Preferd← Back to home
Legal

Privacy Policy

Last updated: July 17, 2026

This policy explains what data Preferd (“we”, “us”) collects when you install and use the app, how we use it, who we share it with, and your rights. We only collect what we need to score and optimize your catalog. We never sell your data.

Who we are

Preferd is a Shopify app operated by Preferd. You can reach us about privacy at [email protected].

What we store

When you install Preferd you authorize it (via Shopify OAuth) to read and write your products. We request the minimum scopes needed (read_products, write_products). We store:

  • Your Shopify store domain and the app access token in server-side session storage. Access is restricted to the service and the token is never sent to the browser.
  • Product data we read to score and optimize: titles, descriptions, tags, image alt text, SEO metadata, product type/category, vendor/brand, GTIN/barcodes and metafields.
  • Computed GEO scores, the optimizations you generate and apply, and before/after snapshots used for the lift and one-click revert.
  • Your subscription plan and usage counters (to enforce plan limits).
  • AI-visibility check results and the competitors you choose to track.
  • AI-traffic events: when a storefront visit or checkout conversion is attributed to an AI assistant (e.g. ChatGPT, Perplexity, Gemini), we record an opaque event ID, the AI source, event type, landing-page path, timestamp and, for conversions, value and currency. The application payload contains no customer identifier, order identifier, contact details or payment details. Raw events are pruned after 90 days; daily aggregate visits, conversions and revenue are retained to show your AI-traffic trend.
  • For the optional monthly report email (paid plans): your store's contact email address as provided by Shopify, your email preference, and when the last report was sent. Deleted with the rest of your data when you uninstall.

We do not use Shopify's Customer or Orders APIs, and we do not store customer records, order records, order IDs, contact details or payment details. The storefront pixel processes de-identified visit and conversion events as described above; it receives no customer or order identifier in its event payload. We do not place non-essential cookies or trackers beyond what Shopify's embedded-app framework requires to keep you signed in.

How we use your data

  • To compute a deterministic GEO score for each product and show you what to improve.
  • To generate AI content suggestions when you request an optimization, and to apply them to your store when you approve.
  • To measure whether AI assistants recommend your store (AI-visibility checks) and to compare you against your sector.
  • To report aggregate visits, conversions and revenue attributed to AI assistants when the storefront pixel is active.
  • To enforce your plan’s limits and process billing via Shopify.
  • To provide support and keep the service secure and reliable.

We do not use your data to train AI models, and we do not sell, rent or share it for advertising.

Who we share it with (subprocessors)

We rely on a small number of trusted providers to run Preferd. Each only receives the data needed for its function:

  • Shopify

    Hosts your store, authorizes the app (OAuth), provides the product data we read/write, and processes all billing.

    Data shared: Store domain, app session, billing status.

  • Railway

    Application hosting and our PostgreSQL database (data at rest).

    Data shared: All data the app stores about your store (see “What we store”).

  • OpenAI

    Generates AI content suggestions when you request an optimization (server-side only, on demand, via an OpenAI-compatible API).

    Data shared: The catalog fields needed to generate the suggestion (including title, description, tags, image metadata, SEO metadata, vendor and relevant metafields).

  • Perplexity

    Powers AI-visibility checks — queries an AI assistant to see whether your store is recommended.

    Data shared: Your store/brand name, product category and the buyer-style search queries used for the check.

  • Resend

    Delivers the optional monthly Impact-Report email (paid plans; you can opt out anytime in-app or via the unsubscribe link).

    Data shared: Your store's contact email address and the aggregate report metrics in the email (scores, optimization counts, AI-traffic totals). Nothing is shared if the email is disabled.

We may also disclose data if required by law, or to protect our rights and the safety of users.

Data retention & deletion

We keep your data only while the app is installed. When you uninstall Preferd, we permanently delete your store’s data (cascade delete of all records tied to your shop), and we honor Shopify’s mandatory GDPR webhooks:

  • customers/data_request — we hold no customer personal data, so there is nothing to return.
  • customers/redact — no customer data is stored to redact.
  • shop/redact — we erase all data associated with your store.

Cookies & website tracking

The public website sets no cookies and loads no third-party trackers or external font CDNs; custom fonts on public pages are self-hosted on our own domain. The embedded app uses only the strictly-necessary session mechanisms Shopify requires to keep you signed in. Full detail in our Cookie Policy.

Processing on your behalf (DPA)

For the store data we process on your behalf, you are the controller and we are the processor. The GDPR Article 28 terms — including the authorized subprocessors and deletion guarantees — are in our Data Processing Addendum, which forms part of our Terms.

Security

Data is transmitted over HTTPS and stored in a managed PostgreSQL database. The Shopify access token is stored in server-side session storage, and access tokens and API keys are never exposed to the browser. All calls to Shopify and third-party AI providers happen server-side. We apply least-privilege scopes and server-side checks on every action.

Your rights

Depending on your location (e.g. the EU/EEA under GDPR), you may have the right to access, correct, export or delete your data, and to object to certain processing. You can exercise these rights at any time by uninstalling the app (which deletes your data) or by contacting us at [email protected].

International transfers

Our providers may process data in countries outside your own. Where required, transfers rely on appropriate safeguards such as the providers’ Standard Contractual Clauses.

Changes to this policy

We may update this policy as the app evolves. We will revise the “Last updated” date above and, for material changes, notify you in-app. Continued use after changes means you accept the updated policy.