The short version
The app reads the product you choose and writes a complete generated store back to your own Shopify store — as a new draft theme your live theme is never touched by. It collects nothing about your customers — no names, emails, addresses, phone numbers or payment details — and it never takes part in checkout. Storefront analytics arrive with personal fields already removed by Shopify.
01Information collected from your store
When you install the app, Shopify grants the permissions shown on the install screen. Using those, the app reads and writes:
| What | Why |
|---|---|
| Store profile — domain, name, contact email, country, currency, time zone | To identify your store, bill the right account, format prices and pick a sensible default language |
| Products — ones you select, or the details generated for your new store | To build product pages and write generated products into your catalog when you ask |
| Themes, pages, navigation menus and files | To install the generated store as a NEW unpublished theme with its pages, menus and imagery. Your live theme is never written to |
| Discounts | To create the quantity-break discount you configure — real discounts, applied in Shopify checkout |
| Anonymized storefront events (via a Shopify web pixel) | To show you page views, add-to-carts and conversion for generated pages. Shopify removes personal fields before events reach the app |
| An offline access token issued by Shopify | To act on your store between visits. Encrypted at rest, never shown in the app |
The app does notrequest access to orders or customers, and therefore never receives your customers’ personal information from Shopify. Analytics events arrive with personal fields already removed by Shopify and carry no names, emails, addresses or payment details.
Shopify loads the app’s pixel only when a visitor’s consent covers analytics. The app declares that pixel for analytics only — not for marketing — and never sells or shares the data it produces.
02Information you provide
- The product URL or description you start a build from, and any instructions you type — market, language, brand preferences, tone.
- Edits you make to generated copy, images and settings before publishing.
- Anything you send us when you contact support.
03Generated stores and imagery
The app generates brand identities, page copy and product imagery with AI, stores them while your build is in progress, and writes the results into your own store — the theme into your theme library as an unpublished draft, images into your Shopify Files, pages and products into your catalog.
Everything written into your store belongs to your store. It keeps working if you uninstall the app — there is no license check and no lock of any kind.
04How the information is used
- To generate a store from the product you choose.
- To install and publish that store only when you explicitly ask.
- To count usage against your plan and bill through Shopify.
- To show you how your generated pages perform.
- To diagnose faults and improve the app.
Your store’s data is never sold, rented, used to build advertising profiles, or shared with other merchants.
05Service providers
The app relies on these processors, and no others:
| Provider | What reaches them |
|---|---|
| Shopify | Platform, authentication and billing — your store data, under Shopify’s own policies |
| Vercel | Hosting — requests made to the app |
| Supabase (self-hosted by SymplysisAI, Inc.) | Database and image storage — store profile, build settings, generated content and images, usage records |
| fal.ai | AI generation — the product title, description, price, images and any instructions you supply for the store being generated |
| PostHog (EU region) | Product analytics — which screens and actions are used, attributed to your store, never to an individual |
06Where data is stored
Data is held on servers operated by SymplysisAI, Inc. and by the providers above, which may sit outside your country. International transfers rely on the safeguards those providers offer.
07Retention and deletion
- While installed — data is kept so your builds stay available. The settings page lists the themes and app discounts the app created, so you can delete those from here; the products, pages, navigation and images it generated are ordinary Shopify content you remove in your admin like anything else.
- On uninstall — the stored access token is destroyed immediately and your subscription is cancelled the same day.
- On erasure — when Shopify sends the shop-erasure request that follows an uninstall (typically after 48 hours), the app deletes your store record, builds, generated images, registries and usage records.
- Stores already generated— anything written into your store belongs to your store and stays there, working. Delete it in Shopify — or from the app’s settings page before uninstalling — if you no longer want it.
You can request deletion at any time by emailing support@symplysis.com.
08Customer data requests
Shopify requires apps to answer customer data and erasure requests. This app requests no customer scopes and never takes part in checkout, so it holds no names, email addresses, phone numbers or addresses.
It does store pseudonymous storefront analytics from its own web pixel: a per-browser identifier generated by Shopify, the page path, referrer and campaign parameters, and — for a completed checkout — the order id and order total. When Shopify sends a customer erasure request, the app deletes the analytics rows for the orders named in it, along with the earlier events recorded against the same browser identifier.
09Your rights
Depending on where you are, you may have the right to access, correct, export, restrict or delete information held about you, and to object to its processing. Email support@symplysis.com and we respond within 30 days.
10Security
- All traffic is served over HTTPS.
- Shopify access tokens are encrypted at rest with AES-256-GCM and never reach the browser.
- Every request from the app’s interface is authenticated with a Shopify session token.
- Store data is scoped so one store can never read another’s.
No system is perfectly secure. If you believe you have found a vulnerability, email support@symplysis.com.
11Children
The app is a business tool, is not directed at children, and does not knowingly collect information from them.
12Changes to this policy
If this policy changes materially the effective date above is updated, and where the change affects how your data is handled you will be notified in the app or by email.