AgentSight privacy policy
Last updated: July 30, 2026
AgentSight is a Shopify app operated by Ellefsen Marketing ("we"). It audits merchant-controlled product data and selected public storefront and Catalog surfaces. This policy describes exactly what data the app touches.
What we access
- Product data (titles, descriptions, images and alt text, variants, categories, SEO fields) — read to produce the audit, written only when you apply a fix.
- Shop information (store name, primary domain) — used to run public endpoint checks against your own storefront.
- Exact-product receipt input (a public product URL after its query parameters are removed, buyer-style query, and two-letter country code) — sent to Shopify Global Catalog only when you request that bounded check.
What we store
- Your shop domain and Shopify API session data. For online sessions, Shopify can include the authorized staff member's Shopify user ID, first and last name, email address, locale, and account or collaborator status.
- Scan results: Shopify product IDs, titles, handles, featured-image and storefront page URLs, scores, detected issues, and the scanned media IDs and alt text needed to explain product findings. Scan-continuation timestamps and cursors are also stored so interrupted scans can resume safely.
- Fix history: one shop-level operation record plus the intended previous and new values persisted before Shopify is asked to change a field. Confirmed changes are kept so you can revert them, while partial or conflicting outcomes are marked for review without automatic retry. Free-plan usage counts merchant operations rather than individual fields.
- Shop-level activation timestamps: when the first scan started and completed, issue results were first viewed, a first fix was applied, and the score was first refreshed after an active fix. These contain no event payload, product content, customer data, or staff identity and are used only to operate and improve the onboarding flow.
- A shop-level next-allowed timestamp and short-lived random lease are used to prevent duplicate exact-product Catalog requests. The lease is cleared after the request; if the process stops, its authority becomes invalid automatically after 30 seconds. AgentSight does not store the submitted product URL, query, country, or Catalog response from this receipt.
- Per-shop and project-wide UTC-day request counts enforce hard daily safety limits. They contain only the shop domain, date, and count — no receipt input or response content.
- Shopify app subscription metadata: plan handle, subscription lifecycle stage, billing-cycle dates, and Shopify event identifiers used to reconcile app access and entitlements. We do not receive card, bank-account, or payment-method details.
What we never access or store
- No customer data of any kind (names, emails, addresses, orders).
- No card, bank-account, payment-method, customer-order, or transaction data.
- No third-party analytics trackers or advertising pixels in the app.
- No saved exact-product receipt inputs or Shopify Global Catalog response bodies.
Data sharing
We do not sell personal data. Vercel processes app traffic and Neon stores app records as infrastructure service providers solely so we can operate AgentSight. Shopify separately processes installation, authorization, app billing, platform events, and an exact-product Global Catalog request when you explicitly run that check, under its own terms.
Deletion
Uninstalling the app invalidates its access immediately. When Shopify sends the shop redaction webhook after uninstall, every stored record for the shop — scans, audits, fix-operation and revert history, activation timestamps, Catalog request gate and daily count, and session — is deleted. You can also email us at any time to request immediate deletion.
Contact
Questions or requests: ellefsenmarketing+agentsight@gmail.com