SikSmart AI Search Optimizer
Back to app overview

Privacy Policy

How SikSmart AI Search Optimizer handles merchant data.

This policy explains how 6smart collects, uses, stores, shares, and deletes data when merchants install or use the app with a Shopify store.

Product-data focused

The app works with Shopify catalog data, not order records or customer profiles.

Merchant-controlled AI

Product data is sent to AI providers only when a merchant starts a generation or analysis action that needs AI.

No storefront tracking

The JSON-LD theme extension does not add analytics cookies, advertising pixels, or visitor tracking scripts.

Shopify compliance

Mandatory privacy webhook handlers are implemented for customer data requests, redaction, and shop redaction.

1

Information We Collect

Shopify grants the app access only to approved scopes needed to provide product SEO, AI content workflows, structured data, llms.txt settings, billing, and support.

DataPurpose
Store domain and basic shop detailsIdentify the store, connect app records to the correct Shopify shop, and provide support.
Shopify admin identity and OAuth session dataAuthenticate authorized store admins and maintain secure app sessions. Depending on the Shopify session, this may include admin name, email, locale, user ID, access tokens, and refresh tokens.
Product titles, descriptions, tags, images, variants, SEO fields, and metafieldsRun product readiness scans, prepare content suggestions, and build structured product context.
Product image URLs and image contentGenerate alt text and image-informed recommendations when merchants request image-based AI features. The app may retrieve an image and send its content to the selected AI provider for that request.
Theme and SEO configurationSupport Theme App Extension access, JSON-LD schema settings, and llms.txt publishing preferences.
Optional storefront password for live auditsUnlock password-protected storefront pages only when merchants request live SEO/AEO audits. The saved password is encrypted at rest, is not shown again in the browser, and is not used for AI generation.
Competitor storefront URLs and public page signalsRun merchant-requested public competitor audits and compare publicly readable SEO and AI-readiness signals.
App usage, credits, billing state, and generation historyEnforce plan limits, show usage history, support Shopify-approved billing workflows, and provide rollback context.
We do not intentionally collect:
  • End-customer personal information such as customer names, emails, phone numbers, or addresses.
  • Order payment details, cardholder data, or PCI-regulated payment information.
  • Storefront visitor tracking behavior from the Theme App Extension.
2

How We Use Information

  • Authenticate merchants through Shopify OAuth and maintain app sessions.
  • Analyze product content and calculate SEO and AI-readiness scores.
  • Generate merchant-requested titles, descriptions, metadata, tags, FAQ content, and alt text.
  • Sync catalog essentials such as product type, vendor, tags, SKU, and GTIN/barcode.
  • Configure JSON-LD structured data and llms.txt settings.
  • Unlock password-protected storefront pages for live audits only when a merchant saves a storefront password.
  • Fetch publicly readable competitor pages only when a merchant runs a competitor audit.
  • Track credits, plan limits, billing state, generation history, and support context.
3

Third-Party Service Providers

Product data is shared with service providers only when required for the selected feature. If a merchant connects a bring-your-own API key, requests are sent to the provider selected by that merchant.

ProviderData processedPolicy
OpenAIProduct text and image input when OpenAI-powered generation or analysis is requested.openai.com
Google GeminiProduct text and retrieved image content when Gemini-powered generation or analysis is requested.policies.google.com
AnthropicProduct text and retrieved image content when Claude-powered generation or analysis is requested.www.anthropic.com
NeonApplication database hosting for app settings, scan results, usage records, and generated content history.neon.tech

We do not sell merchant data or customer personal information.

4

Security

  • Data is transmitted over TLS/SSL.
  • Custom AI API keys and optional storefront audit passwords are encrypted at rest before storage.
  • Saved storefront passwords are never returned to the browser after saving and are used only server-side for live audit requests.
  • Shopify authentication is handled through OAuth. We do not store Shopify admin passwords.
  • Access to app data is limited to authenticated store admins and authorized 6smart personnel for support and maintenance.
5

Data Retention and Deletion

We retain Shopify sessions, store settings, catalog scan results, generation history, usage records, and billing state while the app remains installed so the app can provide its merchant-requested features. Custom AI keys and storefront audit passwords remain stored until they are replaced, removed, or the app is uninstalled. Expired sessions may also be removed as part of normal authentication maintenance.

When Shopify sends an app/uninstalled webhook, we delete the store record and its associated scans, jobs, score snapshots, credit usage, generation history, saved settings, encrypted merchant secrets, and Shopify sessions. When Shopify later sends the mandatory shop/redact compliance webhook, we process it idempotently and delete any remaining store-linked records.

6

Merchant and Data Subject Rights

Merchants may request access, correction, export, or deletion of app data by contacting support@siksmart.com. We respond to privacy requests within applicable legal timeframes.

Shopify also forwards mandatory privacy requests through the customers/data_request, customers/redact, and shop/redact webhooks.

7

Cookies and Storefront Tracking

The embedded admin app relies on Shopify authentication flows. The Theme App Extension used for JSON-LD does not add analytics cookies, advertising pixels, or storefront visitor tracking scripts. Optional storefront passwords are used only to unlock merchant-requested live audit requests and do not install any storefront tracking.

8

Children's Privacy

The app is intended for Shopify merchants and business users. It is not directed to children, and we do not knowingly collect information from children.

9

Changes to This Policy

We may update this Privacy Policy to reflect operational, legal, or product changes. The latest version will be published at this URL with an updated date.

Contact

Questions about data processing?

Send privacy questions, export requests, or deletion requests to 6smart support.