Privacy Policy
Last updated: September 3, 2026
Yeedoor AI Store Manager is operated by 杭州亦道出海数字科技有限公司 (Hangzhou Yidao Chuhai Digital Technology Co., Ltd.). This policy explains how we process merchant, shop, and Shopify protected customer data when merchants install and use the app.
1. Data we process
Merchant and shop data
- Shop domain, store configuration, granted scopes, installation/session information, and app authentication credentials.
- Product, variant, SKU, pricing, inventory, location, market, fulfillment, return, refund, and related operational information when authorized by the merchant.
Protected customer data — Level 1
When authorized, the app may process order- and customer-related Shopify resources needed for merchant operations and analytics, including order totals, order status, line items/SKUs, fulfillment state, refund/return patterns, and operational history.
V1 does not request the protected customer fields Name, Address, Email, or Phone.
2. Why we process data
We process data for the following Shopify-declared purposes:
- Store management: operational monitoring, inventory/order/fulfillment analysis, and issue detection.
- App functionality: providing the AI Operating Team, merchant dashboards, recommendations, approvals, and supported actions.
- Analytics: revenue, order volume, average order value, SKU contribution, operational trends, anomalies, and effectiveness measurement.
We do not use V1 protected customer data for customer-level advertising or personalization, and we do not sell personal data.
3. Data minimization and storage
Raw Shopify protected customer/order data is processed transiently for the merchant's requested analytics and is not persisted in the V1 application database. The V1 database stores Shopify application session/authentication records needed to maintain the merchant's connection.
4. Security
- Shopify and application traffic is transmitted using HTTPS/TLS.
- Shopify access and refresh tokens are encrypted at rest using AES-256-GCM before being written to application session storage.
- Production requires a dedicated session-encryption secret separate from source code.
- Application logging is designed not to record access tokens or raw protected customer data.
5. Retention
| Data | Retention |
|---|---|
| Raw protected customer/order data | Not persisted in V1; processed transiently per request. |
| Shopify session/authentication data | While the app is installed; deleted on uninstall and again when Shopify sends the mandatory shop/redact request. |
| Operational logs | Target maximum 30 days and designed to exclude raw protected customer data and tokens. |
6. Privacy requests and deletion
The app implements Shopify's mandatory privacy webhooks for customer data requests, customer redaction, and shop redaction. See our Data Retention & Deletion Policy.
7. Service providers and international processing
We may use hosting, database, security, and infrastructure providers only as necessary to operate the service. Service providers are required to process data only for service delivery and under appropriate confidentiality and security obligations. Before public launch, the production infrastructure and applicable subprocessors will be reflected in our current documentation.
8. Merchant responsibilities
Merchants determine which Shopify store data is made available to the app through Shopify authorization and remain responsible for their own privacy notices and lawful use of customer data.
9. Contact
For privacy questions or requests, email aiken@yeedoor.com with the subject “Yeedoor AI Privacy”.