Privacy Policy
Last updated: February 2026
Overview
ApiMate ("we", "our", "us") provides AI-powered Shopify store management. This Privacy Policy describes how we collect, use, and protect your information when you use our platform. By using ApiMate, you agree to the practices described below.
Data We Collect
We collect the following categories of information to provide and improve our services:
Account Information
- Name and email address
- Company name (optional)
- Billing information for paid plans
- Profile preferences and settings
Usage Data
- Commands and interactions with our AI
- Platform integrations and connection status
- Feature usage and performance metrics
- Error logs and diagnostic information
Integration Data
- API tokens and authentication credentials (encrypted)
- Data necessary to execute your commands
- Webhook data for real-time synchronization
- Platform-specific configurations
How We Use Your Information
- Process your commands and manage Shopify integrations
- Send service updates and important notifications
- Analyze usage to enhance features and performance
- Provide customer support and troubleshoot issues
- Ensure security and prevent unauthorized access
AI Technology & Data Processing
ApiMate uses AI for natural language processing and command interpretation. AI generates responses and action suggestions only. No automated decision-making occurs without your approval.
Data Processed by AI
- Your chat messages and commands
- Store data needed to fulfill your requests (products, orders, inventory)
- Context necessary for accurate AI responses
- AI does not store or learn from your personal data
How Your Prompts Are Handled
- Prompts are processed in real-time and not stored for AI training
- We do not use Merchant Data or Customer Data (including derived or aggregated data) for training, development, or improvement of AI or machine learning models
- Conversation history stored securely at shop-level for your convenience
- No customer PII is persistently stored by the AI system
- You can request deletion of conversation history at any time
Human-in-the-Loop Approval
All store modifications require your explicit approval. The AI suggests actions but cannot execute changes without your consent.
- Clear approval cards show exactly what will change before execution
- You can approve or reject each proposed modification
- All changes are logged and can be reverted if needed
- Read-only operations (viewing data) do not require approval
Merchant & Customer Data Protection
We are committed to protecting the data of Shopify merchants and their customers in accordance with Shopify's Partner Program Agreement and API License & Terms of Use.
- Merchant Data and Customer Data are used solely to provide the service you requested
- We do not use any merchant or customer data (including derived or aggregated data) for training, developing, or improving AI or machine learning systems
- We do not sell, share, or monetize merchant or customer data with third parties
- We do not engage in scraping, crawling, or unauthorized data mining of Shopify stores
- All data access is performed exclusively through official Shopify APIs with proper authorization
- Upon app uninstall, shop sessions are deactivated and access tokens are invalidated
Data Sharing
We do not sell your personal data. We may share information with:
- Shopify, to execute store operations on your behalf via official APIs
- AI service providers, to process natural language commands (no PII retained, not used for model training)
- Infrastructure providers, for hosting, analytics, and security
- Legal authorities, when required by law or to protect our rights
Data Protection & Security
- All data encrypted with TLS 1.3 (in transit) and AES-256 (at rest)
- Strict access controls and multi-factor authentication
- Regular security audits and vulnerability assessments
- Data minimization: we collect only what is necessary and delete when no longer needed
- OAuth-based authentication with Shopify. We never store your Shopify credentials
Data Retention
We retain your data for as long as your account is active or as needed to provide services. Conversation history is retained for 90 days by default. You may request deletion of your data at any time. Upon account deletion, we remove your personal data within 30 days, except where retention is required by law.
Your Rights
You have the right to:
- Access: request a copy of your personal data
- Correction: update inaccurate information
- Deletion: request removal of your data
- Portability: export your data in a machine-readable format
- Objection: opt out of certain data processing activities
To exercise these rights, contact us at info@apimate.chat.
Cookies
We use essential cookies to maintain your session and preferences. We do not use third-party advertising or tracking cookies. Analytics cookies may be used to understand usage patterns. These can be disabled in your browser settings.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes via email or through the platform. Continued use of ApiMate after changes constitutes acceptance of the updated policy.
Contact
For privacy-related questions, contact our team at info@apimate.chat.