1. Introduction
SEO Agent ("we", "us", "our") is committed to protecting your privacy. This policy describes:
- What information we collect
- How we use your information
- Who we share it with
- Your rights regarding your data
- How to contact us with privacy questions
2. Information We Collect
2.1 Registration Information
| Data Type |
Purpose |
Legal Basis |
| Full Name |
Account identification, personalization |
Contract performance |
| Email Address |
Login, notifications, support |
Contract performance |
| Password (encrypted) |
Account security |
Contract performance |
| Company / Website Name |
Workspace management |
Contract performance |
2.2 Payment Information
| Data Type |
Processor |
Storage |
| Credit Card Details |
Stripe (PCI-DSS compliant) |
Not stored on our servers |
| Billing Address |
Stripe |
Encrypted database |
| Transaction History |
Our database |
Encrypted database |
2.3 Shopify Store Data Shopify App
When you install the SEO Agent app from the Shopify App Store, we collect and process the following data:
| Data Type |
Purpose |
Retention |
| Store domain (myshopify.com URL) |
Identify your workspace and deliver the service |
Until uninstall or redact request |
| Shopify access token |
Read product images and write alt text via Shopify API |
Until uninstall or redact request |
| Product image URLs |
Send to AI model for alt text generation only |
Processed in real time; not stored |
| Subscription status |
Gate access to the service based on active billing |
Until uninstall or redact request |
No customer PII collected. We do not store Shopify customer names, email addresses, order data, or any personally identifiable information about your store's customers. The app operates on product images only.
2.4 General Usage Information
- Content Created: Articles, keywords, strategies (stored to provide the service)
- WordPress Credentials: Encrypted and stored securely for publishing
- API Keys: Google, Anthropic (encrypted storage)
- Activity Logs: Login times, feature usage (for security and analytics)
2.5 Technical Information
- IP Address (for security and fraud prevention)
- Browser type and version
- Device information
- Session cookies (essential for login)
3. How We Use Your Information
3.1 Service Delivery
- Creating and managing your account
- Generating AI-powered content
- Generating and writing image alt text to your Shopify products
- Publishing to your WordPress site
- Providing customer support
3.2 Communications
- Transactional Emails: Account creation, password resets, article completion (necessary)
- Service Updates: New features, important changes (legitimate interest)
- Marketing: Only with your consent (opt-out available)
3.3 Analytics and Improvement
- Understanding how users interact with the platform
- Identifying and fixing bugs
- Developing new features based on usage patterns
4. Third-Party Services
Data Processors We Use:
- Amazon Web Services (AWS): Server hosting (EU region)
- AWS SES: Email delivery (eu-west-1)
- Anthropic (Claude API): AI content and alt text generation
- Stripe: Payment processing (PCI-DSS compliant)
- Shopify: E-commerce platform integration; product data accessed via Shopify API under your authorization
- Google APIs: Search data (if you provide API keys)
All processors are bound by data processing agreements (DPAs) ensuring GDPR compliance.
5. Shopify GDPR Compliance Shopify App
SEO Agent complies with all Shopify mandatory GDPR webhook requirements:
- Customer Data Request: We store no Shopify customer PII, so there is no customer data to provide. We respond 200 OK to all customer data requests.
- Customer Erasure: We store no Shopify customer PII. We respond 200 OK to all customer erasure requests.
- Shop Erasure (48 hours after uninstall): Upon receiving a shop erasure webhook, we permanently delete your store domain, access token, pending alt text jobs, and all associated workspace data from our servers.
Uninstalling the app immediately marks your workspace as disconnected. All pending jobs are halted. Your store data is fully deleted within 48 hours upon receiving Shopify's shop erasure webhook.
6. Data Security
6.1 Technical Measures
- Encryption: HTTPS for all data transmission
- Password Security: Bcrypt hashing (industry standard)
- Database Security: Encrypted credentials, regular backups
- Access Control: Strict authentication and authorization
- Webhook Verification: All Shopify webhooks verified via HMAC-SHA256 before processing
6.2 Organizational Measures
- Limited employee access to personal data
- Regular security audits
- Incident response procedures
- Data breach notification protocols
7. Your Rights (GDPR)
You have the following rights regarding your personal data:
- Right of Access (Article 15): Request a copy of your data
- Right to Rectification (Article 16): Correct inaccurate data
- Right to Erasure (Article 17): "Right to be forgotten" - delete your data
- Right to Restriction (Article 18): Limit processing of your data
- Right to Data Portability (Article 20): Receive your data in machine-readable format
- Right to Object (Article 21): Object to certain types of processing
- Right to Complain (Article 77): Lodge a complaint with supervisory authority
To exercise your rights, contact us at: [email protected]
8. Cookies
8.1 Essential Cookies
- Session Cookie: Maintains your login state (required for service)
- CSRF Token: Security protection (required)
8.2 Optional Cookies
- Analytics: Understand usage patterns (can be disabled)
- Preferences: Remember your settings (can be disabled)
9. Data Retention
| Data Type |
Retention Period |
Reason |
| Account Information |
Until account deletion |
Service provision |
| Generated Content |
Until deletion by user |
User owns content |
| Shopify Store Data |
Until uninstall + erasure webhook |
Service provision; GDPR compliance |
| Payment Records |
7 years |
Tax and legal requirements |
| Activity Logs |
90 days |
Security and debugging |
10. International Data Transfers
Your data may be transferred to and processed in:
- European Union: AWS servers in eu-west-1 (Ireland)
- United States: Anthropic API processing
All international transfers are protected by:
- Standard Contractual Clauses (SCCs) approved by EU Commission
- Adequate safeguards ensuring GDPR-level protection
- Data processing agreements with all processors
11. Children's Privacy
Age Restriction: SEO Agent is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately at
[email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via:
- Email notification to your registered address
- Prominent notice on the platform
- Updated "Last Updated" date at the top of this page
Continued use of the Service after changes constitutes acceptance of the updated policy.
13. Contact Information
For privacy-related questions, requests, or complaints:
Data Protection Officer
For GDPR-related matters, contact our Data Protection Officer at: [email protected]
Supervisory Authority
You have the right to lodge a complaint with your local data protection authority. In Israel, this is the Privacy Protection Authority.