Last Updated: 6th April, 2026
This Privacy Policy explains how Seokai ("we", "us", "our") collects, uses, stores, and protects your data when you use our Shopify application and website. We comply with the GDPR (EU), UK GDPR, CCPA (California), and other applicable data protection laws.
1. Data We Collect
1.1 Shopify Store Data
When you install Seokai, we access your Shopify store through Shopify’s secure OAuth process. We request permission to:
- Read and write product, collection, page, and article metadata (titles, descriptions, tags, images, alt text).
- Read and write store navigation and files (for LLMs.txt exports).
- Read locales and translations; write translated SEO content.
We also collect your store domain, contact email, and language settings for app configuration and reporting.
1.2 Store Content
We store copies of your product, collection, page, and article metadata in our database to perform SEO analysis, scoring, and AI optimization.
1.3 Account and Billing
- Subscription: Plan name, status, and purchase history — managed through Shopify’s billing system.
- Usage: Credit balance and records of AI operations (what was generated, when, credits consumed).
- Settings: Automation preferences, weekly report settings, and feature configurations.
1.4 Authentication
We store secure session tokens provided by Shopify. These are deleted when you uninstall the app.
1.5 Contact and Communication
- Contact form: Name, email, subject, and message — forwarded to our team via email, not stored in our database.
- Newsletter: Your email address is encrypted (AES-256-GCM) before storage. You can unsubscribe at any time.
- Support tickets: Messages and conversation history, stored to provide ongoing assistance.
1.6 Technical Data
- IP addresses: Temporarily collected for rate limiting on public forms. Automatically deleted within minutes.
- Operational events: Processing status of store events — automatically deleted after a short period.
1.7 Exported Files
- LLMs.txt files: Aggregated store content to help AI search platforms discover your store.
- Meta backups: CSV exports of your SEO metadata for backup and portability.
These files are stored securely and can be deleted by you at any time.
We do not collect payment card details, customer order data, or your end-customers’ personal information. All billing is handled by Shopify.
2. How We Use Your Data
- Perform SEO analysis, scoring, and optimization recommendations.
- Generate and optimize meta titles, descriptions, keywords, tags, and image alt text using AI.
- Automatically generate SEO metadata for new products and collections when automation is enabled.
- Generate translated SEO content for multi-language stores.
- Generate LLMs.txt files and meta backup exports.
- Send transactional emails (welcome messages, update notifications, weekly SEO reports).
- Track credit usage and enforce plan limits.
- Provide customer support.
- With your consent, send marketing communications.
3. Automated Processing
When you enable automation, Seokai automatically processes new products and collections:
- Metadata automation: Generates optimized meta titles, descriptions, and keywords for new products and collections.
- Alt text automation: Generates descriptive alt text for new product images.
You can enable or disable each automation independently at any time. Automated processing consumes credits from your plan.
4. Legal Basis for Processing (GDPR)
- Contract performance: Processing necessary to deliver Seokai’s features as part of your subscription.
- Consent: Marketing communications and newsletter subscriptions. Withdrawable at any time.
- Legitimate interests: Service improvement, security, and abuse prevention — balanced against your rights.
- Legal obligation: Where required by applicable law.
5. Data Sharing and Third Parties
We do not sell your personal data. We share data only with the following providers:
- Shopify: Billing, authentication, and store data access. Generated metadata is written back to your store.
- Cloud infrastructure provider: We use a cloud provider to host our application, store data, deliver emails, and process background tasks. This provider acts as a data processor under our instructions.
- AI service provider: Store content data (product titles, descriptions, collection titles, page/article content, and image URLs) is sent to a third-party AI provider for AI-powered generation. The provider may retain this data for service improvement per their own policies. We do not send personal data, customer information, or email addresses to the AI provider.
- Google: Our website uses Google Tag Manager and Google Analytics 4 to analyze website usage. Data is only collected with your consent. See Section 10 for details.
We may also disclose data if required by law or to protect our rights and safety.
6. Marketing Communications
If you subscribe to our newsletter, we may send product updates, SEO tips, and promotional content. You can opt out at any time via the unsubscribe link in any email. We never share your email for third-party marketing.
7. Data Retention
- Active accounts: Data retained for the duration of your subscription.
- After uninstallation: Session data is deleted immediately. Automation is disabled. All remaining data (store content, usage records, subscriptions, support tickets) is purged within 48 hours per Shopify’s data protection requirements.
- Newsletter: Retained in encrypted form until you unsubscribe or request deletion.
- Contact form: Not stored — forwarded to our team and not retained.
- Exported files: Retained until you delete them or uninstall.
8. Your Rights
Depending on your location, you have the right to:
- Access: Request a copy of your data. You can also export via meta backup (CSV) and LLMs.txt.
- Correction: Request correction of inaccurate data, or edit directly in the app.
- Deletion: Request deletion of your data. Uninstalling triggers automatic deletion.
- Portability: Request data in a machine-readable format (CSV).
- Objection: Object to processing based on legitimate interests.
- Restriction: Limit processing. You can disable automations and reports at any time.
- Withdraw consent: Withdraw consent at any time without affecting prior processing.
CCPA (California): You have the right to know what personal information we collect, request its deletion, and opt out of any sale. We do not sell personal information.
To exercise your rights, contact us via Section 13. We respond within 30 days.
9. Data Security
- Encryption in transit (TLS/SSL) and at rest for all data.
- Additional encryption for sensitive data such as email addresses.
- Verification of all incoming Shopify webhooks.
- Rate limiting on public endpoints.
- Restricted access on a need-to-know basis.
No system is 100% secure. If you discover a security issue, please contact us immediately.
10. Cookies and Tracking
Our website uses:
- Essential: Required for site functionality. Cannot be disabled.
- Analytics: Google Tag Manager and Google Analytics 4. Only set with your consent.
- Marketing: Ad campaign measurement. Only set with your consent.
A cookie consent banner appears on your first visit. We use Google Consent Mode v2 — analytics and marketing data is only collected after you grant consent.
The Shopify app does not set its own cookies. Authentication is handled by Shopify.
11. International Data Transfers
Your data is processed and stored in the United States. For transfers outside the EEA or UK, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards.
12. Changes to This Policy
We may update this policy. Material changes will be communicated via email or in-app notice before taking effect.
13. Contact Us
Questions or data rights requests: Contact Us