Quantum Quotient LLC

Privacy policy

Quantum Quotient LLC, Denver, CO, USA · Last updated 1 October 2026

Every statement here describes what the app's code actually does as of this date. If the app changes, this document changes with it.

This policy covers the Shopify app Product Markup for AI Shopping, its theme app embed and web pixel, and the free storefront scanner at app.youraiquotient.com/scan.

The short version

The app reads your product catalogue, scores it, and writes back only the changes you approve. It does not request, receive or store your customers' personal data: no names, emails, phone numbers, addresses, orders or checkouts. Under Shopify's protected customer data rules the app is Level 0, "no customer data", and every permission it asks for is listed below with the reason.

Who controls what

For everything the app holds about your store, you are the data controller and we are your processor. We act on your instructions and write nothing to your store without your explicit approval. For the free public scanner we are the controller of the scan record, which contains only publicly visible storefront data. A data processing agreement is available on request.

The permissions the app asks Shopify for

These are the ten access scopes the app requests at install, and what each one is used for. Nothing else is requested.

PermissionWhy the app needs it
Read and write productsRead every product, variant, image, category and attribute to score it; write back the categories, attributes, descriptions and barcodes you approve
Write filesSet image alt text you approve (Shopify requires the write scope for this; the app reads no other files)
Read and write metaobject definitionsEnable Shopify's own standard category-attribute definitions so attribute values can be written
Read and write metaobjectsRead and add entries in Shopify's taxonomy value lists (shopify--…), never your own metaobjects
Read legal policiesRead your published privacy, terms, refund and shipping policies, which the OpenAI product feed requires as seller fields. Read only
Write pixels and read customer eventsRegister the app's web pixel, described below. "Customer events" is Shopify's name for the scope; the pixel reads one field and no customer identity

The app deliberately does not request access to customers, orders, checkouts, fulfilments, gift cards or Shopify's session analytics.

What we collect through Shopify's APIs

About the store. Your myshopify domain, shop name, storefront domain and plan.

About products. A snapshot of each product as Shopify returns it: title, handle, description, images and their alt text, variants with prices, SKUs and barcodes, taxonomy category and its attributes, publication status, and any review-rating metafields a review app has written. Snapshots are refreshed on each scan and when Shopify tells us a product changed.

About your policies. The text of the published store policies named above, read to check the seller fields, not stored beyond the check result.

About proposed changes. Every draft the app produces, the value it would replace, whether you approved it, and when it was applied. The prior value is kept precisely so an approved batch can be undone.

What we collect directly from you

The email address you enter for the weekly digest, if you switch it on; your choice of AI assistant for the answer check; and, if an agency workspace is offered and you use it, the agency name, logo, colour and which stores are linked. We do not ask you for information about your customers.

What we collect from your customers

Only what the web pixel records, and only if you switch the pixel on.

The pixel subscribes to one event, page view, and reads one field, the referring page's hostname. If that host is not a known AI assistant, nothing is sent. If it is, the pixel sends four values: the assistant's host, the engine name, Shopify's browser client id and a timestamp. The server stores a salted one-way hash of the client id, the host, the engine and the day. The result reads: "ChatGPT sent someone on 12 September." No page URL, no cart, no order, no customer identity, and nothing that can be reversed into one.

The pixel is registered as analytics under Shopify's customer privacy settings, so it runs only where the visitor's analytics consent allows it, and it is marked as not selling data. The app sets no cookies of its own on your storefront.

Automated logs

The app keeps a technical log of each call it makes to an AI provider: the provider, model, token counts, whether it succeeded and how long it took, with your store as the key. These logs hold no product text and no personal data; they exist so we can see cost and failures. The hosting platform keeps ordinary request logs for a limited period.

Checks and answers

Scan history and scores; for the answer check, the shopping questions generated from your catalogue, the full text of each AI assistant's answer and the web addresses it cited; whether the app's page markup was detected on your storefront; and category-fit judgements.

Google Merchant Center

Connecting a Google Merchant Center account is optional. The connection is switched off in the current version and arrives in an update; when it is on, it works exactly as described here.

What you grant. When you choose to connect, Google's own consent screen asks you to allow the app to manage your product listings for Google Shopping (the https://www.googleapis.com/auth/content scope) and to see your Google account's email address. That permission would allow changes to your Merchant Center data. The app makes none: it only reads.

What the app reads from Google. The Merchant Center accounts your Google login can access (account ID and name), so you can pick the one linked to your store; and the status of each product in that account, including the issues Google reports for it: the issue code, its severity (for example disapproved or demoted), the destination it affects, Google's description, detail and suggested resolution, and the product attribute concerned.

What the app stores. The email address of the Google account you connected; a refresh token, encrypted, so a sync can run when you ask for one; the account you chose; each issue above with the product's offer ID and the Shopify product it matches; and the time of the last sync with counts of products and disapproved products. The other product data Google returns with each status, such as titles and prices, is read in memory to find the issues and is not stored.

How it is used. Only to show Google's issues next to the matching Shopify products, to count them in the product's score, and to report the number of disapproved products in your weekly digest. Data from Google is not sent to AI model providers, not shared with other merchants or anyone else, not used for advertising, not sold, and not used to train models. No person at Quantum Quotient LLC reads it, except with your permission to help you with a support request, for security, or where the law requires it.

How to remove it. Disconnecting in the app deletes the token and every stored issue at once, and uninstalling the app deletes them along with everything else. You can also revoke the app's access at any time at myaccount.google.com/permissions; after that the app cannot read anything more.

Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

The free public scanner

Anyone can enter a storefront address. We fetch what any visitor's browser can fetch, store the address and the public data returned, and show the result at a shareable link. We do not store the IP address of the person requesting a scan; a one-way hash is held in memory only, to limit abuse.

How we use it

To score your products, draft the fixes you asked for, apply the ones you approve, publish page markup through the embed you switch on, run the weekly answer check and digest, measure AI referrals, show the Merchant Center issues of an account you connect, and bill through Shopify. We use it for nothing else. We do not sell personal information, share your product data with other merchants, or use your catalogue to train models; the providers below are used through their APIs under terms that exclude training on API inputs.

Who else processes it

We use service providers to host the app and its database, to send the email you have asked for, to look up barcodes when you enable it, and to generate drafts and run the answer check through AI model providers. All of them process data in the United States under contracts that limit its use to providing our service, and the model providers' terms exclude training on the data we send. Shopify handles billing and sees only your subscription status.

What the AI model providers receive is limited to what the feature needs: for drafting, product titles, descriptions and the facts drawn from them; for the weekly answer check, your store's name and a shopper-style question. No provider receives customer data, because the app holds none.

A current list of these providers is available on request at support@qquotient.com.

Where the data lives

Quantum Quotient LLC is a United States company and processes data in the United States. If your store is in the European Economic Area, the United Kingdom or Switzerland, your product and store data is transferred to the United States to provide the service. We will sign standard contractual clauses as part of a data processing agreement on request.

How long we keep it

Uninstalling the app deletes everything. The app purges every record for your store when Shopify sends the app/uninstalled webhook, and again on Shopify's mandatory shop/redact webhook, which arrives 48 hours after an uninstall. The purge covers snapshots, drafts, scans, answer results, pixel rows, digests, logs, connections and workspace links, and is derived from the database schema so a table added later cannot be missed.

The app subscribes to all three of Shopify's compliance webhooks. Because it stores no customer personal data, customers/data_request and customers/redact have nothing to return or erase and are acknowledged as such; shop/redact is acted on immediately, well inside Shopify's 30-day requirement.

Public scan results are kept so their links keep working, and are deleted on request to the address below.

Your rights

Under the GDPR, the UK GDPR, the Colorado Privacy Act, the California Privacy Rights Act and comparable laws, you may request access to, correction of, or deletion of personal data we hold, object to processing, and complain to your supervisory authority. The fastest deletion is uninstalling the app, which erases everything automatically. Otherwise write to support@qquotient.com and we will answer within 30 days.

Security

Traffic is encrypted in transit and data is encrypted at rest by the database provider. Secrets, including any Google refresh token, are additionally encrypted with AES-256-GCM. Shopify access tokens are stored per store and used only for that store. Webhooks are verified against Shopify's signature and rejected otherwise. The public scanner validates every address it fetches and refuses private or internal network ranges.

Changes

Material changes will be announced in the app, and by email to merchants on the digest list, before they take effect.

Quantum Quotient LLC · Denver, CO, USA · support@qquotient.com