Privacy policy
Effective and last updated:
StoreKnows is operated by Invenire Studios. This policy explains how we handle information when someone visits our public website, when merchants use our Shopify app, when we check a public storefront, and when a supported shopping agent uses StoreKnows tools.
Store knowledge, with clear boundaries. We use store and product information to run simulated AI shopper checks and provide merchant-selected, read-only storefront tools.
Published tool data is public. AI checks send relevant information to model providers. Our storefront tool-call records contain usage details, not shoppers’ questions or conversation transcripts.
Privacy questions or requests: support@storeknows.com.
1. Information we handle
- Store and staff information. Shopify provides store identifiers, domains, store profile and contact details, plan, locale, currency and installation permissions. For staff who open the app, we receive their Shopify user ID, name, email, locale and account or collaborator status. We keep access credentials needed to operate the installation.
- Catalog and storefront information. We capture product details, variants, prices, availability, specifications, metafields, metaobjects and relevant storefront content such as policies and size charts, within the permissions granted to the app. Catalog snapshots can include information read through Shopify’s Admin API that is not yet public.
- Checks and previews. We process generated test questions, merchant-entered preview questions, relevant source data, simulated assistant answers, tool interactions, evaluation results, errors, timing and model usage. Saved checks allow merchants to review results and comparisons. Do not put confidential or personal information into test questions or product fields intended for publication.
- Billing and support. We retain Shopify purchase identifiers, amounts, currency, status, included-check allowance usage and related store identifiers, along with messages and contact information you provide to support. Shopify processes payment details; StoreKnows does not collect payment-card numbers.
- Storefront tool calls. Our tool-call records contain the tool name, success or error category, duration, result count, bundle version, argument names, a broad browser family, an automation indicator and receipt time. They do not contain argument values, shopper prompts, conversation transcripts, cart contents, page URLs or visitor identifiers. These records count tool calls, not unique shoppers.
- Public website analytics. On storeknows.com, Google Analytics processes page views, referring sources, broad device and browser information, approximate location derived from network information, and interactions such as scrolling and outbound-link clicks. We do not send Shopify account details, merchant catalog data or information entered in the app to this website analytics stream.
- Technical and compliance records. Servers and service providers process request metadata, which can include IP addresses and user-agent information, for delivery, reliability and security. We also retain Shopify webhook deliveries. A mandatory privacy webhook can contain customer or request identifiers even though the app does not request access to Shopify customer or order records.
If you supply a storefront password for a password-protected store, we use it to perform the requested storefront checks. Stored Shopify access tokens, refresh tokens and storefront passwords are encrypted in the application database.
2. How we use information
We use this information to authenticate the installation and its staff, read and evaluate the catalog, generate and test proposed fixes, publish selected tools, verify storefront availability, show reports, manage purchases, send service messages, provide support, prevent abuse and respond to privacy requests.
Where data-protection law requires a legal basis, these purposes rely on providing the service you request, our legitimate interests in operating and securing it, complying with legal obligations, or consent where required. When we process store information on a merchant’s instructions, the merchant remains responsible for their collection and use of that information.
We do not sell personal information or use storefront tool-call records for behavioral advertising.
4. Public storefront checks
We may evaluate publicly accessible storefront information without an app installation to prepare a store-specific report. These checks use public pages and catalog information, rather than Shopify Admin API access. A report is accessible to anyone who has its report link, so share that link carefully.
To prepare report emails, we store a summary of the public catalog, selected report findings, draft messages, recipient contact details, documented email permission, and review or stop decisions. These preparation records remain private. Report follow-ups require documented opt-in. Unsubscribing stops report marketing emails without deleting the report. We retain minimal domain and hashed-email suppression records to honor opt-outs and avoid sending to addresses that bounce, including after report removal.
Public report links expire after 60 days by default. Expiry removes access to the report; it is not a promise that every stored copy is immediately deleted. The report’s removal option deletes its stored report data and keeps a minimal domain suppression record so we do not repeat the outreach check. You can also contact us to request removal.
5. Retention, uninstalling and deletion
We retain store information, catalog snapshots and check history while needed to provide the app, resolve support issues and meet legitimate operational or legal needs. There is no general automatic expiry for merchant check history in the current app. Our scheduled raw tool-call retention window is 90 days; daily aggregate counts are retained while associated with the store. Browser-runner job records have a scheduled 30-day cleanup window after completion.
Uninstalling ends the app’s Shopify access. It is distinct from deleting all stored records. When Shopify sends its shop-erasure request, we remove the shop record and associated staff, catalog, check and telemetry data, and request removal of associated runner jobs. Minimal billing records, including store-level allowance counts without questions, answers or staff details, may remain to honor purchases and prevent duplicate allowance use after reinstall. A record of the erasure may remain for accounting, legal and compliance purposes.
Deletion from backups, provider systems and operational logs can follow their separate retention cycles. Information already made public may remain with third parties. Contact us if you need information removed before the normal erasure process.
6. Security and cookies
We use encrypted connections, encrypted stored application credentials, authenticated app requests and signed service callbacks to help protect information. Access is limited to operating and supporting the service. No method of transmission or storage is completely secure.
The public marketing website at storeknows.com uses Google Analytics and can store analytics identifiers in the browser. Advertising storage, Google signals and advertising-personalization signals are disabled in our website tag. This privacy page does not load that tag. StoreKnows’ storefront tool-call telemetry does not use cookies, local storage or a device identifier to track shoppers. Shopify and any external services you use may have their own cookies and privacy practices.
7. Your choices and privacy rights
You can review proposed fixes before publication, turn off the theme app embed, or uninstall StoreKnows. Turning off the embed stops it loading through your theme; it does not erase copies of data that have already been retrieved. Contact us for data-removal requests.
Depending on the laws that apply to you, you may request access to, correction of, deletion of or a portable copy of personal information, object to or restrict processing, or withdraw consent where processing relies on it. We may need to verify your identity and connection to the store before responding. We will explain any applicable limits, such as required financial recordkeeping.
For a question about a purchase or the personal information held by a merchant, contact that merchant first. For information held by StoreKnows, contact us below. You may also raise a concern with your local data-protection authority.
8. Contact and policy changes
Contact Invenire Studios, the operator of StoreKnows, at support@storeknows.com for privacy questions, requests or complaints. Include your store domain and a description of your request, but do not send passwords or payment-card details.
We may update this policy as the service or its data practices change. The date at the top identifies the current version. We will provide additional notice of material changes where required.