ShelfSight · Privacy Policy

Privacy Policy

Effective September 28, 2026

Who we are

ShelfSight is a Shopify app that shows merchants where their products appear in AI shopping answers (ChatGPT, Perplexity, Gemini, Claude, Google AI Overviews). This policy describes what data the app touches and why.

ShelfSight is operated by Francesco Donnini (ABN 79 186 451 498), a sole trader based in Australia.

Data we collect

Store data. Our required permission is read and write access to products. We read your product catalog (titles, descriptions, prices, images, status) to audit your product data and suggest prompts, and we store your shop domain, your chosen prompts, and named competitors. We change a product field only after you confirm the change in the app.

Store contact. We read your store’s name and contact email address from Shopify, so the app’s reports reach you.

Scan results. We store the answers AI engines return for your prompts, including the sources they cite, so we can show stability over time. These answers come from the engines, not from your store.

Support conversations. Messages you send through the in-app support page are stored so we can answer them and improve our answers.

Order sources (optional, off by default). If you turn on “Orders AI assistants sent you”, you grant Shopify’s optional order permission and we read your orders from the last 60 days. For each order we keep only its ID, its date, which AI assistant (if any) sent the visit before it, and the website or tag that named the assistant. We delete these rows after 60 days, when you turn the feature off, and on redaction requests.

The free report on this website. When you run the free AI visibility report, we fetch the store’s public product feed, log the store domain you enter with the time of the check, and keep the result (with any competitor domain you added) in a short-lived cache for about 6 hours. We use your IP address only to rate-limit requests: it sits in a counter that expires within an hour and is never stored with the report.

Customer personal information: none. ShelfSight does not request, read, or store your customers’ names, emails, phone numbers, addresses or order contents. Beyond products, order reading is optional and stays off until you turn it on.

How we use it

Solely to operate the service: scanning, scoring, feed auditing, reports, and support. Aggregated, anonymized statistics (for example, “X% of scanned stores are invisible on budget-capped prompts”) may appear in our published content; they never identify a store.

Email

ShelfSight reads your store’s contact email from Shopify. We send automatic emails (the weekly report and drop alerts on paid plans, and a note from the founder) only after you turn email on in the app, and every one has an unsubscribe link. You can turn email off at any time on the app’s Support page. Emails you ask for, such as “Email me this report” or a reply to a support question, go to that same address.

Third parties

Your tracked prompts are sent to AI engine APIs (OpenAI, Perplexity, Google, Anthropic, and SerpAPI) to retrieve the answers we analyze. Anthropic also receives your store name and up to 20 product titles, types and brands to draft buying questions for you; your scan results, the catalog facts they were checked against (product names, prices, stock), your top feed audit findings and the names of competitors you track, to write your weekly report; and any support message you send us, to draft a reply. Orders and customer data are never sent to an AI API. Reports, digests and notices to us (for example a customer’s data request) are delivered by Resend (email). The app is hosted on Fly.io with data stored in Postgres. We do not sell data to anyone.

Data deletion

Uninstalling the app ends our access to your store at once. About 48 hours after you uninstall, Shopify sends the shop/redact webhook, and on it we erase every stored row for your shop: prompts, competitors, scan results, order sources, reports, and profile. You can also email us for immediate deletion.

GDPR & compliance webhooks

We subscribe to all three mandatory Shopify compliance webhooks (customers/data_request, customers/redact, shop/redact). We hold no customer personal data. If order sources are on, customers/redact deletes the rows for that customer’s orders and customers/data_request sends you the rows we hold for the requested orders; shop redaction deletes everything.

Contact

Questions or deletion requests: support@getshelfsight.com.