CortexGuard

Privacy Policy

Last updated: 2026-09-05

CortexGuard ("the App", "we", "us") is a Shopify app that uses AI to enrich merchant product catalogs. This policy explains, at a high level, what data we work with, how we use it, where it is stored, and how it is deleted. It covers the CortexGuard Shopify App and the free public AI-visibility scanner at cortexcommerce.ai/scan. It is written to meet Shopify's App Store requirements and the GDPR.

Who we are

CortexGuard, a CortexCommerce product, is operated by JTS Tech Services, based in Maple, Ontario, Canada. Company and contact details are at jtstechservices.ca.

For the information described in this policy, we are the controller — we decide what is collected and why. Where we act on a merchant's instructions to update their own store catalog, we act as their processor.

For privacy questions, data requests, or to exercise any of the rights below, contact [email protected].

What data we work with

The product information we work with is already publicly visible on a merchant's online store, so the data we handle is low-sensitivity by design.

Data we do NOT access or store

In the Shopify App, CortexGuard does not request, access, or store your end customers' personal information — their names, email addresses, shipping addresses, orders, or payment data. The App works with merchant product-catalog data only.

How we use data

We do not sell merchant data, and we do not use one merchant's data to train AI models or to benefit another merchant.

Public AI-visibility scanner (cortexcommerce.ai/scan)

Separate from the CortexGuard Shopify App, we offer a free, no-account scanner at cortexcommerce.ai/scan. Anyone can submit a public store URL and receive a 0–100 score of how AI crawlers see that storefront.

What we collect

How we use it

Retention and deletion

Scan reports are kept so shared permalinks keep working. Contact details you opted in with can be deleted on request — email [email protected].

Cookies and analytics

Our public web pages use a small number of cookies for basic analytics — to count visits and understand which pages are useful. They are not used to build advertising profiles or to identify you personally, and you can block or clear them at any time in your browser. The CortexGuard app itself and the storefront traffic pixel on a merchant's own store set no cookies of ours.

Sub-processors

To run the service we rely on a small number of trusted providers, by category:

We keep this list at the level of categories so that it stays accurate as tooling changes. If you need the specific providers named — for example for a vendor-security review — email [email protected] and we will provide the current list.

Where data is stored, and international transfers

Merchant App data is stored securely in the United States, kept separate and isolated for each merchant so that one merchant can never access another's. Public-scanner reports and any opt-in contact email you submit on /scan are also stored in the United States.

If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your data is transferred outside your region. We make those transfers under the appropriate safeguards offered by our providers, including standard contractual clauses where they apply.

Data retention and deletion

Merchants may request deletion at any time by uninstalling the App or by contacting [email protected].

Security

We follow industry-standard security practices: data is encrypted in transit, access is authenticated and scoped to each merchant, all platform requests and webhooks are cryptographically verified, and credentials are held in secure managed storage. Each merchant's data is isolated so that one merchant can never access another's.

Your rights

Wherever you are, you may ask us to give you a copy of the personal data we hold about you, correct it, delete it, or stop using it for a particular purpose — including opting out of our service and product messages. Contact [email protected] and we will respond within the time your local law allows.

Depending on where you live, those rights come from the GDPR and UK GDPR (Europe and the UK), PIPEDA (Canada), or state privacy laws such as the CCPA (United States). We do not sell personal information under any of them.

If you are in the EEA or the UK and you are not satisfied with how we have handled your request, you have the right to complain to your local data protection supervisory authority.

Changes to this policy

We may update this policy as the App evolves. Material changes will be reflected by the "Last updated" date above and, where required, communicated to merchants.