event type (search with results / no results)Analytics reporting
TimestampTrends and time-based charts

We do not intentionally collect store visitors’ names, email addresses, phone numbers, payment details, or Shopify customer account IDs through the widget.

The widget loads configuration from our app proxy and sends search requests to our servers. We do not use third-party advertising or analytics trackers (such as Google Analytics) in the widget based on the current App implementation.

3.5 Technical and server data

Like most web applications, our hosting provider may automatically process standard server logs (e.g. IP address, request time, user agent, error logs) for security, debugging, and reliability. This data is not used for marketing profiling.

4. How we use information

We use collected information to:

  • Install, authenticate, and operate the App
  • Save and sync your widget settings and campaigns
  • Run product search against your catalog
  • Show search analytics in the merchant admin (totals, keywords, success rate, trends)
  • Upload and manage banner images in Shopify Files
  • Maintain security and prevent abuse
  • Comply with legal obligations

We do not use storefront search data to serve ads to your customers.

6. How we share information

We may share information only in these situations:

RecipientWhy
ShopifyApp platform, OAuth, Admin API, Files, and webhooks
Hosting provider (e.g. Railway)Running the App infrastructure and database
Service providersInfrastructure strictly needed to operate the App, under confidentiality obligations
Legal authoritiesWhen required by law or to protect rights and safety

We do not sell or rent personal information to third parties.

7. Data storage and location

App data (sessions, widget settings, search analytics) is stored in our application database on servers operated by our hosting provider. Exact storage location depends on your deployment region.

Shopify store content (products, files, etc.) remains in your Shopify account and is governed by Shopify’s Privacy Policy.

8. Data retention

Data typeRetention
OAuth sessionsRemoved when the App is uninstalled or when sessions expire
Widget settingsKept until you delete them, uninstall the App, or request deletion
Search analyticsKept to provide historical reporting until you request deletion or we apply a retention policy
Server logsRetained for a limited period for security and troubleshooting

When you uninstall the App, Shopify sends an uninstall webhook and we delete associated session records. Other stored settings or analytics may remain until manually removed or upon request — contact us if you want all shop data deleted after uninstall.

9. Security

We use reasonable technical and organizational measures to protect data, including:

  • HTTPS for data in transit
  • Access tokens stored securely and used only for authorized Shopify API calls
  • Restricted access to production systems

No method of transmission or storage is 100% secure. You are responsible for controlling access to your Shopify admin and staff accounts.

10. Merchant responsibilities

As a merchant using this App, you are typically the data controller for your customers’ interactions on your storefront. You should:

  • Inform visitors that search queries may be logged for store analytics
  • Publish your own store privacy policy where required
  • Configure the App in line with your legal and industry obligations
  • Only install the App if you agree to the Shopify API scopes listed in the App listing

11. API scopes

The App requests the following Shopify access scopes:

  • read_products, write_products
  • read_content
  • read_files, write_files
  • write_metaobject_definitions, write_metaobjects

These scopes are used for product search, widget configuration, banner uploads, and related admin features — not for unrelated purposes.

12. Children’s privacy

The App is not directed at children under 16. We do not knowingly collect personal information from children. If you believe we have received such data, contact us and we will take appropriate steps to delete it.

13. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or export personal data we hold about you as a merchant or administrator.

To exercise these rights, contact us at your-email@example.com. We will respond within the timeframe required by applicable law.

Store visitors should contact the merchant (store owner) directly for requests related to their relationship with the store.

14. International transfers

If you are located outside the country where our servers operate, your information may be transferred to and processed in other countries. We take steps to ensure appropriate safeguards where required by law.

15. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top. Material changes may be communicated through the App or your contact email. Continued use of the App after changes means you accept the updated policy.

16. Contact us

If you have questions about this Privacy Policy or our data practices:

Smart Shopping Assistant
Email: your-email@example.com
Website: Smart Shopping Assistant

17. Shopify-specific notice

Smart Shopping Assistant is built for Shopify. Your use of Shopify is also subject to Shopify’s terms and privacy policies. This policy applies only to the Smart Shopping Assistant app and related services we operate — not to Shopify’s platform as a whole.