Legal
Privacy Policy
This Privacy Policy explains how AdexPilot collects, uses, shares, protects, and retains information when you visit our public website or use the AdexPilot ecommerce product intelligence platform, integrations, AI workflows, feed tools, billing, and support.
1. Scope and roles
This Policy applies to AdexPilot websites, applications, APIs, worker services, dashboards, support, billing flows, emails, and related services that link to this Policy.
For account, website, billing, security, and support information, AdexPilot generally acts as the business or controller. For store, shopper, product, feed, advertising, and connected provider data that a customer authorizes us to process, the workspace owner or merchant generally controls the data and AdexPilot processes it to provide the service. If you need a data processing agreement or an entity-specific contracting package, contact us.
2. Information we collect
We collect information you provide, information created when you use AdexPilot, information from integrations you authorize, and limited technical information from your browser or device.
Account, identity, and workspace information
- Name, email address, password hash or Google sign-in identity, account status, profile updates, and authentication source.
- Workspace, client, store, role, permission, invite, team member, admin note, and support-action details.
- Session metadata such as token hashes, expiration dates, user agent, IP address, last activity, password reset tokens, and email delivery records.
Shopify and commerce information
- Shopify app and shop identifiers, canonical shop domain, display domain, store name, store email if provided by Shopify, currency, installation state, granted scopes, scope hash, connection health, sync status, and webhook events.
- Shopify session and installation authentication metadata, including encrypted access and refresh tokens, token expiry, token generation, refresh status, and revocation or uninstall timestamps. We do not place access or refresh tokens in browser-visible URLs.
- Products, variants, collections, handles, titles, descriptions, tags, images, vendors, product types, SKUs, prices, compare-at prices, costs, inventory, and margin/economics fields.
- Order, refund, and sales facts needed for product performance, including order IDs or names, event times, line items, product or variant IDs, quantity, price, discount, fulfillment or refund status, currency, and value totals.
- Customer and order fields that Shopify classifies as protected customer data, only when Shopify has approved the access and the fields are necessary for the requested product, reporting, support, or compliance function. We treat those fields as protected customer data and do not use them for unrelated purposes.
- Reduced or hashed commerce-event context, such as checkout token hashes, cart token hashes, source URL hashes, consent snapshots, browser event links, and retention-delete timestamps.
- Shopify compliance webhook information, including app uninstall, customer data request, customer redact, and shop redact events.
Google Ads, Merchant Center, and feed information
- Google sign-in profile details when used for authentication, such as Google user ID, email, and name.
- Google Ads OAuth and account metadata, including external user IDs, account emails, customer IDs, account names, manager account IDs, currency, time zone, scopes, and encrypted tokens.
- Campaign, ad group, campaign criterion, budget, product listing, product performance, spend, click, impression, conversion, conversion value, ROAS, and related metrics.
- Merchant Center account IDs, Content API scopes, product items, data sources, diagnostics, feed labels, supplemental feed registration and verification status, feed artifacts, and provider feed verification results.
Meta and catalog information
- Meta OAuth profile and account metadata, including external user ID, account name or email if provided, businesses, ad accounts, permissions, currency, time zone, and encrypted tokens.
- Meta campaigns, ad sets, ads, insights, pixel or dataset readiness, catalog summaries, catalog item identities, product-set candidates, mapping confidence, and sandbox or production readiness data.
- Where enabled by a customer and supported by the product, conversion-event preparation data such as event name, event time, event ID, value, currency, content IDs, consent status, and hashed or reduced event-link data.
AI, recommendations, attachments, and automation information
- AI conversations, user messages, assistant responses, conversation summaries, titles, referenced entities, and archived status.
- Files uploaded for AI analysis, such as images, PDFs, CSVs, spreadsheets, JSON, or text files, plus file name, MIME type, size, extracted text, extracted JSON, storage key, status, and expiration where configured.
- Store intelligence, product intelligence, recommendations, action drafts, daily briefings, digests, memories, opportunities, approval packs, execution plans, action logs, and AI-generated explanations.
- AI usage metadata such as request type, model, provider, token counts, duration, success or failure, estimated cost, credits consumed, and related conversation or workspace IDs.
Billing, payments, credits, and pricing information
- Plan, subscription, billing cycle, entitlement, workspace billing profile, credit balance, credit ledger, usage meter, usage snapshot, coupon, promotion, and plan recommendation records.
- Shopify app-subscription and one-time-purchase identifiers, checkout-intent and catalog-version identifiers, charge name, amount, currency, billing interval, test or live status, approval and reconciliation state, cycle dates, trial or cancellation status, and timestamps.
- Shopify billing webhook identifiers, event times, status changes, reconciliation receipts, and redacted provider-payload digests used for security, idempotency, support, and audit. Shopify handles the merchant's payment method; AdexPilot does not store complete payment card numbers.
- Pricing experiment assignment and event data, including visitor IDs, user IDs, workspace IDs, plan keys, credit pack keys, and related metadata.
Website, device, analytics, and support information
- Pages viewed, CTA clicks, scroll-depth events, UTM parameters, landing-page variant, referrer, browser, device, IP-derived approximate location, and diagnostic logs.
- Cookies, local storage, session storage, and similar technologies for authentication, security, CSRF protection, analytics, attribution, pricing experiments, and preferences.
- Support emails, issue reports, screenshots or files you send to us, feedback, survey responses, and communications with us.
3. Sources of information
- You, workspace owners, admins, operators, approvers, viewers, invited users, and support contacts.
- Connected providers you authorize, including Shopify, Google Ads, Google Merchant Center, and Meta.
- Shopify's installation and app-billing systems, plus email, hosting, AI, analytics, and infrastructure providers that support the service.
- Automated analysis created by AdexPilot from connected store, feed, ad, billing, usage, and product data.
- Browsers, devices, cookies, logs, analytics tools, and security systems.
4. How we use information
- Create accounts, authenticate users, maintain sessions, route users to workspaces, and enforce roles and permissions.
- Connect, sync, normalize, join, and analyze Shopify, Google Ads, Merchant Center, Meta, feed, catalog, order, refund, inventory, cost, and product data.
- Provide dashboards, product performance views, feed tools, supplemental labels, diagnostics, recommendations, daily briefings, AI chat, reports, approvals, execution plans, and audit trails.
- Process billing, subscriptions, invoices, trials, credits, plan entitlements, payment events, usage metering, and pricing experiments.
- Maintain safety controls, prevent abuse, enforce limits, detect errors, debug syncs, protect accounts, preserve idempotency, and investigate suspicious activity.
- Communicate with you about account activity, onboarding, password reset, welcome messages, billing, support, product updates, security, and legal notices.
- Improve AdexPilot, test pricing and product experiences, measure marketing performance, conduct analytics, and develop new features.
- Comply with law, respond to valid requests, enforce our Terms, and protect AdexPilot, customers, providers, and the public.
5. AI processing
AdexPilot uses AI systems to summarize, classify, rank, explain, and recommend actions from business and ecommerce data. AI outputs may include store profiles, product profiles, recommendations, feed-label proposals, campaign drafts, digests, action plans, and assistant responses.
- Prompts may include the user question, selected workspace context, store intelligence, product data, ad performance, feed evidence, attachments, and prior conversation context.
- AdexPilot may send prompts, attachments, extracted text, and business context to configured AI providers such as Google Gemini or Vertex AI to generate outputs.
- We use AI outputs for decision support. They may be incomplete, delayed, or incorrect and should be reviewed before use.
- AdexPilot does not use customer data to train a general-purpose model owned by AdexPilot unless we tell you and obtain any required permission. Third-party AI providers process data according to their service terms, privacy terms, and any applicable enterprise commitments.
6. Cookies, analytics, and advertising choices
We use cookies and similar technologies for required service functions, including authentication, CSRF protection, fraud prevention, session continuity, pricing experiments, preferences, analytics, and attribution.
The public website may use analytics tools such as Google Analytics when configured. Connected store, shopper, product, feed, and provider data is not sold and is not used by AdexPilot for cross-context behavioral advertising. Some website analytics cookies may be treated as sharing or targeted advertising under certain laws; where legally required, we will honor applicable opt-out or consent controls.
7. How we share information
We share information only as needed to provide, secure, support, improve, bill for, or legally operate AdexPilot.
- With service providers and subprocessors for hosting, databases, storage, queues and caches, security, logging, email delivery, analytics, support, AI processing, and infrastructure.
- With connected providers when you authorize an integration or action, including Shopify, Google, Meta, Merchant Center, and similar services.
- With users inside your workspace according to roles, permissions, workspace settings, approval flows, and audit visibility.
- With Shopify to install and operate the app, verify the shop and granted scopes, create and reconcile app subscriptions and one-time purchases, add approved charges to Shopify billing, process app-billing webhooks, and support credits or refunds where available.
- With professional advisors, auditors, insurers, and legal or compliance representatives.
- In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to appropriate confidentiality or notice where required.
- When required by law, subpoena, court order, regulator request, provider compliance request, or to protect rights, safety, security, and integrity.
We do not sell connected store data, shopper data, product data, feed data, advertising data, or AI conversation data.
Service-provider and subprocessor inventory
Current code and deployment evidence identifies Shopify for installation and app billing; Google services, including Google Cloud, Vertex AI or Gemini, Google Ads, and Merchant Center, for configured infrastructure, AI, and connected-provider functions; Vercel for web hosting; Resend for configured transactional email; Meta for optional connected-provider functions; MongoDB- and Redis-compatible systems for data, queues, and caching; and Google Analytics or Microsoft Clarity when those optional public-site analytics features are enabled.
Optional providers are used only when the relevant feature is configured or authorized. This draft must not be published until AdexPilot confirms the exact production processor and subprocessor legal entities, products, regions, and purposes. The verified production inventory, rather than a development dependency or example environment variable, controls the final disclosure.
8. Google, Shopify, and Meta notes
Google API data
AdexPilot uses Google API data only to provide and improve user-facing features you request, such as sign-in, Google Ads analysis, Merchant Center diagnostics, feed verification, and product performance workflows. AdexPilot use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Shopify data
When a merchant installs AdexPilot, we use Shopify installation, session, token, scope, shop, product, feed, order, refund, inventory, economics, and performance information to authenticate the merchant and provide the service. For paid plans and credit packs, AdexPilot uses Shopify's manual Billing API flow to create charges and verify subscription or one-time-purchase status. Shopify processes the merchant's billing account and payment method; we receive the billing metadata needed to provide access, reconcile credits, prevent duplicate grants, and support billing questions. We also process Shopify customer data request, customer redact, shop redact, and uninstall webhooks according to Shopify requirements and applicable law. Shopify describes its processing in its Privacy Policy.
When Shopify reports a verified uninstall or credential revocation, AdexPilot stops new Shopify reads, writes, and scheduled work and stops using the installation credentials. Access- and refresh-token secrets are removed from active credential storage or rendered irreversibly unusable as soon as operationally safe. We may retain non-secret shop and installation identifiers, status, timestamps, billing references, and redacted audit evidence where needed for security, reconciliation, legal obligations, or dispute handling; we do not retain usable token secrets merely for audit or troubleshooting.
Uninstalling does not by itself delete the separate AdexPilot account or workspace. When Shopify sends a verified customer-redact or shop-redact request, AdexPilot deletes, de-identifies, or restricts the responsive personal data within the applicable Shopify deadline, except for records that must be retained by law. Account or workspace deletion can also be requested through the documented controls or at support@adexpilot.com.
Meta data
Meta data is used for account discovery, catalog readiness, product-set planning, performance analysis, sandbox testing, and, only where supported and authorized, controlled advertising workflows. Customers are responsible for Meta permissions, advertising policies, event consent, and production opt-in decisions.
9. Legal bases for EEA, UK, and similar users
Where a legal basis is required, we rely on one or more of the following bases:
- Contract performance to provide AdexPilot, support accounts, process billing, and deliver requested integrations.
- Legitimate interests to secure the service, prevent abuse, improve product quality, analyze usage, manage provider integrations, and operate our business.
- Consent where required for optional cookies, marketing, certain provider permissions, or optional communications.
- Legal obligations to maintain records, respond to lawful requests, process tax or accounting requirements, and comply with provider or platform obligations.
10. Data retention
We retain information for as long as reasonably needed for the purposes described in this Policy, including providing the service, maintaining security, honoring legal obligations, resolving disputes, enforcing agreements, preserving audit trails, supporting billing, and improving AdexPilot.
- Account and workspace records are generally retained while the account or workspace is active and for a reasonable period afterward.
- Provider connection records and sync metadata are retained while the integration is connected and as needed for audit, troubleshooting, security, and legal obligations. Usable access- and refresh-token secrets are retained only while needed for an authorized active connection or safe rotation; after verified disconnect, uninstall, or revocation, active secrets are deleted or rendered irreversibly unusable.
- Product, ad, feed, and commerce performance data may be retained to provide historical analysis, recommendations, reporting, and audit evidence.
- AI conversations, attachments, extracted text, generated outputs, and usage events may be retained to provide context, history, support, safety review, and billing or credit records. Attachments may also have expiration timestamps where configured.
- Billing, tax, payment, audit, idempotency, support, and security logs may be retained longer where required or reasonably necessary.
- Protected customer data is retained only as long as needed for the approved function and is subject to verified customer-redact and shop-redact requests.
- If an integration is disconnected or a deletion request is received, we delete, de-identify, or restrict applicable data unless retention is required for legal, billing, security, fraud-prevention, backup, audit, or dispute-resolution purposes. Any retained record is limited to what that purpose requires.
11. Security
We use administrative, technical, and organizational safeguards designed to protect information, including hashed passwords, hashed session tokens, HTTP-only cookies, secure production cookie settings, OAuth flows, encrypted provider tokens, workspace permission checks, CSRF protections, audit logs, idempotency controls, provider safety checks, and access restrictions.
No system is completely secure. You are responsible for protecting your credentials, managing workspace users, limiting provider permissions, and promptly notifying us of suspected compromise.
12. Your choices and rights
Depending on your location and relationship to AdexPilot, you may have rights to access, correct, delete, export, restrict, object to, or opt out of certain processing of personal information. You may also have the right to appeal a decision or use an authorized agent where applicable law allows.
- Account users can update some account and workspace information inside the app.
- Workspace owners and admins can manage team access, provider connections, billing, and workspace settings.
- You can revoke connected provider access through AdexPilot or directly through the provider where supported.
- You can control many cookies through browser settings. Some required cookies are necessary for the product to work.
- To make a privacy request, email support@adexpilot.com. We may need to verify your identity and authority before acting.
13. International transfers
AdexPilot and its service providers may process information in the United States and other countries where we or our providers operate. Those countries may have privacy laws that differ from your location. Where required, we use appropriate safeguards for cross-border transfers.
14. Children
AdexPilot is not directed to children and may not be used by anyone under 18. We do not knowingly collect personal information from children. If you believe a child provided information to us, contact support@adexpilot.com.
15. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the date above and may provide additional notice through the website, app, or email. Continued use of AdexPilot after an update means the updated Policy applies as permitted by law.
Contact us
Questions about privacy, security, provider data, or data requests? Email support@adexpilot.com.