Privacy Policy
Last updated: July 28, 2026
Pulse ("the app", "we", "us") is a Shopify app that connects to your store to provide AI-powered insights, workflows, and store actions. This policy explains what data we access, why, how it is processed, and your rights over it.
1. Who we are
Pulse is operated as an embedded Shopify app. We do not run a separate merchant login — your Shopify store is the identity, and the app runs inside your Shopify admin. For any privacy request, contact [email protected].
2. Data we access
When you install Pulse, Shopify grants us an offline access token scoped to the permissions you approve at install. Using that token we read store data required to power the app, which may include:
- Products, collections, and inventory
- Orders and order-level details
- Customer records associated with orders
- Store configuration and metadata (name, domain, settings)
We do not ask for or store merchant passwords. Authentication is handled entirely by Shopify via signed session tokens; we never see your Shopify login credentials.
3. How we use your data
- Generating insights, analytics, and recommendations for your store
- Running workflows and automations you configure
- Executing store actions you approve through the in-app AI agent (subject to your approval settings)
- Operating, maintaining, and improving the app
We do not sell your data, and we do not use it for advertising.
4. AI processing and sub-processors
To provide AI features, relevant store data may be sent to third-party AI model providers — currently Anthropic (Claude models) and OpenRouter (which routes to additional model providers). These providers process the data solely to return the model response and under their own data-processing terms. Billing and payments are handled entirely by Shopify through Shopify's native billing — we never receive or store your payment card details, and no store catalog or customer records are shared for billing.
5. Data retention and storage
Synced store data is stored in our database only as long as the app is installed and needed to provide the service. Shopify access tokens are expiring and refreshed automatically; if a token can no longer be refreshed it is cleared. Session tokens used per request are never stored.
6. Deleting your data
Uninstalling Pulse from your Shopify admin revokes our access token and stops all data access. To request deletion of any store data we have retained, email [email protected] and we will delete it in line with Shopify's data-retention requirements.
7. Your rights (GDPR / CCPA)
Depending on your jurisdiction, you may have the right to access, correct, export, or delete personal data we process, and to object to or restrict certain processing. To exercise any of these rights, contact us at [email protected]. We respond to verified requests within the timeframes required by applicable law.
8. Security
Access to store data is authenticated on every request using signed Shopify session tokens, and store data is scoped so that each store can only reach its own records. We take reasonable technical measures to protect data in transit and at rest.
9. Changes to this policy
We may update this policy as the app evolves or as required by law. The "last updated" date above reflects the most recent revision. Material changes will be reflected here.
10. Contact
Questions about this policy or your data? Email [email protected].