RecoMind

Privacy Policy

Effective date: 29 September 2026 · Last updated: 29 September 2026

1. Who we are and scope

RecoMind ("RecoMind", "we", "us" or "our") is a Shopify application operated by [LEGAL ENTITY NAME], located at [FULL LEGAL ADDRESS, CITY, STATE, PIN, INDIA]. This Privacy Policy explains how we collect, access, use, store, disclose, transfer, secure and delete information when Shopify merchants and their authorised users install or use RecoMind and related services (the "Services").

When a Shopify merchant uses RecoMind to process information relating to its customers, the merchant generally determines the purposes of that processing and RecoMind processes information to provide the Services, subject to Shopify requirements, this Policy and applicable law.

2. Information we may process

Shop and account information. We may process shop domain, shop name, owner/contact information, store currency, timezone, Markets configuration, plan/subscription information, installation status, granted API scopes and billing identifiers.

Authentication and session information. We may process Shopify session identifiers, authorised user identifiers, name, email, locale, collaborator/account-owner status, authentication state, access or refresh credentials/tokens, token expiry information and granted permissions where Shopify makes these available and where required to authenticate the Services.

Product and catalogue information. We may process product IDs, titles, descriptions, HTML descriptions, variants, images, product type, vendor/brand, handles, tags, collections, categories, metafields, pricing/availability information where required, FAQs, and product timestamps.

Order, reporting and analytics information. Where the merchant grants the relevant Shopify permissions, RecoMind may access order, revenue, conversion, traffic and reporting information to provide analytics and impact-measurement features. Our current application database does not maintain a dedicated customer or order-personal-data collection.

RecoMind-generated information. This can include analysis scores, AI-readiness analysis, prompts, keyword and intent clusters, optimised titles/descriptions, FAQs, competitor benchmarks, visibility measurements, optimisation history, job status, reports, usage/token information and audit records.

Merchant-provided information. Merchants may provide prompts, competitor URLs, FAQs, product information, configuration choices, feedback, support communications and other content.

Technical/security information. We may process request timestamps, application events, webhook events, authentication events, logs, error information, browser/device information where generated, IP address where generated by infrastructure, and security events required to operate, secure and troubleshoot the Services.

3. How we obtain information

  • From Shopify through authorised APIs, authentication flows and webhooks.
  • Directly from merchants and authorised users.
  • Automatically through use of RecoMind and our hosting/security infrastructure.
  • From public webpages or merchant-selected competitor URLs when a requested feature requires analysis.
  • From service providers acting on our behalf.

4. How we use information

  • Authenticate merchants and authorised users and connect RecoMind to Shopify.
  • Synchronise selected products and provide catalogue analysis.
  • Generate AI-assisted product, FAQ, prompt, SEO/AEO/GEO and visibility recommendations.
  • Provide competitor, conversion, order, revenue and performance analysis where authorised.
  • Manage plans, billing, usage limits and token quotas.
  • Maintain service reliability, audit history, troubleshooting, abuse prevention and security.
  • Respond to data-rights requests and comply with legal, contractual and Shopify obligations.
  • Improve the functionality and reliability of RecoMind using information we are lawfully permitted to use for that purpose.

5. Artificial intelligence processing

RecoMind uses artificial-intelligence technologies to provide certain features. Product information, merchant-supplied content, prompts and contextual information necessary to provide a requested AI feature may be transmitted to AI service providers, including OpenAI, for processing. AI-generated results may be stored in RecoMind as part of product analysis, recommendations, optimisation history or related functionality.

Merchants should not intentionally submit passwords, card information, government identifiers, medical information or other unnecessary sensitive personal information into RecoMind prompts or fields. AI outputs can be inaccurate or incomplete, and merchants are responsible for reviewing output before publication or reliance.

6. Shopify permissions and protected customer data

RecoMind requests Shopify API permissions required for enabled functionality. Depending on the deployed configuration, these may include product, theme, report, order and Shopify Markets permissions. The exact scopes are shown by Shopify during installation or permission changes.

Order resources can constitute Shopify Protected Customer Data. Where RecoMind receives such access, we restrict processing to authorised functionality, do not sell the data, do not use it for unrelated advertising, apply access controls and honour Shopify privacy/redaction requirements.

7. Shopify mandatory privacy requests

Customer data request (`customers/data_request`). We authenticate Shopify's webhook request and identify responsive data, if any, held by RecoMind for the specified customer/order resources. If RecoMind holds no customer-level data, the request is acknowledged with no responsive customer record.

Customer redaction (`customers/redact`). We authenticate the request and delete or anonymise responsive customer information held by RecoMind, if any, unless retention is legally required.

Shop redaction (`shop/redact`). After Shopify sends a shop-redaction request, we delete/anonymise store-scoped RecoMind data, sessions and credentials unless specific information must be retained by law. Any legally retained information is restricted to that legal purpose and deleted when the retention requirement ends.

8. Legal bases and India data-protection compliance

Depending on the jurisdiction and context, we may process information to perform our agreement with a merchant, follow merchant instructions, comply with law, obtain consent where required, or rely on another lawful basis recognised by applicable law.

Where applicable, RecoMind intends to process digital personal data consistently with India's Digital Personal Data Protection Act, 2023 and applicable rules as their provisions become effective. Individuals may exercise applicable rights through the contact information below.

9. Service providers and disclosures

We may disclose information only where reasonably necessary to operate, secure, support or comply with obligations relating to RecoMind. Categories may include:

  • Shopify — platform integration, authentication, APIs, webhooks and billing.
  • OpenAI and other approved AI providers — requested AI-powered processing.
  • MongoDB/database infrastructure — application data storage.
  • Redis/cache infrastructure — caching, reliability and technical processing where enabled.
  • Render — application hosting where used by the production deployment.
  • Monitoring, logging, backup, email/support and security vendors actually enabled in production.
  • Professional advisers and authorities where lawfully required.

We do not sell merchant or customer personal information.

10. International transfers

Service providers may process information outside the merchant's or individual's country. Where applicable law requires transfer safeguards, we use or require appropriate contractual or other legally recognised safeguards. Merchants remain responsible for any disclosures or agreements required between the merchant and its own customers.

11. Data retention

We retain information only for as long as reasonably necessary to provide the Services, maintain account/billing records, protect security, resolve disputes, enforce agreements, comply with tax/accounting/legal obligations and handle valid privacy requests.

After uninstall, information is deleted or anonymised through Shopify's privacy-compliance process, subject to lawful retention exceptions. Backup copies may persist for a limited period until overwritten through normal backup rotation.

12. Security

We use administrative, organisational and technical safeguards appropriate to the information processed. Measures may include Shopify authentication, webhook HMAC verification through Shopify's authentication library, HTTPS/TLS, restricted infrastructure access, secret/environment management, database access controls, logging/monitoring, dependency management, backups, incident-response procedures and least-privilege permissions.

No internet-based service can guarantee absolute security. Merchants are responsible for securing their Shopify administrator accounts, limiting staff access, removing former users and avoiding unnecessary sensitive data in RecoMind.

13. Cookies and similar technology

RecoMind may use necessary browser storage, cookies, Shopify session mechanisms or similar technologies for authentication, security, application state and core operation. If non-essential analytics or advertising technology is introduced, we will update our disclosures and implement consent controls where legally required.

14. Children

RecoMind is a business service intended for merchants and authorised business users and is not directed to children. Merchants should not intentionally provide children's personal data through RecoMind unless they have a lawful basis and comply with applicable requirements.

15. Privacy rights and grievance contact

Depending on applicable law, individuals may have rights of access, information, correction, updating, deletion/erasure, consent withdrawal, grievance redressal and other rights provided by law. Requests should include enough information to identify the relevant merchant/store and verify the requester.

If your request relates to a Shopify merchant's customer relationship, contact the merchant first where appropriate. We will cooperate with Shopify and merchants as required.

Privacy/Grievance contact: [PRIVACY EMAIL]

Security reports: [SECURITY EMAIL]

Address: [FULL LEGAL ADDRESS, CITY, STATE, PIN, INDIA]

16. Business transfers and legal requests

If RecoMind or its operating business undergoes a merger, acquisition, restructuring, financing or sale of assets, information may be transferred subject to applicable law and appropriate confidentiality obligations. We may preserve or disclose information where required by valid legal process, to investigate fraud/security incidents, to protect rights and safety, or to establish, exercise or defend legal claims.

17. Changes to this Policy

We may update this Privacy Policy when our Services, infrastructure or legal requirements change. The revised version will display a new “Last updated” date. Where law requires additional notice or consent for a material change, we will take the required steps before the relevant processing occurs.

18. Contact us

RecoMind

Operated by: [LEGAL ENTITY NAME]

Address: [FULL LEGAL ADDRESS, CITY, STATE, PIN, INDIA]

Privacy: [PRIVACY EMAIL]

Support: [SUPPORT EMAIL]

Website: https://www.getrecomind.com