Legal
Privacy Policy
What Burnish reads from your Shopify store, what it keeps, who else touches it, and how to get it deleted.
Last updated August 14, 2026
Contents
Documents
Contents
Documents
Burnish (“we”, “our”, “the app”) is a Shopify embedded application operated by Luqman Ifrene. This policy explains what data Burnish accesses, how it is used, and your rights regarding that data.
Our role. With respect to protected customer data accessed from a merchant’s Shopify store — such as order data and storefront customer events — the merchant is the data controller and Burnish acts as a data processor. We process that data only on the merchant’s documented instructions and solely to provide the Burnish service (revenue attribution and AI-visibility measurement for merchant-approved catalog changes). We do not sell protected customer data, use it for advertising, or use it to train machine-learning or AI models. These terms, together with Shopify’s Partner Program Agreement and API License and Terms of Use, constitute our data protection agreement with merchants.
01 Data We Access from Your Shopify Store
When you install Burnish, we request the following Shopify API scopes:
| Products (read and write) | to score and improve product data such as titles, descriptions, metafields, and alt text. |
| Content (read and write) | to update merchant-controlled content fields used in catalog improvement workflows. |
| Product listings (read only) | to assess readiness for external surfaces and channel-facing product data. |
| Orders (read only, protected customer data Level 1) | to compute revenue attribution for merchant-approved catalog changes (per-Action lift and cohort ROI). The pinned query reads only order totals, currency, processed/created/cancelled timestamps, refund totals, and the test-mode flag. It deliberately excludes customer name, email, phone, address, and line items. |
| Customer events (read only, protected customer data Level 1) | via Burnish's first-party Web Pixel, to attribute AI-assistant-driven storefront traffic to conversions and revenue. We collect only non-identifying session signals (event type, timestamp, page and referrer URL, an opaque session identifier, and order value and currency). We do not request the customer name, email, phone, or address sub-scopes, and the pixel stores no customer personal information. |
| Web pixels (write) | to register and configure Burnish's own Web Pixel extension. This writes the pixel's configuration, not customer data. |
| Files (write) | to host Burnish-generated images, such as AI-optimized article images, via the Shopify Files API. |
We do not request Shopify theme scopes or Shopify analytics scopes for the current Burnish product, and we do not request access to all-orders history (only the default order window).
Outside the Shopify API, Burnish makes scheduled requests to your storefront’s
public URLs — the same pages any search engine or AI assistant can already
request. A daily check reads your homepage, robots.txt,
sitemap.xml, llms.txt, llms-full.txt, the
/.well-known/ucp path, and a small sample of product and article pages.
A weekly check requests your homepage once as each AI crawler user agent we track,
to confirm those crawlers are not being blocked. Both checks read only pages your
storefront already serves publicly, and what they record is described in section 2
and retained under section 4.
02 Data We Store
Burnish stores the following data in a PostgreSQL database hosted on Supabase (US West region). The application services that process this data are hosted on Railway.
| Store identity | your store's Shopify domain and installation status. |
| Catalog scoring and gap data | score outputs, issue summaries, and supporting readiness measurements. |
| Storefront monitoring snapshots | what your public storefront returned to the scheduled checks described in section 1 — HTTP status codes and response headers, the contents of robots.txt and llms.txt, sitemap data, the page markup of the sampled pages, and the measurements derived from them. These are recordings of your own public pages. No customer personal information is collected or stored. |
| Audit logs | before-and-after snapshots of approved product changes made through Burnish. |
| Billing and plan state | the information needed to manage subscription status through Shopify billing. |
| Consent and settings records | merchant-controlled preferences and workflow approvals. |
| Pre-install scan records | business email address, submitted Shopify store URL or myshopify handle, source and campaign metadata, qualification responses you submit, scan/report status, and hashed IP data used for abuse prevention and rate limiting. |
| Web Pixel storefront events | non-identifying storefront event signals collected via Burnish's Web Pixel — event type, timestamp, page and referrer URL, an opaque session identifier, and order value and currency — used to attribute AI-assistant-driven traffic to conversions. No customer personal information is collected or stored. |
| Google integration records | encrypted Google OAuth access and refresh tokens, granted scopes, token expiry, Search Console site URLs, GA4 property IDs, and GA4 property timezones when you connect Google Search Console or Google Analytics 4. |
| Search and analytics metrics | Search Console query, landing page, click, impression, CTR, and position data; GA4 source, medium, campaign, landing page, session, user, conversion, and revenue data used for attribution reporting. |
| Attribution evidence | known AI crawler user agents, AI referrer URLs, landing pages, timestamps, inferred AI-session confidence labels, and rollups used to separate SEO, AI, paid, direct, and other organic revenue. |
Burnish is designed around product and catalog operations, not end-customer data storage. We do not store your customers’ names, email addresses, payment information, or shipping addresses as part of the normal scoring, attribution, or catalog workflow.
03 Third-Party Data Processing
Burnish may send relevant product and catalog data to approved LLM providers for scoring, analysis, and fix generation. This can include product titles, descriptions, metafield values, image URLs, and other merchant-controlled catalog fields required for the workflow.
If you submit a pre-install scan, we use the submitted business email and store URL to run the scan, deliver the report, prevent abuse, and follow up about Burnish.
These providers may include OpenAI, Anthropic, Google, Perplexity, and xAI (Grok) under commercial API terms and a zero-retention or no-training posture where available.
Burnish also uses OpenRouter (Crystal Logic Inc.) as a routing
layer for catalog-execution and scoring-auxiliary LLM calls — e.g. product
description rewriting, vision analysis, prompt synthesis, and mention classification
— to route requests to cost-appropriate models. OpenRouter acts as a GDPR
Article 28 Processor under its Data
Processing Agreement, holds SOC 2 Type II certification, and routes requests
under EU Standard Contractual Clauses Module 2 (with UK and Swiss equivalents).
Burnish asserts provider.data_collection: deny and
provider.allow_fallbacks: false on every OpenRouter call so requests
are routed only to provider endpoints that do not retain or train on the data, and
documented processing instructions further bind OpenRouter to “routing
only” — explicitly prohibiting training, fine-tuning, aggregation, or
retention beyond what is operationally required.
If you connect Google Search Console or Google Analytics 4, Burnish calls Google APIs using the OAuth scopes you approve. Google-provided data is used only for Burnish attribution, reporting, and connection-health workflows.
Current infrastructure and subprocessors include Supabase for PostgreSQL hosting, Railway for application and worker hosting, Shopify for embedded app and billing services, Google for connected Search Console and GA4 APIs, OpenRouter for catalog-execution LLM routing, and the approved LLM providers listed above.
No customer personal information is intentionally sent to model providers as part of the normal Burnish workflow.
04 Data Retention
| Audit logs | (the before-and-after record of approved product changes made through Burnish) are retained indefinitely as a permanent compliance trail. Enterprise-tier merchants can configure a custom retention floor. |
| Records of failed or never-applied write attempts | are pruned after 90 days plus a 24-hour grace period; records of completed changes remain part of the audit trail above. |
| Storefront monitoring snapshots | are retained for 180 days, then deleted automatically. |
| Store-level records, pre-install scan records, Google connection records, attribution metrics, and billing-related records | are retained for the duration needed to operate Burnish and for reasonable operational or legal retention periods where required. |
| Google OAuth tokens | are removed or made unusable when the related connection is revoked or the shop deletion workflow runs. |
| Free-trial abuse record | To prevent repeated free-trial abuse, we retain a pseudonymous (one-way hashed) record that a store has already used its free trial; it contains no personal data and survives app uninstall. |
05 Data Deletion
You can request deletion of all your data at any time by uninstalling the app or contacting us. When you uninstall Burnish:
- Your installation is marked inactive.
- Operational data is queued for deletion or retention handling according to our deletion workflow.
We also support Shopify’s mandatory GDPR webhooks:
| Customer data erasure (customers/redact) | handled according to Shopify platform requirements. |
| Shop data erasure (shop/redact) | removes data associated with the requesting shop according to our deletion workflow (the pseudonymous free-trial abuse record described in section 4 is excluded — it contains no personal data and is retained for fraud prevention). |
To request access to your store-level data, correct inaccurate records, or request deletion outside the uninstall flow, contact support@useburnish.com.
06 Data Security
All data is transmitted over HTTPS. Infrastructure providers are selected with commercial-grade security controls. Shopify and Google access tokens are encrypted at rest and are not exposed in merchant-facing content.
07 Cookies
Burnish does not set authentication cookies. Authentication is handled through Shopify’s session token mechanism.
08 Changes to This Policy
We may update this policy as Burnish evolves. Changes will be posted at this URL with an updated date.
09 Contact
For questions about your data or to request deletion, contact us at support@useburnish.com.