Privacy Policy

Last updated: 8 September 2026

Visora ("the app", "we") audits Shopify stores for SEO, performance and AI-search readiness. This policy explains what the app collects, why, who else processes it, and how to have it deleted.

The data controller is Ivan Gordiichuk, Kyiv, Ukraine. Contact: support@seo-assistant.app.

What the app collects

Store identity and settings. Your .myshopify.com domain, Shopify shop ID, store name, primary domain, country, currency and timezone. Read from Shopify when the app is installed and refreshed periodically.

Staff account details from Shopify. When you authenticate, Shopify provides the name, email address, locale and account-owner flag of the staff member signing in. This is stored as part of the session so the app knows who is using it. We do not ask for it separately and cannot see staff who never open the app.

Theme files. The app reads the published theme's Liquid templates, JSON settings and assets through Shopify's Theme Asset API in order to report problems with file and line references. Files are read only — the app never writes to your theme. Contents are held only for the duration of an audit and are not stored afterwards; only the findings are.

Audit results. For each page you track: the URL, Lighthouse and Chrome UX Report scores, the issues found, and a snapshot of the analysis. Kept so the app can show change over time.

Support requests. If you use the in-app support form: your message, the email address you give for a reply, the audit issues you attach, and an optional four-digit Shopify collaborator request code. The code lets us ask Shopify for access to your store; you still approve the request and choose the permissions.

Usage counters. How many page checks and AI analyses you have run this month, so plan limits can be enforced.

What the app does not collect

The app requests no access to customers, orders, payments or checkout, and the access scopes it holds make that technically impossible. Specifically it holds read_themes, read_products, read_content and read_online_store_pages, and nothing else.

It therefore never receives, stores or processes:

Who else processes your data

ProcessorWhat it receivesWhen
Google (PageSpeed Insights API) The public URL of the page being audited Every audit
Resend Your notification email address and the message body When the app emails you
Anthropic (Claude) Public page text: titles, meta descriptions, headings, body copy Only if you enable AI analysis
OpenAI The questions you choose to track Only if you enable AI visibility
Sentry (error tracking) Error reports: what failed, on which page, and your store’s .myshopify.com domain — never page content, tokens, or customer data Only when something in the app breaks
Hostinger (VPS hosting) All stored data — this is where the database runs Always

Data is stored on a virtual private server operated by Hostinger in Phoenix, Arizona, United States. If your store is in the EEA or the United Kingdom, your data is therefore transferred to and held in the United States. Write to the address above if you want to know more about that transfer before installing.

AI analysis is off by default. Nothing is sent to Anthropic or OpenAI until you turn it on in Settings, where the disclosure lists exactly what would be sent. Turning it off stops all such calls immediately.

Only public storefront content is ever sent to an AI provider — the same text any visitor or search engine can read. Theme source code, store settings and support request contents are not.

How long data is kept

Audit history is trimmed automatically on a daily sweep, according to your plan:

PlanAudit history kept
Free60 days
Starter180 days
Pro365 days
EnterpriseKept until you delete it

Support requests and store settings are kept while the app is installed.

Deletion

When you uninstall, Shopify sends a shop redaction request 48 hours later. On receiving it the app hard-deletes the store record, and every audit, issue, snapshot, page profile, schedule, support request and session belonging to it, in a single cascading delete. Nothing is retained in a backup copy beyond 30 days of daily database backups.

Customer data requests and erasure. Shopify also sends customers/data_request and customers/redact webhooks. The app answers both, and the answer is the same in each case: it holds no customer data to return or erase. The requests are logged for audit purposes without recording any personal data from them.

On request at any time. Write to support@seo-assistant.app and we will delete your data without waiting for an uninstall.

Your rights

If you are in the EEA, the UK or another jurisdiction with equivalent law, you have the right to access, correct, export or erase the personal data described above, and to object to its processing. Write to support@seo-assistant.app; we respond within 30 days.

The lawful basis for processing is performance of the contract between us — the app cannot audit a store without reading it — except for AI analysis, which rests on your explicit, revocable consent.

Cookies

The app sets session cookies required for Shopify OAuth and for running inside the Shopify admin. It sets no advertising or analytics cookies and does not track you across sites. This website sets no cookies at all and loads nothing from third parties.

Security

Data is transmitted over TLS and stored in a database that is not publicly reachable. Shopify access tokens are stored so scheduled audits can run without you being present; they are scoped to the four read-only permissions above.

Children

The app is a business tool and is not directed at anyone under 16.

Changes

Material changes will be announced in the app before they take effect. The date at the top shows when this document last changed.