Privacy Policy
Last updated: 2026-08-24
This policy explains what Prudix collects across all of our apps, why we collect it, where it goes, and how long we keep it. Where a specific app has practices beyond what's described here, those are called out in a dedicated section below.
1. Who we are
Prudix ("we", "us", "our") publishes focused Shopify apps at prudix.app. You can reach us at support@prudix.app.
2. What we collect
All apps
Every Prudix app installed on your Shopify store collects:
- Shop identity — your
myshopify.comdomain and a Shopify-issued access token (Fernet-encrypted at rest) - Merchant contact email — your shop's primary contact email, fetched at install and used for account communications and digest emails. This is your business email, never a shopper's email.
- Billing state — plan tier, status (active / trial / cancelled), and Shopify billing events
- Usage logs — which features you use, which AI model was selected, actions consumed, token counts, and cost (USD)
Prudix Commerce (additional)
- Product catalog — titles, descriptions, vendor, images, metafields under our
prudix_*namespaces, inventory levels, prices - Reviews — review text and ratings from your Judge.me or Shopify Reviews integration
- Order line items, return reasons, checkout events — used for Sales Leak Finder, Customer Retention Operator, and Inventory & Cash Flow Operator analytics. Shopify scrubs PII (name, email, phone, address) from these webhook payloads before delivery; we never re-fetch the scrubbed fields.
- Customer first names (Customer Retention Operator only) — live-fetched, never stored. Used to display cohort dashboards and personalize merchant-side retention copy.
- Shopper questions (AI Concierge only) — typed product questions from the PDP widget. Stored for 30 days under an opaque
session_hashnot tied to any Shopify customer record. - Generated outputs — ad copy, FAQs, descriptions, Content Kits, AI Concierge answers we produced for you
3. What we don't collect
- Your customers' names, emails, phone numbers, or addresses (except the single first-name carve-out noted above for Prudix Commerce)
- Payment card information — Shopify handles all billing directly under their App Billing API
- Persistent shopper profiles or cross-session behavioral tracking — shopper questions (Prudix Commerce AI Concierge) are stored for 30 days under an opaque session identifier as disclosed in Section 2, but we do not build persistent shopper profiles, track behaviour across sessions, or link questions to any Shopify customer record
- Anything used to train AI models — see Section 5
- Analytics cookies, session replays, or heatmaps on our merchant dashboards — we do not run Microsoft Clarity, Google Analytics, Hotjar, FullStory, or any similar tool
4. How we use it
We process the data above for two purposes only:
- Delivering the service — computing analytics, generating AI content, and surfacing results in your dashboard and digest emails
- Account communications — billing notifications, digest emails, and support responses
We do not sell your data, share it with third parties for their own purposes, or use it to advertise to you.
5. Third-party processors
The following processors handle data on our behalf:
- OpenAI and Anthropic — we send selected prompts (including your product, review, and order metadata) to their APIs to generate content. Both providers commit not to train on API data by default.
- Supabase — hosts our PostgreSQL database in the US (Ohio region) with AES-256 encryption at rest and automated encrypted backups. EU-located merchants: this constitutes an international data transfer governed by Standard Contractual Clauses per our Data Processing Addendum (available on request).
- Railway — hosts our application servers
- Postmark — sends digest emails and account notifications; also processes bounce and spam-complaint webhooks to maintain our suppression list
- Sentry — receives application error events for observability; sensitive headers (Shopify access tokens, cookies, OAuth codes, database URLs) are scrubbed by our before-send hook before any event leaves our server
Optional merchant-connected integrations: if you connect your own Klaviyo account, we push AI-generated content (not customer lists) into your Klaviyo workspace. Your Klaviyo account's data handling is governed by Klaviyo's own privacy policy.
6. Data retention
- Your data is retained while your subscription is active
- AI Concierge shopper questions (Prudix Commerce) are retained for 30 days, then auto-purged
- When you uninstall, your Shopify access token is revoked immediately and a 30-day retention window begins
- At the end of the 30-day window, all your shop data is permanently deleted from our database
- On a Shopify
shop/redactwebhook, we purge immediately rather than waiting 30 days
7. GDPR / CCPA rights
We support all three Shopify-mandated GDPR webhooks
(customers/data_request, customers/redact,
shop/redact) wired to real handlers — not stubs. You
can request data export, deletion, or any other rights request by
emailing support@prudix.app;
we respond within Shopify's mandated window.
8. Security
- Shopify access tokens encrypted at rest using Fernet symmetric encryption
- Database encrypted at rest via Supabase AES-256 (managed)
- All HTTP traffic over TLS
- Internal admin behind HTTP Basic Auth with a strong random password
- Application-level access scoped per shop — no cross-shop data leakage
- Documented incident-response flow: identify → contain → purge via
shop/redact→ notify Shopify and affected merchants → remediate
9. Changes
We'll update this page when our practices change. Material changes will be communicated to active merchants by email at least 14 days before they take effect.
10. Contact
Privacy questions: support@prudix.app.