Privacy Policy
Effective August 6, 2026
Who We Are
ITGeeks Apps publishes AI Search & Product Filter, a Shopify app that powers search, filtering, merchandising, and product recommendations for online stores. This policy explains what data the app handles and why.
When a merchant installs the app, that merchant is the data controller for their shoppers’ personal data. We act as a processor on the merchant’s behalf and handle that data only to provide the app’s features. For data about the merchant and their account, we are the controller.
Questions about this policy or about your data: support@accounteditor.com.
Information We Collect From Merchants
When you install and use the app, we store:
- Your shop domain and basic store details supplied by Shopify at installation.
- Shopify access tokens and session records needed to call the Shopify API on your behalf.
- Your app configuration — search settings, filters, sorting options, synonyms, redirects, merchandising rules, and language preferences.
- Your plan, subscription state, and feature usage counters, used to apply plan limits and billing.
- Dashboard preferences, such as which reports you have pinned.
Information We Process About Shoppers
To make search and recommendations work, the app processes data about people who visit your storefront:
- Search queries typed into the storefront search box, along with result counts and whether the search returned nothing.
- Interaction and analytics events — searches performed, results clicked, filters applied, and products viewed.
- Recommendation state associated with a Shopify customer ID, so returning shoppers see relevant products.
We also mirror your product and collection catalog so the app can serve search and filtering quickly. Catalog data is store data, not shopper data.
We never receive or store payment card numbers, passwords, or full payment methods. Shopify handles payments; the app has no access to them.
Permissions We Request and Why
Shopify requires us to state what each requested permission is used for:
read_products,read_publications,read_markets,unauthenticated_read_product_listings— build and serve the search and filter index, and show the right products for each market and sales channel.read_customers,read_orders— generate personalized and complementary product recommendations.read_customer_events,write_pixels— measure search behavior and conversion for your analytics dashboards.read_files,write_files— save AI-generated banner images into your store’s Files so you can use them in your theme.
How We Use Information
We use the data described above only to operate the app:
- Ranking search results and powering autocomplete and search suggestions.
- Building filters and sorting options for collection and search pages.
- Applying merchandising rules, synonyms, and search redirects you configure.
- Producing product recommendations.
- Generating the reports and dashboards you see inside the app.
- Providing support, preventing abuse, and meeting legal obligations.
We do not use this data for advertising, and we never combine one merchant’s data with another merchant’s. Each store’s data is kept separate.
AI Processing
Some features use AI. When you use them, we send search queries, product metadata, and prompts you write to third-party AI providers in order to generate synonyms, filter suggestions, query classifications, and banner imagery.
This data is not used by us or by those providers to train AI models. No shopper payment data is ever sent to an AI provider.
Sub-Processors
We rely on the following service providers to run the app:
- Shopify Inc. — the platform and source of record for store data.
- Fly.io — application hosting and database, located in the United States.
- Groq, Inc. — text and structured data generation for AI features.
- Amazon Web Services, Inc. (Amazon Bedrock) — image generation for AI banners.
- deAPI — image generation for AI banners.
Data Retention and Deletion
We keep your data for as long as the app is installed. Uninstalling the app deletes the stored session records for your shop.
We implement Shopify’s three mandatory compliance webhooks:
- Customer data request — we receive the request and route it to the merchant, who responds to the shopper as the data controller.
- Customer redact — we delete that shopper’s stored recommendation data.
- Shop redact — we delete the shop’s recommendation and analytics data.
Shopify sends shop redaction requests 48 hours after uninstall, and we act on redaction requests within the 30-day window Shopify allows.
Your Rights
If you are in the European Economic Area, the United Kingdom, or Switzerland, the GDPR and UK GDPR give you the right to access your personal data, correct it, have it erased, receive it in a portable format, restrict or object to its processing, and lodge a complaint with your local supervisory authority.
If you are a California resident, the CCPA and CPRA give you the right to know what personal information is collected, to have it deleted, to have it corrected, and to opt out of its sale or sharing.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
If you are a shopper, contact the store you shopped at — that merchant controls your data and can action your request. If you contact us directly, we will forward your request to the relevant merchant and assist them in responding. Merchants can reach us at support@accounteditor.com.
Security
Data is encrypted in transit using TLS. Shopify access tokens are scoped to only the permissions listed above, credentials are held in environment configuration rather than in source code, and access to production systems is limited to personnel who need it.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.
International Data Transfers
The app is hosted in the United States, and data is processed and stored there. If you are located in the European Economic Area, the United Kingdom, or Switzerland, your data is transferred outside your region. We rely on Standard Contractual Clauses or another lawful transfer mechanism for those transfers.
Children’s Privacy
The app is built for merchants and is not directed to children. We do not knowingly collect personal data from anyone under 16. If we learn we have collected such data, we delete it.
Changes to This Policy
We may update this policy as the app changes. Material changes will be published on this page with a new effective date. Continuing to use the app after that date means you accept the updated policy.
Contact Us
ITGeeks Apps
support@accounteditor.com
We respond to privacy requests within 30 days.