Capyo Capyo
es
Instalar en Shopify

Privacy Policy

Last updated: 2026-09-19

This policy explains what data the Shopify app Capyo: AI Visibility & GEO and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a data controller.

1. Who is responsible

The controller for the processing described here is Capyo, operated by an individual developer. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.

Operator legal name and address: [to be added]

For the personal data of your customers, you remain the controller and Shopify is your processor under Shopify's own terms. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses — see section 2 for exactly what it does read and store.

2. Data the app processes

It comes from Shopify when you install the app, from your storefront's Web Pixel, from the answers the engines return, and from you. In detail:

Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.

3. What the storefront pixel records

Capyo installs one Web Pixel extension through Shopify's own pixel API. It runs inside Shopify's strict sandbox: no DOM access, no third-party script and no advertising tags. It records AI referral visits and orders only; it is not a general analytics or advertising pixel. Its customer-privacy declaration is analytics on, marketing and preferences off, and whether it runs is governed by your store's privacy settings and Shopify's own consent handling.

The extension subscribes to two standard storefront events: page_viewed and checkout_completed. When a page view arrives with a referrer — or a utm_source — that matches a known AI assistant, the pixel stores an assistant label and a timestamp in localStorage under the key capyo_ai_ref for 7 days (first touch wins inside that window) and sends one small beacon to Capyo's own /collect endpoint. When a checkout completes with a valid stored reference, it sends a second beacon with the order id, value and currency. With no AI referrer, the pixel sends nothing at all.

The beacons carry a version marker, the shop domain, the kind (visit or order), the assistant label, the random per-visit id, the order id and value where relevant, and a timestamp. /collect accepts small JSON or plain-text bodies, rejects anything over 2 KB, answers 204 whether or not the input was valid, and is rate-limited. It stores no IP address, user agent, page URL, customer id or email; the request's IP address is used only to apply the rate limit and is never written to the database.

The llms.txt itself is plain Liquid rendered by Shopify from your own store data. It contains no URL of, call to, or dependency on Capyo.

4. What we never store

The query text and the engines' answers are about your products and your store, not about your customers, and the app requests no read_orders scope and no protected customer data.

Shopify sends every public app the two mandatory customer-privacy webhooks (customers/data_request and customers/redact). Capyo acknowledges them; because it holds no customer personal data, there is nothing to return.

5. This website

This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.

The free store check. The check box on the home page asks a Cloudflare Worker to read your store's public /llms.txt, /robots.txt and /agents.md and its storefront home page, and to show you what it found. If you ask for the full six-point report, we store the email address you enter and the store domain you checked, and use them to send that report and occasional product updates. That is the only personal data this website collects. It is processed by Cloudflare on our behalf, kept for up to 12 months, never sold, and deleted on request — email us and we remove it. Every report includes a one-click unsubscribe link. The check itself stores no IP address, and the Worker logs only the request path, status and duration.

6. Why we process it, and on what legal basis

We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.

7. How long we keep it

8. Who else is involved (sub-processors)

Sub-processorCompany countryWhat they doWhere the servers are
Shopify International Ltd Ireland The platform the app runs on and the source of all store data; also handles billing Per Shopify's own DPA
OpenAI United States Receives the app's query set and returns the answers and citations the report is built from — the app asks through the app's own OpenAI API key, on paid plans only, and no account or credential of yours is involved United States
Perplexity United States Receives the same query set through the app's own Perplexity search API key and returns the answers and citations the report is built from — paid plans only United States
Resend United States Weekly email digest to the merchant's own address, and only when email sending is enabled (EMAIL_ENABLED=on); until then no email code path runs and Resend receives nothing United States
Hostinger International Ltd Cyprus Application hosting — the virtual server the app runs on United States
netcup GmbH Germany Database hosting — the PostgreSQL database holding everything in section 2 United States
GitHub, Inc. United States Hosting of this website only — no app data reaches it GitHub Pages global infrastructure
Cloudflare, Inc. United States The free store check on this website: runs the check against your public storefront files and stores the lead email only when you ask for the full report Cloudflare's global network

There is no analytics provider, no error-tracking SaaS, no advertising network and no CRM in this list. We will update this table before any new sub-processor starts processing, including when the email digest is switched on.

9. International transfers

Merchant data processed through the app is stored on servers located in the United States — the application server and the PostgreSQL database. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The query set sent to OpenAI and Perplexity, and any future email digest through Resend, also involve United States-based processors.

For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 10. The app stores no end-customer personal data, so nothing about your shoppers is transferred anywhere. What crosses the border is the store configuration, template state, validator results, query set, answers and excerpts, referral counts and orders, usage counters and access token described in section 2.

Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.

10. Security

We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.

11. Protected customer data

Capyo requests no Shopify protected customer data and no read_orders scope. It never receives customer names, emails, phone numbers or addresses. A future feature that needed protected customer data would only follow a separate Shopify approval and a change to this policy before it started.

12. Your rights

Under the GDPR you can ask us to:

Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app starts the deletion described in section 7.

You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.

13. Changes to this policy

When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.

14. Contact

gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.