Privacy Policy
Last Updated & Effective: August 12, 2026
Speclyn ("we", "our", or "us") provides AI-driven product specification analysis, missing attribute detection, and AI Answer Engine Optimization (AEO) services for Shopify merchants through the Speclyn Shopify Application ("Application").
This Privacy Policy explains how we collect, use, store, and protect store data, product catalog information, and merchant account information when you install and use our Application.
1. Information We Collect
To provide automated product catalog analysis and metadata synchronization, we collect the following categories of information:
- Shopify Store Information: Store domain name (`myshopify.com` domain), store primary locale, and plan settings.
- Product Catalog Data: Product titles, descriptions, handles, product types, tags, vendor names, image URLs, variant attributes, and Metafields required for attribute analysis.
- Merchant Communication: Support tickets, messages, and settings preferences submitted within the Application.
- Usage & Audit Logs: System logs, API rate limit metrics, and background processing task logs for system stability and maintenance.
2. Customer Data & Zero-PII Policy
🔒 Zero End-Customer PII Storage:Speclyn does NOT collect, store, or process end-customer Personally Identifiable Information (PII) such as customer names, email addresses, phone numbers, or credit card billing details.
We handle Mandatory Shopify Privacy Webhooks (`customers/data_request`, `customers/redact`, and `shop/redact`) automatically to ensure full compliance with GDPR, CCPA, and Shopify App Store policies.
3. Artificial Intelligence & Third-Party Processors
Speclyn utilizes Google Gemini AI API to analyze public product information and generate structured category questions for missing attributes.
- Product text content is transmitted securely using strict boundary tags (`<product_content>`) to eliminate prompt injection risks.
- No personal data or store credentials are ever sent to AI model endpoints.
- Product information processed via API is strictly used to return structured specification JSON outputs for your store.
4. Data Security & Isolation
All store data is stored in isolated PostgreSQL database structures with strict store-level multi-tenant boundaries (`shopId` isolation). Data transmissions between Shopify, our servers, and database layers are encrypted using TLS 1.3 standards.
5. Data Retention & Account Deletion
When you uninstall the Speclyn Application from your Shopify store:
- We receive Shopify's `app/uninstalled` webhook and immediately deactivate your account.
- All associated product findings, questions, answers, and support tickets are permanently deleted from our database within 48 hours, in full accordance with Shopify GDPR requirements (`shop/redact`).
6. Contact Information
If you have any questions regarding this Privacy Policy or data processing practices, please reach out to us:
Speclyn Support Team
App Support: Accessible directly via the embedded Merchant Support Portal inside Shopify Admin.
© 2026 Speclyn. All rights reserved. Built for Shopify.