1. What this covers
This policy covers the Rankbull for Shopify app installed from your Shopify admin. The main Rankbull platform has its own policy at rankbull.io/privacy.
2. What we store
When you install the app we store: your shop's myshopify domain, an API access token issued by Shopify (encrypted at rest with AES-256-GCM), the results of AI visibility scans you run (scores, engine answers, storefront checks), content the app generates for you (articles, topics, FAQs, meta descriptions), your app settings, and — only if you save it — your storefront password, also encrypted.
3. What we never store
We store no customer data. No customer names, emails, addresses, orders, or payment information ever reach our systems. The app requests only product, content, and file scopes — it cannot read your customers or orders at all.
4. What third parties see
To run scans and write content, we send your catalog context (product titles, types, descriptions, images) to AI model providers (Google Gemini, and OpenAI where configured). These requests carry no customer data. Scan questions are generic shopper questions about your niche. Our backend runs on Convex and our app server on Vercel, both under standard data-processing terms.
5. Emails
The optional weekly check-in email goes to your shop's registered email address and can be turned off any time in the app's tracking settings. We send nothing else.
6. Deletion
Uninstalling the app deletes your session and access token immediately. Shop data (scans, generated content, settings) is deleted in line with Shopify's mandatory data-erasure webhooks. Content the app published to your own store — blog articles, meta descriptions, alt text, FAQs — is yours and stays in your store.
7. GDPR & requests
We honor Shopify's customers/data_request, customers/redact, and shop/redact webhooks. Because we hold no customer data, customer requests return empty by design. For anything else, contact support@rankbull.io.