Example App privacy policy
This policy covers Example App, our app for Shopify, and only that app. It names the scopes the app is granted, the records it reads and writes, how long each category is kept, and what happens when you uninstall.
Worked example. This is not a real app, and it must not be submitted to any app store. Example App does not exist. Nobody can install it, no merchant has ever granted it a scope, and no data has ever passed through it. This page is published so that a reviewer, a merchant or whoever writes the next app policy can see the finished shape: which sections a per-app policy carries, how scopes are named one at a time, and where a value is still missing. Every scope, webhook and record type below is written out to show the level of detail expected, not to describe a live integration. To publish a real app policy, stamp a fresh page from /legal/apps/_template/ rather than editing or copying this one.
Draft, not yet reviewed by a lawyer. These documents were prepared as a structured starting point. Every highlighted value still needs to be supplied, and the whole set needs review by qualified counsel in India before it is relied on.
What this app is and which platform it runs on
Example App is an app for Shopify. A Platform is Shopify, Wix, WordPress, Ecwid, HighLevel, BigCommerce, or another system an Agent connects to. You install Example App on your own Shopify account, and it reaches your data only through the Shopify API, using the scopes you approve at install.
What the app does for a merchant: {{TODO: one or two sentences describing this app's job, supplied by whoever lists the app}}
The categories of data it touches are orders, products, customers and fulfillment records. Each is broken out below.
The app is published by AI Speedforce, trading name of {{TODO: registered legal entity name, e.g. AI Speedforce Technologies Private Limited}}, {{TODO: full registered address, Delhi, India}}, India.
Rules that Shopify places on every app built for it, rather than on this app in particular, live in the platform annex at /legal/platforms/shopify/. This page inherits those facts and does not restate them, so there is one place to correct when Shopify changes a rule. Our site-wide policies still apply on top: the privacy policy, the terms and the data processing addendum.
Data read via the Shopify API: scopes and resources
Example App requests these scopes at install. It asks for nothing outside this list, and each scope is here because a named task needs it. You can see the granted scopes in your Shopify admin and remove the app at any time.
| Scope or resource | What it contains | Why the app needs it |
|---|---|---|
read_orders |
Orders placed on the store: line items, quantities, prices, discounts, order status, and the customer and address attached to each order. Order records carry end customer personal data. | To read the order a support question is about, so the agent can answer from the real record rather than a guess. |
read_customers |
Customer records: name, email address, phone number, saved addresses, order count and any tags or notes the merchant has added. | To match an inbound question to the right shopper, and to check what that shopper has already bought before drafting a reply. |
read_products |
Products, variants, prices, options, images and the product descriptions and metafields on them. No personal data. | To quote the correct variant, price and option when answering a question about an item. |
write_products |
The same product records, with permission to change them. No personal data. | To apply a product description or metafield edit the merchant has approved at the human approval gate. Nothing is written before that approval. |
read_fulfillments |
Fulfillment records and their tracking numbers and carrier status against an order. | To answer "where is my order" from the current fulfillment state instead of an out of date copy. |
read_inventory |
Inventory levels per variant, per location. No personal data. | To say whether an item is in stock before the reply promises it. |
{{VERIFY: confirm every scope name in this table against Shopify's current access scope documentation, confirm what each one grants, and confirm that a merchant can still review granted scopes and remove the app from the Shopify admin, before this page is submitted for review}}
The app holds only the scopes its tasks need. Credentials are held per merchant and are not shared between merchants.
Data collected from you directly
Separately from the Shopify API, we hold a small amount of data about you as the merchant. In the clause library this is Service Data: data we hold to run our own business.
- Account. Your store or site identifier, the contact name and email address on the account, and the install and uninstall events for Example App.
- Billing. {{TODO: how the app is billed, and whether billing runs through the platform's own billing API or a payment processor. Name the processor if there is one, and confirm whether we ever see card data}}
- Support correspondence. Email you send to us about the app, our replies, and any screenshots, exports or record identifiers you attach to them. Support messages can contain personal data if you paste it in, so send only what the question needs.
- App logs and run traces. A run trace is the record of an Agent run: plan, tool calls, inputs, outputs, timings and cost. A run trace can contain personal data, including data about your customers.
For this data we are the controller.
Data about your end customers
Read this section carefully. It is the one that matters most for review.
Example App may read personal data about people who are not our customers. An End Customer is an individual who deals with you, for example a shopper or a lead. End Customer Data is personal data about that individual which the app reads or writes on your systems. Depending on the scopes you grant, that can include a name, an email address, a phone number, a shipping or billing address, order history and anything you or they have written into a note or a message.
Different laws use different words for the same two roles. Under the EU and UK GDPR they are controller and processor. Under India's Digital Personal Data Protection Act 2023 they are Data Fiduciary and Data Processor, and an individual is a Data Principal. Under the CCPA and CPRA they are business and service provider, and an individual is a consumer. Where this document says controller and processor, the equivalent role under the law that applies to you is meant.
For End Customer Data that an Agent reads or writes on your systems, you are the controller and we are the processor. You decide what the Agent does, which systems it reaches, and what it is allowed to write. We act on your documented instructions, which are the scope and configuration we agree with you in writing.
For Service Data, we are the controller.
In practice this means the merchant, not AI Speedforce, decides why an end customer's data is processed by this app. If an end customer asks us to delete their data, we route the request to you. The routing wording is in data requests below.
Why the app uses each category
Each category has one purpose. The app does not use a category for anything outside this table.
| Category | Purpose |
|---|---|
| Platform records read through the granted scopes | To carry out the task you installed the app for, on the records you point it at. |
| End Customer Data inside those records | Only as part of the same task, on your instructions, as your processor. |
| Merchant account data | To identify your install, apply your configuration, and contact you about the app. |
| Billing records | To charge for the app and to meet accounting and tax obligations. |
| Support correspondence | To answer your question and to keep a record of what was changed and why. |
| Run traces and error logs | To show you what the app did, to debug a failed run, and to score changes against evals. |
We do not sell personal data, we do not use End Customer Data for advertising, and we do not build profiles of your customers for our own purposes. What is sent to a model provider during a run, and what we do about training on your data, is set out in AI and your data.
How long each category is kept
Retention runs per category, not as one blanket period. Where a period is still marked below, it has not been set and must not be assumed.
| Category | How long it is kept | Why |
|---|---|---|
| Platform records cached by the app | {{TODO: how long the app caches platform records before re-reading them}} | The app holds the least it can and re-reads from the Shopify API where it is able to. |
| End Customer Data inside those cached records | {{TODO: how long the app caches platform records before re-reading them}} | It is deleted on the same clock as the record that carries it. It is not kept separately. |
| Run traces and error logs | {{TODO: how long run traces and logs are kept. This one matters, traces can contain end-customer data}} | Traces can contain personal data, so this period is a privacy decision, not only an engineering one. |
| Merchant account data | {{TODO: retention during and after an engagement}} | Kept while the app is installed, then for the period set here. |
| Billing records | {{TODO: statutory retention period for accounting and tax records in India, to be confirmed with counsel}} | Accounting and tax law sets this period, not us. |
| Support correspondence | {{TODO: how long support email is kept}} | Kept so a later question about the same change can be answered. |
| Backups | {{TODO: backup retention and rotation}} | A deleted record can persist in a backup until that backup rotates out. |
| Everything, after uninstall | {{TODO: COMMERCIAL TERM. Days after termination within which client data is deleted or returned}} | See deletion on uninstall. |
Deletion on uninstall
When you uninstall Example App, the app's access token stops working and the app can read nothing further from your account. {{VERIFY: confirm with Shopify's current documentation what uninstalling does to an app's access token, and how quickly it takes effect}}
What is deleted. Platform records the app had cached, the app's own working records about your store, and your configuration, including any thresholds and approval gates you set.
When. {{TODO: COMMERCIAL TERM. Days after termination within which client data is deleted or returned}} Deletion also runs on the platform's own redaction mechanism where one applies, described in Shopify compliance mechanism.
What is retained, and why. Billing records are kept for the statutory period in the retention table above, because accounting and tax law requires them. A record that you installed and uninstalled the app is kept so we can answer a later question about it. Backups are kept until they rotate out on the schedule in the retention table, so a deleted record can persist in a backup for that window and is deleted when the backup expires. Nothing retained is used to carry on processing your customers' data.
What we cannot delete. Data that lives in your own Shopify account is yours and stays there. Uninstalling the app does not remove records the app wrote into your store, because those are now your records. If you want them removed, remove them in your admin.
Sub-processors
A Sub-processor is a third party we use that may process Client Data or End Customer Data on our behalf. The current list, what each one does, what it receives and where it sits, is published once at /legal/subprocessors/ and is not duplicated here, so there is only ever one list to keep correct.
Model providers used for agent reasoning are on that list. What is sent to them during a run is described in AI and your data.
Data requests, and how to file one
Depending on where you live, you may have rights to access a copy of your personal data, to correct it, to have it deleted, to object to or restrict how it is used, to receive it in a portable form, and to complain to a regulator. Under India's DPDP Act 2023 a Data Principal also has the right to nominate another person to exercise their rights, and the right to a grievance redressal process.
If you are the merchant
Write to {{TODO: support@aispeedforce.com, confirm the mailbox exists}}, or to hello@aispeedforce.com, from the address on the app account, and say which app and which store you are asking about. You can ask for a copy of what Example App holds about your store, for a correction, or for deletion. Deletion of everything is what uninstalling triggers anyway.
If you are an end customer of a merchant
If you are an End Customer of a merchant that uses one of our apps, the merchant is the controller of your data and you should contact them first. If you contact us directly, we will pass your request to the merchant and support them in answering it.
The reason for that routing is not to deflect you. The merchant decides what data exists and why, so the merchant is the only party who can answer the whole question. We do not have a way to identify you across a merchant's store without the merchant.
How long we take
Our published response times are {{TODO: GDPR Art 12(3) default is one month. Confirm the commitment you want to publish}} for GDPR requests, {{TODO: DPDP Act response period, to be set in your published grievance policy}} under the DPDP Act, and {{TODO: CCPA/CPRA default is 45 days, extendable. Confirm}} under the CCPA and CPRA. Grievances are acknowledged within {{TODO: acknowledgement window for a grievance}}.
Grievance Officer: {{TODO: name and email of the Grievance Officer. India's DPDP Act 2023 requires a Data Fiduciary to publish a contact who answers Data Principal questions}}
Encryption in transit and at rest
In transit: HTTPS and TLS for this website, for every call between Example App and the Shopify API, and for every call to a model provider. The app does not accept plain HTTP.
At rest: {{TODO: confirm what is encrypted at rest and by which provider}}
Access to app data follows least privilege, and credentials are held per merchant. The full set of controls, including secret handling and incident response, is at /legal/security/. We hold no security certification and we claim none.
Shopify compliance mechanism
Shopify operates its own mandatory mechanism for data requests and deletion that a listed app has to answer, whatever the app itself stores. The mechanism for Shopify, and the deadline attached to it, is described once in the platform annex at /legal/platforms/shopify/. The table below names the parts Example App answers.
| Mechanism | What it is for | What Example App does |
|---|---|---|
customers/data_request |
Sent when a shopper asks the merchant for the data a store and its apps hold about them. It carries the shop and the customer being asked about. | Example App answers it, gathers whatever it holds for that customer, and returns it to the merchant so the merchant can give it to the shopper. The merchant is the controller and answers the shopper. |
customers/redact |
Sent when a merchant asks for one shopper's data to be erased, or when the platform's own retention window for a customer of that store has passed. | Example App answers it and deletes the records it holds for that customer, including that customer's data inside cached orders and inside run traces. |
shop/redact |
Sent after a shop has uninstalled the app, to have everything held for that shop erased. It is the whole-store version of the customer redaction above. | Example App answers it and deletes the store's cached records, its configuration and its run traces, leaving only what the retention table says is kept and why. |
{{VERIFY: confirm against Shopify's current app requirements that these are still the mandatory mechanisms, that the names, payloads and triggers are unchanged, and what the current response deadline is}}
Answering this mechanism is a condition of staying listed, so it is implemented before an app is submitted rather than after.
Contact
App support and data requests: {{TODO: support@aispeedforce.com, confirm the mailbox exists}}
Privacy questions: {{TODO: privacy@aispeedforce.com, confirm the mailbox exists}}
Working fallback that reaches us today: hello@aispeedforce.com
Postal address: {{TODO: full registered address, Delhi, India}}
EU representative: {{TODO: GDPR Art 27 representative in the EU, required if you have EU data subjects and no EU establishment}} UK representative: {{TODO: UK GDPR representative, same condition for UK data subjects}}
Changes to this policy
We may update this document. When we do, we change the "Last updated" date and add a row to the version history at the foot of the page. Section anchors are stable and we do not rename them, so a link to a section keeps working.
If Example App asks for a new scope, or starts reading a record type that is not in the table above, we change this page before the new scope is requested, not after.
Version history
| Version | Date | Change |
|---|---|---|
| 0.1-draft | {{TODO: the date you publish these}} | First published draft. Not yet reviewed by counsel. |