1. Introduction
AllSteps.ai ("AllSteps", "we", "our", "us") values your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights. By installing and using our Shopify app, you agree to this Policy.
2. Information We Collect
We collect only the minimum data required to provide store analysis and optimization.
Store Data (via Shopify API scopes you authorize)
- Theme configurations
- Product information and descriptions
- Store content structure (blogs, pages, menus)
Analysis Data
- Performance metrics and optimization recommendations generated by our algorithms
Usage Data
- Feature usage, clicks, and in-app events to improve service quality
We do NOT collect
- Customer personal data (PII)
- Payment information
- Sensitive financial/business data not necessary for analysis
3. How We Use Information
- Analyze store performance and structure
- Generate personalized optimization recommendations
- Improve features, algorithms, and user experience
- Provide customer support when requested
We access data only through Shopify's APIs with scopes you grant at install and process it solely for authorized purposes in line with Shopify's API Terms.
4. Data Storage & Security
- Encryption in transit (HTTPS/TLS) and at rest
- Secure, industry-standard cloud infrastructure
- Role-based access controls and audit logging
- Data retained for 12 months or until app uninstallation (whichever is sooner)
- Upon uninstallation, all store-related data is deleted within 30 days
5. Data Sharing
We do not sell, rent, or trade your data. We may share data only:
- With your explicit consent
- To comply with law, regulation, or legal process
- In aggregated, anonymized form to improve services (no store can be identified)
Third-Party Services: We may use reputable cloud hosting, logging, and analytics providers that comply with applicable security and privacy standards. These providers process data solely on our behalf.
6. GDPR & CCPA
GDPR (EU/EEA)
- Role: You are Data Controller; AllSteps is Data Processor
- Rights: Access, deletion, portability, objection, restriction
- Privacy by design and appropriate technical/organizational measures
- Data Processing Addendum (DPA) available upon request
CCPA (California)
- We do not sell personal information
- Rights: Access, deletion, disclosure of categories of information collected
7. Your Rights & Controls
You may request at any time:
- Access – A copy/summary of data we store about your store
- Deletion – Erasure of stored data
- Portability – Export of analysis results
- Uninstall – Triggers deletion within 30 days
Contact us (Section 9) to exercise rights. We may verify your identity/authorization.
8. Cookies & Tracking
We may use cookies or similar technologies in the app dashboard to understand usage and improve the product. We do not track or collect your customers' personal data.
9. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at:
Email
hello@allsteps.ai
Support
https://allsteps.ai/support
10. Changes to This Policy
We may update this Policy as our services or laws change. Material changes will be communicated in-app or by email. Continued use constitutes acceptance.