Privacy Policy: Control AI Agents: AI Traffic
Effective date: September 29, 2026
Last updated: September 29, 2026
This policy explains what data the Shopify app Control AI Agents: AI Traffic (the "App") collects, why, who it shares data with, how long it keeps data, and the choices you have. The App is provided by Control AI Agents ("we", "us").
It applies to:
- Merchants who install the App on their Shopify store.
- Visitors and customers of those stores, whose data the App processes on the merchant's behalf.
Summary
- The App shows a store which products AI assistants (such as ChatGPT, Perplexity, Gemini and Copilot) send shoppers to, and which orders and visits came from AI shopping agents that browse and buy on a shopper's behalf (such as Meta Muse, ChatGPT agent, Perplexity Comet and Claude in Chrome). It builds pages from the store's own reviews, returns and product data, and measures whether AI visits change.
- We process customer data at Shopify's Level 1 only, for orders. We don't store a customer ID with orders, and we never collect customer names, email addresses, phone numbers or postal addresses.
- The web pixel runs only for storefront visitors who have granted the permissions it declares.
- We keep visit-level data for 90 days. After that we keep only daily totals.
- We never email, contact or profile shoppers. We don't sell data or use it for advertising.
- For shopper data, the merchant is in control and we act on the merchant's instructions. The Data Processing Agreement governs this.
1. Our role
- For data about a store's visitors and customers, the merchant is the controller (or "business"), and we are a processor (or "service provider") acting on the merchant's instructions under our Data Processing Agreement. Shoppers who want to exercise their rights should contact the store. We help the store respond.
- For merchant account data (such as the store's contact email and billing status), we are the controller.
2. What we collect
From the merchant's store, through Shopify's APIs
| Data | What exactly |
|---|---|
| Store details | Store domain, store name, contact email, currency, primary domain, time zone, whether it is a development store, the App plan and subscription status, and, on the Scale plan, the languages the store has published. Shopify handles payment; we never see card details. |
| Access credentials | The access token Shopify issues so the App can call Shopify's APIs for the store. |
| App settings | Choices made in the App: auto-publish, weekly email, reviews source, returns source, products excluded from tests, and the languages chosen for page translations. Review app API tokens are also stored, encrypted. |
| Products | Titles, handles, descriptions, product types, vendors, categories, tags, options (such as sizes), price ranges, image links, online store links and product specifications from metafields. |
| Orders (Level 1 protected customer data) | Order ID and number, date, total and currency, sales channel (including an AI shopping agent that placed the order, such as Meta Muse), line items (product, variant, quantity and price), and the attribution for the order's first and last visit: landing page URL, referrer URL, visit source and UTM tags. We don't collect who placed the order: no customer ID, name, email, phone number or address. |
| Returns and refunds | Return or refund ID, order ID, product, variant (such as "M / Blue"), quantity, return reason (such as "Too small"), the reason label the merchant defined, and the customer's return note with personal details removed. |
At install we read the orders from the last 60 days. After that we read each new order as it's placed.
From storefront visitors, through the App's web pixel
The pixel runs in Shopify's sandbox for web pixels. Shopify only loads it for visitors who have granted the permissions it declares under the store's privacy and consent settings. If a visitor withdraws consent on the page, for example in the store's cookie banner, the pixel stops recording straight away, without waiting for a reload. For visitors who have granted consent it records:
- Shopify's event ID and the event type: page viewed, product viewed or search submitted.
- A random browser identifier that Shopify assigns (not a name or account), and a session key derived from it.
- The time.
- The page's address: the store's domain, the page path and the UTM tags, with the rest of the query removed. For checkout, order status and customer account pages we keep only the first word of the path (such as
/checkouts), never the token that follows it, so a visit can't be tied to an order or an account. - The referring site, with at most the first word of its path (such as
perplexity.ai/search). We never keep the rest of the referrer's path or its query, which can hold a conversation ID or the question the shopper asked. - The product viewed.
- The text of on-site searches, with emails, phone numbers and similar personal details removed before storage.
- If the browser's user agent carries a token that the agent's vendor documents for its AI agents (today
Google-Agentfrom Google andMeta-ExternalFetcherfrom Meta), the name of that agent. We keep only the name, not the user agent. Agents that browse with an ordinary browser, such as ChatGPT agent, Perplexity Comet and Claude in Chrome, send no such token, so their visits aren't marked as agent visits.
From these we work out whether a visit came from an AI assistant or an AI shopping agent, and which one.
We don't store IP addresses, device fingerprints or user-agent strings. To stop abuse, the App and its load balancer count requests per IP address in memory, for up to an hour, without writing IP addresses to the database or to logs.
Reviews
When the merchant uploads a review export (CSV) or connects a review app, we store each review's rating, title, text, date, verified flag and product.
- Reviewer names are dropped when the file is read and are never stored.
- Emails, phone numbers and similar details are removed from review text before storage.
What the App creates
- Shopper needs (for example "fit of linen shirts"), and facts extracted from reviews and returns, with short quotes that have personal details removed.
- Page ideas, draft and published guide pages, and the result of each claim check.
- Product description suggestions, and a saved copy of each original description so it can be restored.
- On the Scale plan, translations of published guide pages into the languages the merchant chose. They're stored as translations in the merchant's Shopify store.
- Split test assignments (which products get pages and which stay untouched), daily totals of visits and orders per product and page, and test results.
- The weekly email summaries, a log of App actions (such as "page published"), and a record of each privacy request received from Shopify, with the IDs Shopify sent in it.
- For a customer data request, the file the App compiles for the merchant to download and send to the customer.
Logs
Our servers keep technical logs (errors, job status and response times) to run and secure the service. We don't write shopper data, review text or search text to logs.
3. Why we use it
We use the data only to provide the App to the merchant:
- Report AI traffic. Count orders and visits from AI assistants and AI shopping agents, by assistant, agent, product, landing page and search.
- Learn what shoppers need. Sort AI-referred visits, searches and orders into the store's shopper needs.
- Build pages and product copy. Draft guide pages and description updates from the store's reviews, returns and specs. Check each claim against that data, and publish only what the merchant approves (or auto-publishes, if the merchant turns that on).
- Measure the effect. Run the split test and report AI visits, AI orders and Google visits for tested and untouched products.
- Tell the merchant. Send the weekly email to the store's contact email.
- Bill, support and secure the service. Check the Shopify subscription, answer support requests, prevent abuse and fix errors.
- Meet legal obligations. Handle Shopify's privacy requests and keep records needed to show compliance.
We don't:
- Sell or rent personal data, or share it for cross-context behavioral advertising.
- Contact, email or target a store's shoppers.
- Build profiles of individual shoppers, or link a shopper across different stores.
- Make decisions about shoppers that have legal or similarly significant effects. The App's classifications describe anonymous visits and only decide which pages to suggest to the merchant.
Aggregated insights across stores
We may combine aggregated, de-identified statistics across stores. Examples are how often shoppers ask about fit in a product category, or pooled split test results. We use them to improve the App and to publish general reports, such as which kinds of products AI assistants sent shoppers to over Black Friday. These statistics never identify a store or a shopper. We don't publish any store's own figures without its permission.
4. AI processing
The App uses AI models to label data and write drafts. The only data we send to them is:
- product data,
- review text and return notes with reviewer names and personal details removed,
- search phrases with personal details removed,
- landing pages and products from AI-referred visits,
- counts computed by our own code,
- on the Scale plan, the text of published guide pages, to translate them.
We never send customer IDs, names, email addresses, phone numbers or postal addresses. Orders are stored without them, and the records of privacy requests are never sent to AI models.
- Claude, through Amazon Bedrock (AWS). Writes pages and product copy, translates pages on the Scale plan, and runs judgments when Jev isn't available. AWS runs the model in its own accounts; according to AWS, model providers such as Anthropic have no access to prompts or outputs. Depending on the model, AWS may keep requests for a limited time to detect abuse. Requests use global cross-region inference, so AWS may process them in any of its commercial Regions. We don't turn on Bedrock's model invocation logging, and AWS doesn't use prompts or outputs to train models.
- Jev, from TypeSafe. Sorts visits into shopper needs, labels reviews and returns, and checks claims against the data. TypeSafe AI, Inc. hosts its service in the United States, processes requests under its data processing addendum, and doesn't train or fine-tune models on them.
5. Where data is stored and how we protect it
- Location. Data is stored on Amazon Web Services in the United States (region (us-east-1)).
- Encryption in transit. All connections to the App use HTTPS (TLS 1.2 or 1.3). Connections between our servers and the database require TLS.
- Encryption at rest. The database, its automated backups and snapshots are encrypted with AES-256 using AWS Key Management Service. Secrets are held in AWS Secrets Manager. Review app API tokens are also encrypted with AES-256-GCM before they are stored.
- Network isolation. The database runs in a private network, isn't reachable from the internet, and accepts connections only from the App's own servers.
- Access. Access to production systems is limited to authorized Control AI Agents personnel and follows least privilege. The App's servers can only call the AWS services they need.
- Minimization. We store only the fields listed in section 2 and remove personal details from free text before we store it.
6. Subprocessors
We use these service providers to run the App. Each is bound by a contract that protects the data.
| Subprocessor | Purpose | Data | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Hosting (Amazon ECS), database and backups (Amazon RDS), secrets (AWS Secrets Manager), logs (Amazon CloudWatch), rate limiting (AWS WAF) | All data described in section 2 | United States (us-east-1) |
| Amazon Web Services, Inc.: Amazon Bedrock | Claude models for writing pages and product copy, translating pages (Scale plan), and judgments when Jev is unavailable | The data listed in section 4 | United States, and other AWS Regions through global cross-region inference |
| Amazon Web Services, Inc.: Amazon SES | Sending the weekly email to the merchant | Merchant contact email and the report contents (totals, page titles, ideas) | United States |
| TypeSafe AI, Inc. | Jev judgments: sorting visits into shopper needs, labeling reviews and returns, checking claims | The data listed in section 4 | United States |
Shopify provides the platform the App runs on. It isn't our subprocessor. We'll tell merchants about new subprocessors at least 30 days in advance, as described in the Data Processing Agreement.
7. How long we keep data
| Data | How long |
|---|---|
| Visit-level pixel data (individual events and AI-referred sessions) | 90 days, then deleted. Only daily totals per product and page remain, with no visitor identifiers. |
| Daily totals and split test results | While the App is installed |
| Orders, returns, reviews, products and App-created content | While the App is installed, unless the merchant or Shopify asks us to delete them sooner |
The orders listed in a customers/redact request |
Deleted, with their line items and returns, and with the facts and quotes taken from those return notes. They're also erased from earlier customer data request files and from page idea evidence. This happens within 30 days of the request (Shopify's deadline), usually within minutes. |
Customer data request files (customers/data_request) |
60 days. We email the store's contact address when a file is ready, and the merchant downloads it in the App (Settings > Customer data requests) to send to the customer. After 60 days the file is cleared, and only a record remains: the request type, when it arrived and was compiled, and how many orders it covered. |
| All of a store's data after uninstall | Shopify sends a shop/redact request 48 hours after uninstall, and we then delete all of that store's data. |
| Database backups | Automated backups roll over after 7 days, so deleted data leaves backups within 7 days. |
| Server logs | 30 days |
| Records of privacy requests | While the App is installed, to show we completed them. Each record holds the request type, the dates it arrived and was completed, and the IDs Shopify sent with it (the order IDs and the customer ID), not the data itself. The customer ID Shopify sent is the only customer ID we keep: here, and in the compiled file for a customer data request. shop/redact deletes these records, except the record of that request, which holds only the store's ID and domain. |
Guide pages the merchant published are stored in the merchant's own Shopify store. They stay there after uninstall, and the merchant controls them.
8. Your rights and choices
Merchants
- Access or export. Email us to get a copy of your store's data.
- Correction. Email us, or change your settings in the App.
- Deletion. Uninstall the App. Shopify then asks us to delete your store's data, and we do. To have it deleted sooner, email us.
- Stop the weekly email. Turn it off in Settings.
- Stop visit tracking. Uninstalling removes the web pixel.
- Control publishing. Nothing is published or changed in your store without your approval unless you turn on auto-publish. Product description changes can be undone.
- Object or complain. Depending on where you are, you can object to or restrict processing, or complain to your data protection authority.
Shoppers and store visitors
- Contact the store you visited or bought from. It controls your data.
- When a store asks Shopify to fulfil your request, Shopify sends it to us, and we act on it within 30 days. We delete your data, or we put together a copy of what we hold for the store to send to you.
- You can also email us, and we'll pass your request to the store.
9. What merchants should tell their shoppers
Merchants are responsible for their own storefront privacy policy and consent banner. Suggested wording:
We use the Control AI Agents: AI Traffic app to understand which products shoppers find through AI assistants and AI shopping agents, and to improve our product guides. If you allow analytics, it records the pages you view and the searches you make on our store, without your name or contact details.
10. International transfers
We store data in the United States, and requests to Claude may be processed in other AWS Regions (see section 6). For merchants in the European Economic Area, the United Kingdom or Switzerland, the Data Processing Agreement includes the Standard Contractual Clauses (and the UK Addendum) for these transfers.
11. Children
The App is for businesses. It isn't directed at children, and we don't knowingly collect children's data.
12. Changes to this policy
If we make a material change, we'll email merchants at least 30 days before it takes effect. If the change also affects the Data Processing Agreement, we publish a new version of it, and the App asks merchants to accept it. The "Last updated" date above shows the latest version.
13. Contact
Control AI Agents
Email: hello@controlaiagents.com