1. Overview
This Privacy Policy describes how Banify Apps ("Banify", "we", "us", or "our") collects, uses, and protects information when you install and use the Banify: AI Visibility & LLMs.txt Shopify application ("the App").
By installing and using the App, you agree to the collection and use of information as described in this policy. If you do not agree with any part of this policy, please uninstall the App from your Shopify store.
2. Who We Are
Banify Apps is a Shopify app development company. We build tools that help Shopify merchants grow their stores.
- Website: banifyapps.io
- Email: [email protected]
- Support: [email protected]
3. Data We Collect
The App collects the minimum data necessary to provide the LLMs.txt generation service.
3.1 Merchant Data (Store Owner)
| Data | Source | Purpose |
|---|---|---|
Shopify shop domain (e.g., yourstore.myshopify.com) | Shopify OAuth | Identify and authenticate your store |
| Store name, owner name, email address | Shopify Admin API | Display in app dashboard and include in LLMs.txt file |
| Store country, currency, timezone | Shopify Admin API | Include in LLMs.txt store overview section |
| Shopify plan name | Shopify Admin API | Displayed in app for informational purposes only |
| Access token (encrypted) | Shopify OAuth | Authenticate API calls to read store data |
3.2 Store Content Data
| Data | Purpose |
|---|---|
| Product titles, handles, types, tags, prices | Generate the Products section of LLMs.txt |
| Product descriptions (body HTML, stripped to text) | Generate llms-full.txt detailed product entries |
| Collection titles, handles, descriptions | Generate the Collections section of LLMs.txt |
| Store page titles and handles (About, Contact, FAQ) | Generate About, Contact, FAQ sections |
| Shipping and refund policy URLs | Generate the Shipping & Returns section |
| Blog post titles and handles | Generate the Blog & Guides section (Pro plan) |
3.3 App Usage Data
| Data | Purpose |
|---|---|
| Store description (entered in Step 2) | Stored per-store and included in LLMs.txt header |
| Store category selection | Stored per-store and included in LLMs.txt |
| Section toggle preferences (on/off for 11 sections) | Stored per-store to control what is included in LLMs.txt |
| Generated LLMs.txt content | Stored in database to serve files at your domain URL |
| Generation timestamps and word counts | Displayed in Generation History log on Dashboard |
3.4 Data We Do NOT Collect
- Customer personal data (names, emails, addresses, phone numbers)
- Order data, transaction records, or payment information
- Customer browsing behavior or analytics
- Any data from your customers interacting with your storefront
- Passwords or payment card information of any kind
4. How We Use Your Data
We use the data we collect for the following purposes only:
- LLMs.txt generation: Reading your store's products, collections, and pages to build your LLMs.txt and llms-full.txt files
- File serving: Storing the generated file content in our database to serve it at
yourstore.com/llms.txtvia Shopify App Proxy - App functionality: Storing your preferences (section toggles, store description, category) so they persist between sessions
- Support: Using your store domain and email to respond to support requests if you contact us
- Security: Verifying Shopify HMAC signatures on all requests to protect your store data
We do not use your data for advertising, marketing profiling, data brokerage, or any purpose not listed above.
5. Data Storage & Security
Where data is stored
Your data is stored in our secure database hosted on cloud infrastructure. Our servers are located within the European Union / United States (depending on your region). All data is encrypted at rest using AES-256 and in transit using TLS 1.2 or higher.
Access token security
Your Shopify access token is stored encrypted in our database. It is used only to make authenticated Shopify Admin API calls when you trigger a generation. Tokens are never exposed in logs, error messages, or to any third party.
Security measures
- All API endpoints require verified Shopify HMAC signature validation
- Access tokens are encrypted at rest
- HTTPS enforced on all connections
- Database access restricted to application servers only
- Regular security audits and dependency updates
6. Data Sharing & Third Parties
We do not sell, rent, or trade your data with any third party.
We use the following third-party services to operate the App:
| Service | Purpose | Data shared |
|---|---|---|
| Shopify | Platform authentication and API access | Required by Shopify for all app integrations |
| Anthropic Claude API | AI Generate button — writing your store description | Store name, category, product count. No customer data. |
| Cloud hosting provider | Application and database hosting | Encrypted data stored per their privacy policy |
| Crisp Chat | Customer support chat widget | Only if you initiate a chat — your store domain and message |
7. Shopify Store Data Usage
Banify accesses your Shopify store data through the Shopify Admin API using the permissions you approve during installation. We comply with Shopify's API Terms of Service and Shopify's Privacy Policy.
Read-only access
Banify only uses read permissions for your store content. We never create, modify, or delete your products, collections, orders, customers, or any other store data.
Scope of access
See the Data Banify Accesses section of our User Manual for a full list of permissions and why each is needed.
When you uninstall
When you uninstall the App, Shopify revokes our access token immediately. We receive an APP_UNINSTALLED webhook and process it within 24 hours to mark your store as uninstalled in our database. Your store data (generated LLMs.txt content, preferences) is retained for 90 days after uninstall to allow reinstallation without re-onboarding, then permanently deleted.
8. Cookies
The Banify app itself (running inside Shopify admin) does not use cookies beyond what Shopify requires for session management. Shopify handles all session cookies as part of its embedded app framework.
Our marketing website at banifyapps.io may use cookies for analytics (e.g., visitor counts). No cookies from the App are ever placed on your customers' browsers.
9. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Right to access: Request a copy of the data Banify holds about your store
- Right to correction: Request correction of inaccurate data
- Right to deletion: Request deletion of your store's data (note: uninstalling the App triggers deletion after 90 days; you can request immediate deletion by contacting us)
- Right to data portability: Request your generated LLMs.txt content in a readable format
- Right to object: Object to any use of your data beyond operating the App
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
GDPR (EU Merchants)
If you are based in the European Union, you have additional rights under the General Data Protection Regulation (GDPR). Banify acts as a data processor on your behalf when processing Shopify store data. You (the merchant) are the data controller for your store's content.
CCPA (California Merchants)
If you are a California resident, the California Consumer Privacy Act (CCPA) may apply. We do not sell personal information. California residents may request disclosure of personal information collected and deletion of personal information. Contact us at [email protected].
10. Data Retention
| Data type | Retention period |
|---|---|
| Store profile data (domain, name, description, preferences) | While app is installed + 90 days after uninstall |
| Generated LLMs.txt content | While app is installed + 90 days after uninstall |
| Generation history logs | While app is installed + 90 days after uninstall |
| Access token | Revoked by Shopify immediately on uninstall |
| Support communications | 2 years from last contact |
After the retention period, all data is permanently and irreversibly deleted from our systems.
11. Children's Privacy
The Banify App is a business tool intended for use by Shopify merchants who are 18 years of age or older. We do not knowingly collect personal information from children under the age of 13. If you believe we have inadvertently collected such information, contact us immediately at [email protected].
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page
- Notify active merchants via email (to the store owner email on file)
- Show a notice inside the Banify app dashboard
Continued use of the App after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
13. Contact Us
For any questions, concerns, or requests regarding this Privacy Policy or your data:
- 📧 Privacy: [email protected]
- 📧 General: [email protected]
- 💬 Live Chat: banifyapps.io/pages/contact
- 🌐 Website: banifyapps.io
We aim to respond to all privacy-related requests within 5 business days.