Effective date: July 28, 2026
This Privacy Policy explains how SkuWatch AI Visibility, operated under the
SkuWatch brand (“SkuWatch AI Visibility,” “SkuWatch,” “we,” “us,” or “our”),
collects, uses, discloses, and deletes information through the SkuWatch AI
Visibility Shopify app, visibility.skuwatch.app, app.skuwatch.app, and
related services that link to this policy (collectively, the “Services”).
SkuWatch AI Visibility is designed for Shopify merchants. It does not require access to customer, order, Shopify POS, payment-card, or checkout data.
When you request a public storefront scan, we process the email address and store URL you submit, request metadata used for abuse prevention, and the resulting diagnostic findings. Cloudflare Turnstile processes verification data to distinguish legitimate requests from automated abuse. We use the email to associate and follow up on the requested scan; no Shopify login, theme access, or customer data is required.
1. Information we collect
Shopify account and installation information
When a merchant installs or uses the app, we receive information needed to authenticate the installation and associate data with the correct store. This may include:
- the store’s
myshopify.comdomain, primary storefront domain, store name, installation status, and granted access scopes; - Shopify session and access-token records required to make authorized API requests;
- app-plan, billing-cycle, subscription-status, and included-usage information supplied through Shopify App Pricing; and
- installation, uninstallation, permission-change, and privacy-compliance webhook records.
Shopify processes plan charges and payment details. We do not receive or store merchant payment-card numbers.
Product and catalog information
With the required read_products permission, we may process product information
such as:
- product titles, descriptions, handles, vendors, product types, status, tags, collections, images, and image alternative text;
- variant names and options, SKUs, barcodes, prices, availability, and product update times; and
- product URLs and other catalog facts needed for audits, recommendations, monitoring prompts, and change verification.
If a merchant chooses Apply to Shopify, the app requests the optional
write_products permission. We use that permission only to write the specific
merchant-reviewed product change. We retain the relevant Before/After draft,
backup, confirmation status, and Undo history so the merchant can inspect and,
where supported, reverse the change.
We do not request Shopify customer or order scopes and do not use Shopify customer records, order records, checkout data, or Shopify POS data.
Merchant-provided information
We collect information a merchant enters or confirms in the app, including:
- brand name, product category, markets, languages, positioning, and audience context;
- buyer questions, prompt selections, monitoring schedules, and product notes;
- competitor domains and decisions such as Track, Not relevant, Retailer, Marketplace, Publisher, or Same brand;
- edits to a proposed product change and confirmation to apply or undo it; and
- support messages, business email address, screenshots, and other information voluntarily sent to us.
Do not send passwords, Shopify access tokens, AI API keys, payment-card information, customer records, health data, or other sensitive information through support or general contact channels.
Public storefront and web evidence
Store scans and competitor research may collect information available without authentication on public websites, including:
- storefront and product-page URLs, page content, response status, canonical URLs, redirects, and timestamps;
- robots directives, sitemap entries, structured data, product descriptions, and public catalog facts;
- public competitor, retailer, marketplace, publisher, and citation domains; and
- scan findings, evidence excerpts, confidence labels, and verification results.
Public scans do not intentionally bypass passwords, access controls, paywalls, or other technical restrictions.
AI Visibility and generated-content records
When a merchant runs or schedules an AI Visibility check, or requests a product improvement, we may process and retain:
- the buyer question, prompt version, market, language, target category, relevant store or product context, and requested providers;
- provider status, model identifier when available, timestamps, retries, token usage, and diagnostic information;
- raw provider answers, source URLs, citations, identified brands, stores, products, competitors, and matching evidence; and
- generated product suggestions, quality-check results, merchant edits, and verification outcomes.
These records support the Answer Archive, comparison over time, provider-failure exclusion, competitor analysis, and Fix-to-Impact history.
Website, comments, and technical information
Our hosting and security systems may process IP address, browser and device type, requested URL, timestamps, response status, and diagnostic or security events. If you use an article discussion, CommentBox.io may process login or profile information, public comments, replies, votes, flags, and interaction data. Comments and displayed profile details are public.
2. How we use information
We use information to:
- install, authenticate, operate, and secure the Services;
- audit products and public crawler access;
- create merchant-relevant buyer questions and run AI Visibility monitoring;
- retain raw answers, citations, competitor evidence, and change history;
- prepare, preview, apply, verify, back up, and undo authorized product changes;
- enforce package allowances and verify Shopify subscription status;
- diagnose provider or application failures and prevent abuse;
- respond to support and privacy requests;
- improve matching, scoring, quality checks, and merchant experience;
- create aggregate or de-identified operational insights; and
- comply with applicable law and enforce our agreements.
We do not use merchant data to create fake reviews, false sales activity, or guaranteed AI-ranking claims.
3. Shopify permissions and merchant control
The app requests read_products as its required Shopify scope. Product writing
is optional. The app requests write_products in context only after a merchant
chooses an action that requires it. A merchant can review the proposed change
before confirming the write.
The app uses a Theme App Extension for its optional storefront integration. It
does not request write_themes and does not directly edit theme assets.
Merchants can remove optional product-writing access through Shopify, uninstall the app, or contact us to request deletion. Revoking a permission may disable the related feature without deleting evidence already needed for audit, security, or change history.
4. AI service providers
SkuWatch AI Visibility uses API services provided by OpenAI, Perplexity, Google Gemini, and Anthropic. Depending on the action, we send only the information reasonably needed to produce the requested result. This can include a buyer question, store or brand name, public domains, market and language, and relevant product or catalog facts.
These providers process information under their own contracts, privacy terms, and API data controls. Do not place customer personal information or confidential information in buyer questions, product notes, or prompts.
AI answers and generated suggestions can be incomplete or inaccurate. We retain the provider evidence and label unavailable results instead of treating them as a negative merchant result.
5. How we disclose information
We do not sell personal information or use merchant information for cross-context behavioral advertising.
We disclose limited information when necessary to:
- Shopify, for app installation, API access, managed pricing, subscription verification, and platform compliance;
- OpenAI, Perplexity, Google Gemini, and Anthropic, for merchant-requested AI Visibility checks and generated product suggestions;
- Cloudflare, for website delivery, TLS, network routing, availability, and security;
- CommentBox.io, when a visitor loads or uses public article discussions;
- application hosting, MongoDB-backed storage, monitoring, and support infrastructure used to operate the Services;
- professional advisers, auditors, or service providers bound to appropriate confidentiality obligations;
- a successor in a merger, financing, acquisition, reorganization, or sale of relevant assets, subject to applicable law; or
- authorities or other parties when reasonably necessary to comply with law, protect rights and security, or investigate abuse.
6. Cookies and similar technologies
The marketing site does not currently use first-party advertising or behavioral-analytics cookies. Infrastructure providers may use standard request information for delivery, reliability, and security.
Loading or using a CommentBox.io discussion connects the browser to CommentBox.io. If we add non-essential analytics, advertising, or similar tracking, we will update this policy and provide consent controls where required.
The embedded Shopify app uses Shopify authentication and session mechanisms needed to operate inside Shopify Admin.
7. Retention and deletion
While the app remains installed, we retain shop-scoped information as needed to provide the merchant’s package, Answer Archive, catalog audits, backups, Undo, change history, security, and support. The amount of history visible in the app depends on the current package and does not necessarily represent a separate physical copy of the data.
When we receive a verified app/uninstalled or shop/redact webhook, the app
deletes Shopify sessions and shop-scoped application records, including scans,
prompts, answers, citations, competitor selections, product drafts and backups,
change events, usage records, and badge history.
We may retain limited security logs, support correspondence, records needed to resolve disputes or meet legal obligations, and aggregate or de-identified data that no longer identifies a merchant or individual. Those records are retained only as long as reasonably necessary for the relevant purpose.
8. International processing
The Services and their providers may process information in Canada, the United States, and other countries. Privacy protections in those countries may differ from those in your location. Where required, we rely on appropriate contractual or legal safeguards for international transfers.
9. Legal bases
Where a law requires a legal basis, we process information:
- to provide Services requested under our contract with the merchant;
- for legitimate interests in operating, securing, documenting, and improving the Services;
- with consent where we request it; and
- to comply with legal obligations.
10. Your rights and choices
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent. You can also:
- edit merchant-provided context and monitoring prompts in the app;
- revoke optional Shopify permissions;
- uninstall the app through Shopify Admin; and
- request access or deletion by emailing us with the subject
Privacy request.
We may need to verify the requester’s identity and authority over the relevant store. We will not discriminate against a person for exercising a privacy right provided by applicable law.
11. Security
We use reasonable administrative and technical safeguards appropriate to the information handled, including HTTPS, Shopify-authenticated requests, shop-scoped data access, protected production configuration, and signed webhook verification. No internet service is completely secure, and we cannot guarantee absolute security.
12. Children
The Services are business tools and are not directed to children under 16. We do not knowingly collect personal information from children.
13. Third-party links
The Services link to Shopify, AI providers, public storefronts, competitors, and other third-party websites. Their privacy practices are governed by their own policies.
14. Changes to this policy
We may update this policy when the Services, providers, or legal requirements change. We will revise the effective date and provide additional notice where required for a material change.
Contact
Privacy questions or requests can be sent to
[email protected] with the subject
Privacy request.