Privacy Policy
Effective 2026-07-02
Information obtained from Shopify
OmniAI processes shop identity, installation and session data, granted scopes, billing status, product and variant data, confirmed-change audit records, and app-owned theme block configurations. For merchant-requested revenue reports, OmniAI fetches only order dates, shop-currency totals, discounts, refunds, cancellation state, and purchased-item titles and quantities. It does not request customer names, email addresses, phone numbers, postal addresses, payment credentials, or fulfillment details.
Information provided by merchants
OmniAI processes merchant chat instructions, settings, imported files, previews, generated media, support communications, and usage records needed to provide and secure the service. Merchants control this content and must not submit customer personal information that is not needed for the requested task. Shopify access tokens are stored server-side and are never included in merchant exports or sent to AI providers.
Customer and storefront data
OmniAI does not create customer profiles, maintain customer-indexed records, or retain raw Shopify order records. Merchant-provided chats or files are retained as merchant content and can contain information the merchant chooses to submit. OmniAI's Theme App Extension does not set storefront cookies, fingerprint visitors, or run advertising or product-analytics tracking. Service providers may create essential infrastructure and security logs when requests reach OmniAI. OmniAI does not sell personal information or use it for targeted advertising.
How information is used and AI processing
We use information to authenticate the embedded app, answer merchant requests, generate previews, execute merchant-confirmed changes, provide rollback where supported, operate billing, enforce plan limits, troubleshoot failures, prevent abuse, and comply with legal obligations. Relevant merchant prompts and product context may be processed by OpenAI. Requests are configured not to be stored by OpenAI and are not submitted for model training by OmniAI. Access tokens and customer personal data must not be sent to AI providers.
Processors and international transfers
OmniAI uses Shopify, Supabase, Vercel, and OpenAI to provide the service. Depending on the merchant's location, information may be processed in another country. Where applicable, transfers rely on provider contractual safeguards, adequacy decisions, or standard contractual clauses required by data-protection law.
Retention and deletion
Raw Shopify order data is fetched on demand for revenue calculations and is not retained. Chat history may retain the resulting aggregate report text. While a shop is installed, OmniAI retains its settings, chats, previews, generated assets, usage, billing, and audit records until the merchant deletes them where controls are available or uninstalls the app; short-lived previews and credit reservations expire automatically. Operational and security logs are retained only as long as reasonably necessary for security and troubleshooting. After uninstall, access is disabled immediately and merchant data is scheduled for deletion after 30 days, allowing restoration on reinstall during that period. A verified Shopify shop/redact webhook deletes shop data immediately. Deletion covers database records and stored imports/generated assets, leaving only a non-reversible hashed deletion receipt. Customer privacy webhook identifiers are HMAC-hashed rather than stored raw.
Privacy requests and rights
Merchants can export retained app data from Settings, delete supported content, uninstall OmniAI, or contact the privacy address below to request access, correction, deletion, restriction, portability, or objection where applicable. Merchants remain responsible for handling requests from their customers and can initiate Shopify's mandatory privacy process. OmniAI verifies those webhook signatures and, because it does not maintain customer-indexed records, records only a hashed audit receipt confirming that no matching indexed record was found. Merchants must handle customer information they placed in unstructured chats or files through their authenticated export and deletion controls or by contacting us. We may request information needed to verify the requester and will respond within the period required by applicable law.
Security and contact
Server routes verify Shopify signatures, session tokens, and webhook HMACs. Privacy contact: app.omniai@gmail.com. Support: app.omniai@gmail.com.