Privacy Policy
Last updated: 15 July 2026.
Data Protection
As a rule, it is possible to use our website without entering your personal data. In so far as personal data (e.g. name, address or email addresses) are collected on our pages, then this is always done as far as possible on a voluntary basis. Should you provide such data, it will not be passed on to third parties for marketing purposes without your explicit agreement.
We draw your attention to the fact that the transmission of data on the internet (e.g. in the course of communication per e-mail) can be subject to security vulnerabilities. Absolute protection of data from access by third parties is not possible.
This Privacy Policy describes how ACE (Agentic Commerce Engine) collects, uses and discloses information, and what choices you have with respect to the information.
Our Commitment to Privacy
Your privacy is important to us. To better protect you, we provide this Policy explaining our online information practices and the choices you can make about the way your information is collected and processed.
Please read our Privacy Policy carefully as it describes our collection, use, disclosure, retention and protection of your personal information. This Policy applies to our websites, applications, and services (collectively "the Sites"), as well as offline activities and services. If you do not agree with the terms, do not access or use the Services or Websites.
Where you provide us with your personal information, you agree that we may collect, store and use it (a) in order to perform our contractual obligations to you, (b) based on our legitimate interest for processing (e.g. for internal administrative purposes or for the detection or prevention of crime) or (c) based on your consent, which you may withdraw at any time.
By using the Sites or any of our services you consent to the privacy practices described in this Policy.
How We Collect Information
To the extent permissible under applicable law, we collect information about you when you:
- register to use our Sites or services (including registering for an account); this may include your name, address, email address, IP address and telephone number;
- place an order using our Sites or services; this may include your name, address, contact details, IP address and payment details;
- complete online forms, take part in surveys, or participate in interactive areas on our Sites;
- interact with us using social media; and
- contact us offline (e.g. by telephone, email or post).
We may also collect information from your devices and applications you use to access our Sites or services (e.g. device identification, location information, statistics on page views, your IP address, browsing history and web log information). We may do this using cookies or similar technologies.
When you visit or log into our website, we may collect: (1) Usage data (how you use our site); (2) Device information (IP address, browser type, operating system); (3) Personal data you provide (e.g. email, phone number).
How We Use Your Information
We use your information to:
- provide information and services that you have requested;
- provide, maintain, protect and improve our applications and services;
- manage and administer your use of our products and services;
- manage our relationship with you (e.g. customer services and support);
- monitor, measure, improve and protect our content, website and services;
- comply with our regulatory or legal obligations;
- detect, prevent, investigate or remediate crime or prohibited activities;
- contact you for customer research or feedback;
- deliver targeted advertising, marketing or information which may be useful to you; and
- communicate with you, including personalised content based on your interests.
To the extent permitted by applicable law, we retain information about you after the closure of your account for as long as permitted for legal, regulatory, fraud prevention and legitimate business purposes.
AI-generated content
Agentic Commerce Engine generates product copy, SEO metadata, and JSON-LD structured data by sending your product information (title, description, attributes, images) to a third-party large-language-model provider. We display the generated content back to you and never publish it to your storefront until you explicitly approve each change.
We do notuse Merchant Data or Customer Data — including derived or aggregated data — to train any AI or machine-learning system. Per Shopify's Partner Program Agreement update (February 27, 2026), AI/ML training on such data is prohibited without explicit written consent, and we do not seek that consent.
Prompt and completion logs are retained only for the time needed to debug failed generations (currently 30 days) and are not shared with any party other than the model provider that processed the request. You can request deletion at any time by contacting support.
Data Retention
We will retain your personal data in accordance with your instructions, our Terms of Service, and as required by applicable law. We may retain information pertaining to you for as long as necessary for the purposes described in this Privacy Policy, including after you have deactivated your account, for the period needed to pursue legitimate business interests, conduct audits, comply with legal obligations, resolve disputes and enforce our agreements.
We apply the following retention periods, enforced by automated deletion:
| Data | Retention |
|---|---|
| Account data (projects, products, content, settings) | Life of the account; deleted when you delete your account |
| Public audit reports and the email you provide to receive one | 12 months |
| AI crawler traffic events (hashed IP, user agent) | 13 months |
| Storefront experiment and content view events | 13 months (aggregated statistics are kept) |
| In-app notifications | 12 months |
| LLM prompt and completion debug logs | 30 days |
| Shopify webhook payloads | 14 days |
Sharing Your Information
We will not sell your personal information to third parties. We may share your information with:
- our service providers and agents who process information on our behalf;
- partners that help us provide you with applications, products and services;
- third parties used to facilitate payment transactions;
- regulators to meet our legal and regulatory obligations;
- law enforcement agencies to detect or prevent crime or prosecute offenders;
- any third party in the context of actual or threatened legal proceedings (e.g. in response to a court order);
- our professional advisors and auditors; and
- another organisation if we sell or buy any business or assets.
We will use commercially reasonable endeavours to ensure the confidentiality of your personal information. However, we cannot guarantee that your personal information will not be disclosed to third parties in all circumstances.
Our Commitment to Data Security
We have put in place appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect online. Each account holder is asked to create a unique password, which is required to access their account. It is each user's responsibility to protect the security of their login information. No guarantee can be made that your information will be secure from intrusions and unauthorised release to third parties.
Marketing
From time to time, we may use your information to contact you with details about our products and services which we feel may be of interest to you. You have the right at any time to stop us from contacting you for marketing purposes. Every email we send contains an unsubscribe link in its footer. You can also manage notification emails per project under Settings, then Notifications, or contact us to opt out.
Your Rights
If you are based within the EEA or another jurisdiction with similar data protection laws, you may have the right to:
- be told how we use your information and obtain access to your information;
- have your information rectified or erased or place restrictions on processing;
- object to the processing of your information (e.g. for direct marketing);
- data portability (receive your data in a structured, machine-readable format);
- withdraw consent where processing is based on consent; and
- lodge a complaint with your supervisory authority (e.g. the Information Commissioner's Office in the UK).
If you withdraw your consent, we may not be able to provide you with access to all or parts of our website, applications, and services.
Cookies and Analytics
Cookies are small text files transferred from our websites and stored on your device. On ace.authoritas.com we set only strictly necessary first-party cookies: the authentication cookies that keep you signed in. We do not use third-party analytics, advertising, or tracking cookies on this site, which is why we do not show a cookie consent banner (strictly necessary cookies are exempt from the consent requirement). When we protect public forms against abuse we store a salted hash of your IP address; the raw address is never stored.
For the full list of cookies, including the first-party cookie the optional ACE experiment script can set on a merchant's own storefront, see our Cookie Policy.
Children's Privacy
We never knowingly collect or maintain information from those we know are under the age of 16, and no part of our website is structured to attract anyone under 16.
Other Websites
Our Sites may contain links to other websites. When you click on these links, you are entering another website over which we have no control. We encourage you to read the privacy statements on all such websites.
Changes to This Policy
We reserve the right to change this Policy without notice at any time. If we make changes, we will post a new policy on our Site and update the "last updated" date. The updated Policy will be effective immediately. We recommend that you check the Policy prior to using our Sites.
Shopify-specific data handling
When you install Agentic Commerce Engine ("ACE") from the Shopify App Store or open it from the embedded Shopify admin, ACE acts as a "Data Processor" for your Shopify merchant data under UK GDPR and EU GDPR. You remain the "Data Controller".
What we read from your Shopify store
ACE reads, on your behalf, the minimum data needed to enhance product detail pages and surface them in AI search:
- Products — title, description, vendor, product type, handle, tags, status, SEO settings, category, collection memberships, variants, options, and media URLs.
- Product metafields in the
seo,ace_*, and any custom namespaces you author against. We never read metafields from other Shopify apps' namespaces. - Shop profile — store name, primary domain,
myshopify.comdomain, contact email, currency, plan name, IANA timezone. Used only to identify your store inside ACE and address you correctly in any communications.
ACE does not read orders, customers, draft orders, checkouts, inventory levels, locations, files, or themes.
What we write to your Shopify store
ACE writes only after you click "Approve" on a suggestion in the review queue. Writes are limited to a product's title, body description, SEO title and description, tags, and metafields in our own ace_* namespace plus a single seo.json_ld metafield that powers search-result structured data on your storefront. Variant pricing, inventory, fulfilment, and customer-facing settings are never modified.
How your store is authenticated
ACE uses Shopify's recommended Token Exchange flow to obtain an offline access token scoped to read_products, write_productsonly. The token is encrypted at rest using AES-256-GCM with a key managed in our hosting provider's environment configuration, and is never logged or written to client-side storage.
Webhooks we subscribe to
customers/data_request,customers/redact,shop/redact— mandatory GDPR support.customers/redactis acknowledged but ACE does not store customer data, so nothing needs to be deleted.shop/redacttriggers permanent deletion of the store row, access token, and all enrichment history within 48 hours.app/uninstalled— deactivates the store record, discards the access token, and stops all processing.products/create,products/update,products/delete— refreshes the review queue for affected products. Payload retained up to 14 days for delivery audit, then purged.
Every webhook delivery is verified with HMAC-SHA256 against our app secret. Tampered or unsigned requests are rejected.
What happens when you uninstall
Within seconds of Shopify firing app/uninstalled, ACE sets the store record to inactive, discards the encrypted access token, stops in-flight enrichment jobs, and expires queued webhook deliveries. Catalog history (enrichment suggestions, AI prompt logs you generated during your active subscription) is retained for 30 days to support audit and chargeback windows, then permanently deleted. You can request immediate deletion by emailing the contact address on our website with your .myshopify.com domain.
Sub-processors that may see Shopify data
- Vercel Inc. — application hosting and edge network. Sees product data in transit and encrypted access tokens at rest.
- Supabase Inc. — managed PostgreSQL and authentication. Stores product metadata, encrypted access tokens, and enrichment history.
- Inngest, Inc. — background job queue. Receives webhook payloads with a 14-day retention.
- OpenAI, Anthropic, and Google — large language model inference for content generation. Receive product titles, descriptions, and prompts derived from them. Per their enterprise agreements, this data is not used for model training.
- Resend, Inc. — transactional email delivery. Receives recipient email addresses and the rendered content of the emails we send you.
- Langfuse (self-hosted) — LLM observability, run on our own infrastructure at an Authoritas-internal domain. Receives the prompts and completions of content-generation requests for debugging.
- Authoritas (Analytics SEO Ltd) — AI search visibility data. Receives store domains, brand names, and research queries; never account credentials.
- Oxylabs — proxy network used to fetch publicly available storefront pages during audits and catalog analysis. Receives only public URLs.
- Cloudflare, Inc. — Turnstile bot protection on public forms. Processes your IP address to distinguish humans from bots.
- Amazon Web Services — object storage for uploaded feed files and, where configured, CDN log analysis for AI crawler analytics.
We do not share Shopify merchant data with advertisers, data brokers, or any party outside this list. For the processor relationship, international transfer safeguards, and the full sub-processor table, see our Data Processing Addendum.
Sales tax, billing, and PII
ACE bills via Shopify's recommended billing API. Billing identifiers (charge IDs, plan name) are kept for the period required by UK tax law (currently 6 years). No payment-card data is ever transmitted to or stored by ACE — Shopify handles payment in full.
Data Protection Contact and Requests
ACE is operated by Rezolve Ai Limited, 21 Sackville Street, London W1S 3DN, England. To exercise any of your rights (access, rectification, erasure, portability, restriction, or objection), or for any question about this Privacy Policy, contact our data protection team at DPM@rezolve.com. We respond to verified requests within 30 days.
You can exercise the most common rights directly in the product: Settings, then Data & Privacy lets you export a complete copy of your data and permanently delete your account.
We do not sell your personal information, so no "Do Not Sell or Share" opt-out is required under California law.