Privacy Policy
Last updated: 2026-09-19
This policy explains what data the Shopify app Capyo: AI Visibility & GEO and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a data controller.
1. Who is responsible
The controller for the processing described here is Capyo, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.
Operator legal name and address: [to be added]
For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses — see section 2 for exactly what it does read and store.
2. Data the app processes
It comes from Shopify when you install the app, from your storefront's Web Pixel, from the answers the engines return, and from you. In detail:
- Store record. Your
.myshopify.comshop domain, your current plan and when it was last checked, your primary and extra domains, store name, the top five vendor names used to recognise your store in an answer, primary locale, country code, merchant email, pixel id, install and uninstall timestamps, when the review prompt was shown, when the first run finished, and the day and hour your weekly run is scheduled. - Sessions. The Shopify access token issued to the app for your store, together with the shop domain, stored so the app can call Shopify's API on your behalf.
- Template state. Whether your llms.txt template has been previewed, written or removed, whether it was written manually, the theme id it was written to, the options it was generated with, the preview and written checksums, and when it was written.
- Validator results. The six read-only check results for your store's public surface — each with its pass, warn or fail state and the sentence explaining it.
- Query set. For each question: its text, language, whether the app proposed it or you wrote it, whether it is active, and its order in your list.
- Runs. When a run started and finished, what triggered it, its status, how many queries it covered, and the per-engine breakdown of surfaced, mentioned, absent and error answers.
- Answers. The query text as it stood when the run happened (a snapshot that survives later edits), which engine answered, the outcome, the matched URL when there was one, the citations (URL and title, at most 20), an excerpt of the answer of at most 500 characters, the response time, and the cost of the call.
- AI referral data. Per day and per assistant (ChatGPT, Perplexity, Claude, Gemini, Copilot and a generic other-AI label): visits, orders and revenue; a dedupe row per visit holding only the day and a random id the pixel mints for it; and one row per referred order with the order id, assistant, order value and currency.
- Monthly usage. Engine calls made and their cost for the current month, so plan limits can be applied.
- Alerts. The kind of alert (a drop in the weekly report, or a validator check that moved to fail), its payload, when it was first shown, and — once the weekly email digest is enabled — when it was emailed.
- Product-usage events. Shop domain, an event name from a fixed list (install; a setup step; template previewed, written or removed; validator run; queries saved; run finished; report viewed; plan changed; alert created; review requested; uninstall) and a timestamp — no personal data, used only to see which setup steps merchants get stuck on.
Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.
3. What the storefront pixel records
Capyo installs one Web Pixel extension through Shopify's own pixel API. It runs inside Shopify's strict sandbox: no DOM access, no third-party script and no advertising tags. It records AI referral visits and orders only; it is not a general analytics or advertising pixel. Its customer-privacy declaration is analytics on, marketing and preferences off, and whether it runs is governed by your store's privacy settings and Shopify's own consent handling.
The extension subscribes to two standard storefront events: page_viewed and
checkout_completed. When a page view arrives with a referrer — or a
utm_source — that matches a known AI assistant, the pixel stores an assistant label
and a timestamp in localStorage under the key capyo_ai_ref for 7 days
(first touch wins inside that window) and sends one small beacon to Capyo's own
/collect endpoint. When a checkout completes with a valid stored reference, it sends
a second beacon with the order id, value and currency. With no AI referrer, the pixel sends
nothing at all.
The beacons carry a version marker, the shop domain, the kind (visit or order), the assistant
label, the random per-visit id, the order id and value where relevant, and a timestamp.
/collect accepts small JSON or plain-text bodies, rejects anything over 2 KB,
answers 204 whether or not the input was valid, and is rate-limited. It stores no
IP address, user agent, page URL, customer id or email; the request's IP address is used only to
apply the rate limit and is never written to the database.
The llms.txt itself is plain Liquid rendered by Shopify from your own store data. It contains no URL of, call to, or dependency on Capyo.
4. What we never store
- Your customers' names, email addresses, postal addresses, phone numbers or customer ids.
- IP addresses and user agents.
- Page URLs.
- Full AI answers beyond the 500-character excerpt.
- Merchant API keys — the app asks you for none.
- Payment or card data — Shopify handles billing.
The query text and the engines' answers are about your products and your store, not about your
customers, and the app requests no read_orders scope and no protected customer data.
Shopify sends every public app the two mandatory customer-privacy webhooks
(customers/data_request and customers/redact). Capyo acknowledges them;
because it holds no customer personal data, there is nothing to return.
5. This website
This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.
The free store check. The check box on the home page asks a Cloudflare Worker to
read your store's public /llms.txt, /robots.txt and /agents.md
and its storefront home page, and to show you what it found. If you ask for the full six-point
report, we store the email address you enter and the store domain you
checked, and use them to send that report and occasional product updates. That is the only
personal data this website collects. It is processed by Cloudflare on our behalf, kept for up to
12 months, never sold, and deleted on request — email us and we remove it. Every
report includes a one-click unsubscribe link. The check itself stores no IP address, and the Worker
logs only the request path, status and duration.
6. Why we process it, and on what legal basis
- To provide the app you installed — keeping the llms.txt template state, running the six checks, counting AI referral visits and orders, storing your query set and, on Growth and Pro, running the weekly queries and building the report. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To send your query set to OpenAI and Perplexity, using the app's own API access, so the report can show which questions cite your store. The queries are your own text about your own store. Legal basis: performance of a contract with you.
- To bill you through Shopify's Managed Pricing. We read which plan is active; Shopify performs the billing. Legal basis: Art. 6(1)(b) GDPR.
- To keep the service secure and working — rate limiting, error handling, abuse prevention, and the usage events that show which setup steps fail. Legal basis: legitimate interests, Art. 6(1)(f) GDPR.
- To answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
- To meet legal obligations, including Shopify's mandatory compliance webhooks. Legal basis: Art. 6(1)(c) GDPR.
We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.
7. How long we keep it
- Sessions: deleted immediately when Shopify sends the
app/uninstalledwebhook, together with any queued jobs for your shop. - Referral dedupe rows: pruned daily; rows older than 2 days are deleted.
- Runs and answers: pruned daily; rows older than 12 months are deleted.
- Everything else about your shop — store record, template state, validator
results, query set, referral day totals and orders, monthly usage and alerts: deleted when
Shopify sends the
shop/redactwebhook, which deletes every row for the shop in every table. Ask us to delete earlier and we will. - The template file itself is not stored by Capyo — it lives in your theme until you remove it. One click in the app removes it; if it is left behind it keeps working, because it is plain Liquid with no connection to this app. Remove it before uninstalling if you do not want it to stay.
8. Who else is involved (sub-processors)
| Sub-processor | Company country | What they do | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | The platform the app runs on and the source of all store data; also handles billing | Per Shopify's own DPA |
| OpenAI | United States | Receives the app's query set and returns the answers and citations the report is built from — the app asks through the app's own OpenAI API key, on paid plans only, and no account or credential of yours is involved | United States |
| Perplexity | United States | Receives the same query set through the app's own Perplexity search API key and returns the answers and citations the report is built from — paid plans only | United States |
| Resend | United States |
Weekly email digest to the merchant's own address, and only when email sending is enabled
(EMAIL_ENABLED=on); until then no email code path runs and Resend receives
nothing
| United States |
| Hostinger International Ltd | Cyprus | Application hosting — the virtual server the app runs on | United States |
| netcup GmbH | Germany | Database hosting — the PostgreSQL database holding everything in section 2 | United States |
| GitHub, Inc. | United States | Hosting of this website only — no app data reaches it | GitHub Pages global infrastructure |
| Cloudflare, Inc. | United States | The free store check on this website: runs the check against your public storefront files and stores the lead email only when you ask for the full report | Cloudflare's global network |
There is no analytics provider, no error-tracking SaaS, no advertising network and no CRM in this list. We will update this table before any new sub-processor starts processing, including when the email digest is switched on.
9. International transfers
Merchant data processed through the app is stored on servers located in the United States — the application server and the PostgreSQL database. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The query set sent to OpenAI and Perplexity, and any future email digest through Resend, also involve United States-based processors.
For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 10. The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere. What crosses the border is the store configuration, template state, validator results, query set, answers and excerpts, referral counts and orders, usage counters and access token described in section 2.
Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.
10. Security
- All traffic to the app and to this website is served over HTTPS/TLS. There is no plaintext endpoint.
- The database is not exposed to the public internet: it accepts PostgreSQL connections only from the application server, over password authentication (scram).
- Shopify access tokens are stored in that database and are never written to logs or shown in the UI.
- Administrative access to the server and the database is limited to the operator, over SSH with key authentication.
- Webhook requests from Shopify are verified by HMAC signature before anything is acted on.
-
The app requests the minimum Shopify scopes it needs:
read_products,read_themes,write_themes, and the Web Pixel. It requests noread_ordersscope and no protected customer data. -
The
/collectendpoint is rate-limited, and the IP address it sees is used only for that limit and is never stored.
We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.
11. Protected customer data
Capyo requests no Shopify protected customer data and no read_orders scope. It never
receives customer names, emails, phone numbers or addresses. A future feature that needed
protected customer data would only follow a separate Shopify approval and a change to this policy
before it started.
12. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (access, Art. 15);
- correct anything inaccurate (rectification, Art. 16);
- delete it (erasure, Art. 17);
- restrict what we do with it (Art. 18);
- hand it over in a machine-readable form, or send it to another provider (portability, Art. 20);
- stop processing based on legitimate interests (objection, Art. 21).
Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app starts the deletion described in section 7.
You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.
13. Changes to this policy
When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.
14. Contact
gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.