Privacy Policy
Last updated: 2026-09-05
CortexGuard ("the App", "we", "us") is a Shopify app that uses AI to enrich merchant product catalogs. This policy explains, at a high level, what data we work with, how we use it, where it is stored, and how it is deleted. It covers the CortexGuard Shopify App and the free public AI-visibility scanner at cortexcommerce.ai/scan. It is written to meet Shopify's App Store requirements and the GDPR.
Who we are
CortexGuard, a CortexCommerce product, is operated by JTS Tech Services, based in Maple, Ontario, Canada. Company and contact details are at jtstechservices.ca.
For the information described in this policy, we are the controller — we decide what is collected and why. Where we act on a merchant's instructions to update their own store catalog, we act as their processor.
For privacy questions, data requests, or to exercise any of the rights below, contact [email protected].
What data we work with
- Product-catalog data — the titles, descriptions, images, and related fields that make up a store's products. This is the information the App reads, enriches, and writes back.
- Store-related information we receive when you register — the account and store details Shopify provides when you install the App, including contact details for the store owner, together with the secure credentials needed to update your catalog on your behalf. We keep this to what we need to run the account.
- Aggregate storefront traffic counts — visits per product, broken out by referral source (such as search, social, or AI assistants), collected via a lightweight first-party pixel on the merchant's storefront. These counts are aggregate and never identify an individual visitor.
The product information we work with is already publicly visible on a merchant's online store, so the data we handle is low-sensitivity by design.
Data we do NOT access or store
In the Shopify App, CortexGuard does not request, access, or store your end customers' personal information — their names, email addresses, shipping addresses, orders, or payment data. The App works with merchant product-catalog data only.
How we use data
- AI enrichment. Product details and the merchant's brand profile (voice, tone, examples) are processed by leading large language models to generate improved titles, descriptions, tags, and SEO content.
- Review & write-back. Generated content is stored for the merchant to review and approve, then written back to their Shopify catalog. Merchant-locked fields are never modified. Merchants who switch on automation choose the confidence threshold and limits under which content publishes without a further review step; automation is off unless the merchant turns it on.
- How we contact you. We use the contact details we received at registration to email you about the service — a welcome note when you install, occasional service or account messages, and, if you uninstall, a single follow-up about coming back. You can tell us to stop at any time by replying to any of those messages or writing to [email protected].
- Usage billing. Billing is handled entirely by Shopify; we do not store any payment details.
We do not sell merchant data, and we do not use one merchant's data to train AI models or to benefit another merchant.
Public AI-visibility scanner (cortexcommerce.ai/scan)
Separate from the CortexGuard Shopify App, we offer a free, no-account scanner at cortexcommerce.ai/scan. Anyone can submit a public store URL and receive a 0–100 score of how AI crawlers see that storefront.
What we collect
- Measurements of publicly reachable storefront pages (the same HTML, robots, and discovery files an AI crawler would fetch). We do not ask for a store password, admin credentials, payment data, or a customer list.
- If you opt in, a contact email so we can send the report link or complete an email-gated full-catalog crawl. You may also give a first name and company. Those contact fields are never shown on the shareable /scan/r/{id} report.
- Technical request metadata used only to rate-limit abuse (not used to build a marketing profile).
How we use it
- To run the scan, show and email the report, and (if you asked) continue a full-catalog crawl.
- To follow up about CortexCommerce products when you submitted a contact email.
- We do not sell this information.
Retention and deletion
Scan reports are kept so shared permalinks keep working. Contact details you opted in with can be deleted on request — email [email protected].
Cookies and analytics
Our public web pages use a small number of cookies for basic analytics — to count visits and understand which pages are useful. They are not used to build advertising profiles or to identify you personally, and you can block or clear them at any time in your browser. The CortexGuard app itself and the storefront traffic pixel on a merchant's own store set no cookies of ours.
Sub-processors
To run the service we rely on a small number of trusted providers, by category:
- Shopify — the platform your store runs on, and our billing processor.
- A leading cloud infrastructure provider — secure hosting and storage.
- Established AI providers — content generation. Data is processed under their terms and is not used to train their models.
- An email delivery provider — sending the service messages described above.
We keep this list at the level of categories so that it stays accurate as tooling changes. If you need the specific providers named — for example for a vendor-security review — email [email protected] and we will provide the current list.
Where data is stored, and international transfers
Merchant App data is stored securely in the United States, kept separate and isolated for each merchant so that one merchant can never access another's. Public-scanner reports and any opt-in contact email you submit on /scan are also stored in the United States.
If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your region. We make those transfers under the appropriate safeguards offered by our providers, including standard contractual clauses where they apply.
Data retention and deletion
- On uninstall (app/uninstalled): the merchant record is marked uninstalled immediately and all tenant data is scheduled for hard deletion 48 hours later.
- GDPR shop/redact (sent by Shopify ~48 hours after uninstall): triggers a full, permanent deletion of all stored product and settings data. If the merchant has reinstalled the App before this webhook fires, deletion is skipped and their data is retained.
- GDPR customers/data_request and customers/redact: because we store no end-customer personal data, there is nothing to return or erase; these requests are acknowledged and logged.
- Scan reports are retained so that shared permalinks keep working, and any contact email submitted on /scan is retained until you ask us to delete it.
Merchants may request deletion at any time by uninstalling the App or by contacting [email protected].
Security
We follow industry-standard security practices: data is encrypted in transit, access is authenticated and scoped to each merchant, all platform requests and webhooks are cryptographically verified, and credentials are held in secure managed storage. Each merchant's data is isolated so that one merchant can never access another's.
Your rights
Wherever you are, you may ask us to give you a copy of the personal data we hold about you, correct it, delete it, or stop using it for a particular purpose — including opting out of our service and product messages. Contact [email protected] and we will respond within the time your local law allows.
Depending on where you live, those rights come from the GDPR and UK GDPR (Europe and the UK), PIPEDA (Canada), or state privacy laws such as the CCPA (United States). We do not sell personal information under any of them.
If you are in the EEA or the UK and you are not satisfied with how we have handled your request, you have the right to complain to your local data protection supervisory authority.
Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected by the "Last updated" date above and, where required, communicated to merchants.