[ 20 ] PRIVACY
Privacy Policy
Effective: 2 August 2026 · Last updated: 2 August 2026
We keep this in plain language on purpose. If anything is unclear, email us at support AT ghostbot.ai.
01 · What this policy covers
GhostBot ("GhostBot", "we", "us") is an AI-powered A/B testing tool for Shopify merchants: it drafts experiment variants for your storefront, runs A/B tests, and measures conversion and revenue lift.
This policy covers personal data handled across our domains:
ghostbot.ai: this website (including the early-access waitlist)app.ghostbot.ai: the merchant admin appedge.ghostbot.ai: variant assignment and event ingestionsdk.ghostbot.ai: the storefront script merchants enable on their stores
It covers three audiences: merchants who install GhostBot, storefront visitors of those merchants' stores, and visitors to this website. It does not cover the practices of third parties, including Shopify or the merchants' own stores.
02 · The short version
- We are built to know as little about shoppers as possible: pseudonymous IDs, no names, no emails, no addresses from storefront traffic.
- The storefront script honors Shopify's consent signals automatically. If a shopper hasn't consented to analytics where consent is required, we don't track, and if consent is revoked we wipe our identifiers.
- Purchase data reaches us server-side from Shopify, minimized to order total, currency, ID, and timestamp. We never store the raw order or the customer's identity.
- We don't sell personal data. We don't use your data to train AI models.
- Deletion requests flow through automatically: when Shopify tells us to erase a shop or a customer, we erase across all our systems.
03 · Our two roles
For storefront visitor data processed while running experiments on a merchant's store, the merchant is the data controller and GhostBot is a processor acting on the merchant's instructions. The merchant is responsible for its own storefront notices and lawful basis; our Data Processing Addendum (available on request at support AT ghostbot.ai) governs this relationship.
For merchant account data and this website (including the waitlist), GhostBot is the controller and this policy describes that processing directly.
04 · Data we collect from merchants
When you install and use GhostBot, we collect:
- Store identifiers and details: your shop's domain, Shopify shop ID, plan, country, and locale.
- A Shopify access token: authorizing GhostBot to call the Shopify Admin API for your store. It is encrypted at rest at the application layer.
- Merchant user records: account email and, where provided, name and avatar for users of the admin app, plus an audit log of administrative actions.
- An AI store profile: a generated profile of your store (vertical, estimated average order value, brand-voice fingerprint) used to draft experiment ideas and variant copy.
- Page snapshots: rendered captures (HTML + screenshot) of your storefront pages, used to generate experiment hypotheses and variants. A rendered page may incidentally include customer-visible content you display (for example, a reviewer's name in a product review).
05 · Data we process about storefront visitors
When a merchant enables GhostBot on their store, the script and our edge service process, on the merchant's behalf:
- Pseudonymous identifiers: a randomly generated visitor ID (stored in the
browser and mirrored in a first-party cookie,
_gb_vid, with roughly a one-year lifetime) and a per-tab session ID. These are generated on the device and are not derived from anyone's name, email, phone, or account. They are pseudonymous rather than anonymous: order IDs stored for purchase attribution could be resolved to a customer inside the merchant's own Shopify systems. - Browsing context: page URL, referrer, device type (desktop / mobile / tablet), and UTM parameters.
- Behavioral events: which experiment variant was shown (
exposure), product-page views, add-to-carts, and checkout starts. - Purchase attribution (server-side, minimized): purchase data comes from
Shopify's
orders/createwebhook, not from the browser. We keep only the order total, currency, order ID, timestamp, a test-order flag, and our own attribution IDs. We deliberately do not collect or store the customer's name, email, phone, or address, and we do not persist the raw order payload.
06 · Consent and cookies
GhostBot's storefront script checks Shopify's Customer Privacy API before doing anything:
- Where a merchant's store requires consent for analytics (for example under EU/UK rules), GhostBot stays inert until the shopper's consent allows analytics processing.
- If a shopper declines or later revokes consent, GhostBot stops tracking, wipes its stored identifiers from the browser, and clears its attribution attributes from the cart.
- Where no consent framework applies, the script sets only the first-party, pseudonymous storage described above.
Shoppers can also clear GhostBot's identifiers at any time by clearing cookies and site data for the store they visited.
07 · This website and the waitlist
If you join the early-access waitlist on ghostbot.ai, we collect your email and, optionally, your store URL and role. These are stored as a contact record with our email provider, which is what we use to send the confirmation message and, when a place opens up, your install invitation. We keep no second copy in a separate database. You can unsubscribe at any time via the link in any email; unsubscribing stops the emails, and you can ask us to delete your waitlist record entirely at support AT ghostbot.ai.
This website does not run third-party advertising trackers.
08 · How we use data
We use the data above to operate the service: authenticate merchants, call the Shopify Admin API on their behalf, draft experiment variants, assign visitors to variants, measure conversion and revenue lift, secure the service, and keep required records.
Two commitments worth stating plainly:
- We do not sell personal data, and we do not use storefront visitor data for our own purposes or for cross-merchant advertising.
- We do not train AI models on your data, and we have not agreed to let our AI provider do so either. Variant generation runs under commercial API terms that do not permit training on inputs or outputs.
09 · Who we share data with
We use a small set of infrastructure providers (sub-processors under our DPA):
| What they do for us | Data involved |
|---|---|
| Application and website hosting | Merchant account data; waitlist submissions in transit |
| Edge delivery, variant assignment and event ingestion, config storage, page-snapshot rendering | Visitor identifiers and events; merchant config; snapshots |
| Database and object storage | Merchant account data; store profiles; snapshots |
| Analytics event store | Visitor events; minimized order-attribution rows |
| AI generation | Store profile and page-snapshot content |
| Background job processing | Order-attribution data; deletion instructions |
| Email delivery and contact storage | Waitlist email addresses, store URL, role |
We will name the specific providers behind each of these to any merchant who asks, and our Data Processing Addendum lists them by name, because merchants are entitled to know who processes their shoppers' data and to object to a change. Write to support AT ghostbot.ai for the current list.
Shopify is not our sub-processor. It's the platform your store runs on, under your own agreement with Shopify; it is the source of the account and order data described above.
We may also disclose personal data where required by law or legal process, or to protect our rights, our users, or the public.
10 · Where data is processed
GhostBot stores and processes data in the United States. Our databases, object storage, and analytics store are hosted in US regions.
One nuance worth stating plainly: the edge provider that serves our storefront script and receives events runs a global network. A shopper's request may first be handled at a point of presence near them, including outside the US, before the data is stored in the United States.
During early access the service is offered to US-based Shopify stores; installs from regions with consent-first requirements (EEA/UK) are not currently accepted. When we open those regions, we will put the appropriate cross-border transfer mechanisms in place and update this section.
11 · Retention and deletion
- Merchant data is retained while your account is active. When you
uninstall GhostBot, your shop record and stored access token are deleted
immediately. When Shopify sends its follow-up
shop/redactrequest (roughly 48 hours after uninstall), we hard-delete the shop's remaining data (database records, analytics rows across all event datasets, and stored page snapshots) via a durable, automatically retried job. - Customer deletion requests (
customers/redact, routed via Shopify from the merchant) trigger a full cascade: we resolve the affected orders to our pseudonymous visitor IDs and delete both the order-attribution rows and that visitor's behavioral event rows across our analytics datasets. - Data access requests (
customers/data_request) are supported through the merchant, who is the controller for shopper data. - Waitlist records are kept until you unsubscribe and ask for deletion.
We would rather describe our retention accurately than quote a number we don't
enforce. Today, deletion is event-driven rather than age-driven: the
triggers above (uninstall, shop/redact, customers/redact, a deletion
request) are what erase data, and outside of them analytics events are retained
for as long as the merchant's account is active, because experiment results
depend on them. We are working toward a fixed maximum age for behavioral event
data and will state it here once it is actually enforced in the product.
12 · Security
We describe only measures we actually use, and we claim no certifications:
- TLS/HTTPS for all traffic between our services and providers.
- Shopify access tokens encrypted at the application layer (XChaCha20-Poly1305 authenticated encryption) before database storage.
- Encryption at rest in our managed infrastructure providers.
- HMAC signature verification on all Shopify webhooks before processing.
- Least-privilege OAuth scopes.
- Revenue integrity: our public ingestion endpoint rejects client-asserted purchase values; purchase data is accepted only from the verified Shopify webhook.
No system is perfectly secure, and we can't guarantee absolute security.
13 · Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or port your personal data, to object to processing, and to complain to a supervisory authority. Under California law (CCPA/CPRA) you may have rights to know, delete, correct, and opt out of sale or sharing. We don't sell or share personal data in the CCPA sense.
If you're a shopper on a store that uses GhostBot, the merchant is the controller, so direct requests to them. We support the merchant through the Shopify deletion and access flows described in Section 11.
If you're a merchant or website visitor, contact us at support AT ghostbot.ai. We may need to verify your identity, and we respond within the timelines required by applicable law.
14 · Children
GhostBot is a business tool for merchants and is not directed to children. We don't knowingly collect personal data from children under 16; if you believe a child has provided us data, contact us and we'll delete it promptly.
15 · Changes to this policy
When we make material changes, we'll update the date at the top and provide notice by reasonable means, either in the admin app or by email to merchants.
16 · Contact
Questions, requests, or complaints: support AT ghostbot.ai.