Privacy Policy
Last updated 7 August 2026
Summary
RankBoost AI reads your store's product, collection, page and blog content in order to find SEO problems, generates replacement text with AI, and writes the changes you approve back to Shopify.
It does not request, receive or store customer or order data of any kind. The app's access scopes cover products, collections, online store pages, blog content, files and translations only.
Data we access from your store
When you install the app, Shopify grants it the following scopes. Each is used for one specific purpose:
- read_products, write_products: read product and collection titles, descriptions and metafields to detect SEO issues, and write approved meta titles, descriptions and JSON-LD schema back.
- read_content, write_content: read and update blog article SEO fields.
- read_online_store_pages, write_online_store_pages: read and update page SEO fields.
- write_files: update image alt text.
- read_translations, write_translations: read translatable SEO content and register translations, for stores using multi-language SEO.
No scope granting access to customers, orders, checkouts, payments or financial data is requested, and the app cannot read that data.
Data we store
We keep only what the app needs to function:
- Your shop domain and Shopify access token, so the app can call the Admin API on your behalf.
- SEO issues found by a scan, the AI-generated suggestions for them, and whether you applied each one.
- Your settings: scan schedule, tracked keywords, report preferences and plan.
- Billing state synced from Shopify: your plan, billing period and AI fix usage. We never see or store your payment details; Shopify handles all payments.
- If you connect Google Search Console, the OAuth refresh token for that connection, plus the click, impression and position figures returned for your own site.
- If you supply your own OpenAI API key, that key, encrypted at rest with AES-256-GCM.
How AI is used
To generate a fix, the app sends the relevant content (for example a product title, its description and its current meta tags) to OpenAI's API, which returns suggested replacement text. Only the content needed for that specific suggestion is sent.
OpenAI states that data submitted through its API is not used to train its models. Suggestions are stored against the issue in our database so you can review them before applying, and nothing is written to your store until you approve it.
If you provide your own OpenAI API key in Settings, requests are billed to your OpenAI account instead of ours. Your key is encrypted before storage and is never shown in full again after you save it.
Sub-processors
- OpenAI: generates the suggested SEO text, as described above.
- Amazon Web Services: hosts the application, database and job queue in the US East (N. Virginia) region.
- Google: only if you choose to connect Google Search Console, to retrieve your own site's search performance data.
We do not sell your data, and we do not share it with anyone else.
Data retention and deletion
When you uninstall the app, Shopify sends an app/uninstalled webhook and we immediately delete the stored session and access token for your shop.
We also implement Shopify's three mandatory compliance webhooks. On shop/redact, which Shopify sends 48 hours after uninstall, all remaining data for your shop (scans, issues, suggestions, settings, keywords and reports) is permanently deleted.
You can request deletion at any time before that by emailing contact-us@gettheapp.io.
Security
- All traffic is served over HTTPS with TLS.
- Shopify webhooks are verified using HMAC signatures; requests that fail verification are rejected.
- Secrets are held in AWS Secrets Manager, not in source control.
- Merchant-supplied OpenAI keys are encrypted at rest with AES-256-GCM.
- The database is not publicly accessible and is reachable only from the application's own private network.
Your rights
You may ask us what data we hold about your shop, ask for it to be corrected, or ask for it to be deleted. Email contact-us@gettheapp.io and we will respond within 30 days.
Changes to this policy
If this policy changes materially, the date at the top of this page is updated and, where the change affects how your data is used, we notify you in the app.
Contact
RankBoost AI: contact-us@gettheapp.io