Privacy Policy
Effective 2026-07-30
Information obtained from Shopify
OmniAI processes shop identity, installation and session data, granted scopes, billing status, product and variant data, confirmed-change audit records, and app-owned theme block configurations. For merchant-requested revenue reports, OmniAI fetches only order dates, shop-currency totals, discounts, refunds, cancellation state, and purchased-item titles and quantities. It does not request customer names, email addresses, phone numbers, postal addresses, payment credentials, or fulfillment details.
Information provided by merchants
OmniAI processes merchant chat instructions, settings, imported files, previews, generated media, support communications, and usage records needed to provide and secure the service. Merchants control this content and must not submit customer personal information that is not needed for the requested task. Shopify access tokens are stored server-side and are never included in merchant exports or sent to AI providers.
Customer and storefront data
OmniAI does not create customer profiles, maintain customer-indexed records, or retain raw Shopify order records. Merchant-provided chats or files are retained as merchant content and can contain information the merchant chooses to submit. OmniAI's Theme App Extension does not set storefront cookies, fingerprint visitors, or run advertising or product-analytics tracking. Service providers may create essential infrastructure and security logs when requests reach OmniAI. OmniAI does not sell personal information or use it for targeted advertising.
How information is used and AI processing
We use information to authenticate the embedded app, answer merchant requests, generate previews, execute merchant-confirmed changes, provide rollback where supported, operate billing, enforce plan limits, troubleshoot failures, prevent abuse, and comply with legal obligations. Relevant merchant prompts and necessary product context may be processed by OpenAI or the selected media provider. Requests to OpenAI are configured with storage disabled and are not submitted for model training by OmniAI. Access tokens, secrets, and customer personal data must not be sent to AI providers. See the AI transparency notice.
Processors and international transfers
OmniAI uses Shopify, Supabase, Vercel, OpenAI, and selected media-processing providers to provide the service. Depending on production configuration and the merchant's location, information may be processed in another country. Applicable processor contracts, transfer mechanisms—which may include an adequacy decision or standard contractual clauses—assessments, and production regions must be verified by the operator before public release. See the subprocessor register; publication of that register does not itself prove execution of a DPA or transfer mechanism.
Retention and deletion
Raw Shopify order data is fetched on demand for revenue calculations and is not retained. Chat history may retain the resulting aggregate report text. While a shop is installed, merchant-controlled settings, chats, generated assets, billing, and audit records persist until the merchant uses an available deletion control or uninstalls. A daily retention job deletes expired command previews after 7 days, billing-start locks after 1 day, completed or expired credit reservations after 30 days, verified or expired trial-attempt records after 90 days, and failed-operation diagnostics after 30 days. Provider, infrastructure, security-log, and backup lifecycles remain subject to verified production configuration and processor terms. After uninstall, access is disabled immediately and merchant data is scheduled for deletion after 30 days, allowing restoration on reinstall during that period. A verified Shopify shop/redact webhook deletes shop data immediately. Deletion covers database records and stored imports/generated assets, leaving only a non-reversible hashed deletion receipt. Customer privacy webhook identifiers are HMAC-hashed rather than stored raw.
Privacy requests and rights
Merchants can export retained app data from Settings, delete supported content, uninstall OmniAI, or contact the privacy address below to request access, correction, deletion, restriction, portability, or objection where applicable. Merchants remain responsible for handling requests from their customers and can initiate Shopify's mandatory privacy process. OmniAI verifies those webhook signatures, stores only an HMAC of the customer identifier, and queues customer data and redaction requests for authenticated manual review because customer information may exist in merchant-controlled unstructured chats or files. It does not claim that no matching data exists without that review. We may request information needed to verify the requester and will respond within the period required by applicable law.
Security and contact
Server routes verify Shopify signatures, session tokens, and webhook HMACs. Privacy contact: privacy@omniai.ltd. Support: support@omniai.ltd.