Legal · Shopify App

Agent Privacy Policy

This policy covers RankCrawler Agent, our Shopify app and storefront chat widget. Our SEO platform has a separate policy.

Last updated: August 27, 2026

01Who This Covers

RankCrawler Agent is operated by RankCrawler ("we", "our", or "us"). This policy explains what we collect from two groups of people:

  • Merchants — Shopify store owners and staff who install the app and use the dashboard at agent.rankcrawler.com
  • Shoppers — visitors to a merchant's storefront who open the chat widget and send it a message

For shopper data, the merchant is the data controller and we act as their processor. For merchant account data, we are the controller.

02Store Data We Collect

When you install the app, we read published content from your Shopify store through the Admin API and index it so the agent can answer questions from it. Nothing here is written back to your store.

WhatWhy we need it
Store domain & nameIdentifies your installation and scopes every query to your store alone
Contact emailCreates your dashboard login and lets us reach you about the service
Products & collectionsTitles, descriptions and variants, so the agent can recommend and compare
Pages & blog articlesPublished long-form content the agent can answer from
Store policiesRefund, shipping, terms and privacy pages
Access & refresh tokensAuthorises our read requests to your store; encrypted at rest
Plan & usage countersEnforces your plan limits and shows usage in your dashboard

What we never receive: customer records, order history, checkout data, or payment details. We do not request those permissions, so Shopify will not release them to us. Subscription payments run through the Shopify Billing API, which means card numbers never reach our servers.

03Permissions We Request

Every scope we ask for is read-only:

  • read_products — products, variants and collections
  • read_content — pages and blog articles
  • read_themes — lets the widget be placed through your theme editor
  • read_legal_policies — your published store policies

We request no write scopes. The app cannot edit products, change your theme, create orders, or modify anything in your store.

04Shopper Data

When a visitor opens the chat widget on a merchant's storefront, we process the following on that merchant's behalf:

WhatWhy we need it
Messages sentGenerates a reply, and shows the merchant which questions went unanswered
Conversation transcriptKeeps context so follow-up questions make sense
Anonymous visitor IDA random identifier stored in the browser; groups messages into one conversation
Product clicksTells the merchant which recommendations shoppers actually followed

The visitor ID is randomly generated and is not linked to a Shopify customer account, an email address, or any profile. We do not use it to track visitors across other websites, and we do not build advertising profiles.

Shoppers should not send sensitive information — card numbers, passwords, government IDs or health details — into the chat. The agent does not ask for them and has no use for them. Merchants: link this policy from your own privacy page so your visitors know the widget is there.

05How AI Processing Works

The agent uses OpenAI's API in two ways. When your store is indexed, the text of your products, pages, articles and policies is converted into numerical embeddings so it can be searched by meaning. When a shopper asks a question, that question and the most relevant passages from your content are sent to a language model, which writes the reply.

This means shopper messages and your published store content are transmitted to OpenAI as part of normal operation. OpenAI does not use data submitted through its API to train its models. We do not use your content or shopper conversations to train any model of our own.

The agent answers from the passages it retrieved. When it can't find a relevant one, it says so rather than guessing, and the question is logged for the merchant to review.

06Who Else Processes Data

We do not sell, rent or trade personal information. We share data only with the providers that run the service:

ProviderRole
ShopifySource of store data, app authentication, and subscription billing
OpenAIEmbeddings and reply generation
SupabasePostgreSQL database hosting
RailwayApplication hosting

Each is bound by its own data-processing terms. We may also disclose information where we are legally required to.

07Storage & Security

  • All traffic runs over HTTPS/TLS
  • Shopify access and refresh tokens are encrypted at rest with AES-256-GCM
  • Dashboard sessions use signed JSON Web Tokens in httpOnly cookies, which page JavaScript cannot read
  • Every database query is scoped to a single store, so one merchant's data cannot be returned to another
  • Access tokens are short-lived and refreshed automatically; a revoked token stops working immediately

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant authorities as required by law.

08Retention & Deletion

We support all three of Shopify's mandatory compliance webhooks and act on them automatically:

  • customers/data_request — a request from a shopper, through the merchant, for the data we hold on them. Logged and answered.
  • customers/redact — a deletion request for a specific customer's data
  • shop/redact — sent by Shopify roughly 48 hours after uninstall. On receipt we permanently delete everything indexed from that store, along with its conversations, analytics and agent configuration.

When you uninstall, your access token stops working immediately and the app can no longer read anything from your store. Your indexed content is then erased when the redaction request arrives. You do not need to email us to make this happen.

Store content is refreshed each time you re-sync, replacing what was there before. Conversation records and analytics are kept while the app is installed so your dashboard can show history.

09Merchant Rights

Depending on where you are, you may have the right to:

  • Ask what personal data we hold about you and receive a copy
  • Correct anything inaccurate
  • Have your data deleted
  • Object to or restrict how we process it
  • Withdraw consent, by uninstalling the app

Write to support@rankcrawler.com and we'll respond within 30 days. Uninstalling triggers deletion on its own — you don't need to ask.

10Shopper Rights

If you chatted with an agent on a store and want your messages removed, contact that store. They control the data and can request its deletion through Shopify, which reaches us as a redaction request. You can also write to us at support@rankcrawler.com and we'll work with the merchant to handle it.

Clearing your browser's storage for that store removes the anonymous visitor ID, which ends the link between you and any past conversation on that device.

11Cookies & Local Storage

The storefront widget stores one value in the browser: a randomly generated visitor ID, used to group messages into a conversation. It sets no advertising or cross-site tracking cookies.

The merchant dashboard sets one httpOnly session cookie to keep you signed in. That's the only cookie it uses.

12International Transfers

We operate from India, and our providers run infrastructure in several countries. Your data may therefore be processed outside the country you live in. Where a transfer involves personal data from the EEA or UK, we rely on the safeguards offered by those providers, including standard contractual clauses.

13Children's Privacy

The app is built for merchants and is not directed at children. We do not knowingly collect personal information from anyone under 13. If you believe a child has sent information through the widget, write to us and we will delete it.

14Changes To This Policy

We will update this policy as the app changes. The date at the top always reflects the current version. If a change materially affects how we handle your data, we will tell installed merchants by email.

15Contact Us

Questions about this policy, or about data we hold:

Email: support@rankcrawler.com
Support: rankcrawler.com/agent/support
RankCrawler · Mumbai, Maharashtra, India