1. Who we are
Kivviq is an analytics application for Shopify merchants. It reads a store's commercial data — together with the advertising and email platforms a merchant chooses to connect — and presents it back as dashboards and as answers from an AI analyst.
In data-protection terms, Kivviq acts as a processor for the merchant who installs it. The merchant is the controller of their store's data and of their shoppers' data; Kivviq processes that data only to provide the service described here. Where Kivviq holds data about the merchant's own staff — the accounts that sign in to the dashboard — it acts as a controller.
This policy explains what Kivviq collects, why, where it is kept, who else processes it, and how to have it deleted.
2. Shopify store data we access
When a merchant installs Kivviq and authorises it, Shopify issues an offline access token scoped to the permissions the merchant approved on the consent screen. Kivviq requests these read permissions:
read_orders— order totals, dates, sales channel, financial and fulfilment status, discounts, shipping, taxes, refunds, and line items. Shopify limits this to the trailing 60 days, so Kivviq sees no further back than that.read_productsandread_inventory— product and variant titles, prices and costs, used for margin and product-performance reporting.read_customers— used only to identify whether an order came from a new or returning customer, and to rank customers by lifetime value.read_discounts— discount codes, status and usage counts.
Kivviq requests no write permission of any kind. It cannot create, modify, cancel or refund an order, change a product or a price, install anything on the storefront, or contact a customer. Every permission above is read-only, and permissions that turned out to have no consumer in the product were removed rather than left on the consent screen.
Kivviq also reads the store profile — shop name, myshopify.com domain,
plan, and the merchant contact email Shopify holds for the store — to identify
the connected account and to display it in the dashboard.
3. Protected customer data
Shopify designates some fields as protected customer data. Kivviq's use of them is deliberately narrow.
What is read. From each order, Kivviq reads the customer's Shopify identifier, display name, and account creation date. These are used to count unique and new customers, to compute repeat-purchase and cohort behaviour, and to show a merchant the highest-value orders in their own store.
Order email, for matching only. One part of Kivviq — the routine that reconciles storefront analytics sessions against completed orders — does read the email address on an order. It is converted to a SHA-256 hash the moment it arrives and the original address is discarded; the hash is compared against the hash of an email the storefront supplied at checkout, so that a purchase can be credited to the session that produced it. No email address is stored, displayed, logged, exported or sent to the AI model. If the store has not granted the permission, Kivviq falls back to matching on order number alone.
What is never read. Kivviq does not request or retrieve customer phone numbers, shipping addresses, billing addresses, or payment details from the Shopify Admin API. They do not appear in any query the application issues.
What is not stored. Shopify order and customer data is held in process memory for the life of a short-lived cache and is not written to Kivviq's database. Restarting the service discards it. The only Shopify-derived values Kivviq persists are product and variant cost figures, used for margin calculations, which contain no customer information.
What is not sent to the AI model. Customer identity is excluded from the data supplied to the AI analyst. The analyst receives aggregate figures — revenue, order counts, channel splits, product performance — and, for high-value orders, the order number and total without any customer name or identifier attached.
4. Storefront pixel and shopper data
If a merchant enables attribution, Kivviq installs a Shopify web pixel that runs in Shopify's strict sandbox on the storefront. It records page views, product views, cart and checkout events, and purchases, so that revenue can be attributed to the marketing channel that produced it.
For each event, Kivviq stores:
- a randomly generated visitor identifier and session identifier, created by the pixel and stored in the shopper's browser — not supplied by Shopify and not linked to any account outside Kivviq;
- the page host and path only — query strings are never transmitted, so identifiers a merchant or an ad platform appends to a URL do not reach Kivviq;
- the referring URL and the first-touch and last-touch marketing parameters used for attribution;
- device type and browser family, derived from the request's user-agent header;
- the shopper's consent state as reported by Shopify's Customer Privacy API at the time of the event;
- the Shopify customer, order, cart and checkout identifiers associated with the event, where the storefront provides them.
Email addresses are never stored. Where the storefront supplies an email on a checkout event, it is hashed with SHA-256 on receipt and the original value is discarded before anything is written. The hash exists only so that a purchase can be matched to the session that produced it.
IP addresses are never stored. The requesting IP is hashed with a server-held salt and truncated before storage. The raw address is not written to the database, to the event log, or to any application log.
Bot traffic is discarded. Requests with no user-agent, or with a recognised crawler user-agent, are rejected and never stored.
The pixel records the shopper's consent state alongside each event so a merchant can see it. Kivviq relies on Shopify's own consent enforcement in the strict pixel sandbox and on the merchant's configuration of Shopify's customer privacy settings; it does not operate an independent consent banner or a second consent decision of its own.
5. Connected services
A merchant may connect additional accounts. Each is optional, each is connected with the merchant's own credentials, and each is read-only.
- Google Analytics 4 — aggregate reporting only: sessions, active users, page views, key events, revenue, and breakdowns by channel, country, city and page path. No user-level or individual GA4 data is retrieved.
- Google Ads — campaign and account performance: spend, impressions, clicks and conversions. No audience lists and no customer-identifying data.
- Meta Ads — account and campaign insights: spend, delivery and results. No audience or Custom Audience data.
- Pinterest Ads — ad account metadata and account- and campaign-level analytics: spend, impressions, clicks, checkouts and conversion values. No audience data and no customer-identifying data.
- Omnisend — email and SMS campaign performance, audience totals by subscription status, and the eight most recently created contacts, which are displayed in the Omnisend section of the dashboard and include those contacts' email addresses as held in the merchant's own Omnisend account.
The Omnisend section — including those eight contact rows — is written to a cache file on the application server so the dashboard survives a restart and Omnisend's rate limits. Nothing from any other connected service is stored with contact-level detail.
6. Why we process this data
Kivviq processes the data above for these purposes and no others:
- Providing the dashboards the merchant installed the app to see — sales, products, customers, cohorts, retention, advertising and email performance.
- Marketing attribution — connecting a purchase back to the channel and campaign that produced it, which is the reason the pixel exists.
- Answering the merchant's questions through the AI analyst, using their own data as evidence.
- Operating the service — authenticating users, enforcing workspace boundaries, rate limiting, diagnosing faults, and metering AI usage and cost.
Kivviq does not sell data, does not share one merchant's data with another merchant, does not build cross-merchant profiles, does not use merchant or shopper data to train AI models, and does not use any of this data for its own advertising.
7. AI processing
The AI analyst is built on Anthropic's Claude models, accessed through Anthropic's API. When a merchant asks a question, Kivviq sends the question, the conversation so far, and the specific evidence needed to answer it — aggregate metrics from the connected sources, and the text of any document the merchant attached to that conversation.
Customer identity is excluded from that evidence, as described in section 3. Where the merchant asks about individual visitor journeys, the analyst can receive pseudonymous pixel visitor and session identifiers; it does not receive names, email addresses or email hashes.
Kivviq records telemetry about each AI request — timing, which model ran, token counts and cost. That telemetry contains no prompt text, no answer text and no tool results; the schema has no column for them. The questions and answers themselves are stored separately as the merchant's own conversation history, so they can reopen a thread.
8. Storage and retention
Kivviq runs on Railway (application hosting) and stores durable data in Supabase (managed PostgreSQL and object storage). Database access is backend-only through a service-role credential; row-level security is enabled on every table with no policies for anonymous or authenticated roles, so nothing but the application server can read or write. The browser never connects to the database.
What is stored durably:
- storefront pixel events and derived visitor sessions and journeys;
- the merchant's AI conversations and their message content;
- documents a merchant uploads to the analyst, together with the extracted text used to answer questions about them;
- strategy records, saved questions, opportunity findings, dashboard layouts and preferences a merchant creates;
- product and variant cost figures used for margin calculations;
- connection records for each authorised data source, and AI usage telemetry;
- the name, email address and profile picture of each user who signs in.
What is not stored durably: Shopify order, customer, product and discount data pulled for a dashboard view, which is held only in a short-lived in-memory cache.
Retention. Kivviq does not currently operate an automatic expiry schedule. Data is retained for as long as the merchant's account exists, and is deleted when the merchant disconnects a source, deletes the record, asks us to delete it, or when Shopify sends a redaction request for their store — see section 10. The one exception is the pixel event log file on the application server, which rotates at 64 MB and keeps a single previous generation.
Credentials. Access and refresh tokens for connected accounts are encrypted at rest with AES-256-GCM before they are written, using a key held only in the server environment and never in the database. Each encrypted value is cryptographically bound to the workspace, the provider and the specific field it belongs to, so a token lifted from one row cannot be decrypted into another. Tokens are never logged and never sent to the browser.
9. Subprocessors
These are the third parties that process data on Kivviq's behalf:
| Subprocessor | Purpose | Data involved |
|---|---|---|
| Railway | Application hosting | All data in transit through the service; the pixel event log and cache files on the application volume |
| Supabase | Managed PostgreSQL and private object storage | All durable data listed in section 8 |
| Anthropic | AI analyst | Questions, conversation history, aggregate evidence, and attached document text |
| Google (Sign-In) | Authenticating dashboard users | The signing-in user's email address, name and profile picture |
| Google (Fonts) | Web fonts for the dashboard interface | The dashboard user's IP address and browser, by virtue of the font request |
Kivviq runs no third-party analytics or advertising script of its own, in the dashboard or on the storefront. The only script it places on a storefront is its own Shopify web pixel, described in section 4.
Shopify, Google Analytics, Google Ads, Meta, Pinterest and Omnisend are the merchant's own sources, not Kivviq's subprocessors. Kivviq reads from them under the merchant's authorisation and their own privacy terms continue to apply.
10. Deletion, uninstalling, and your rights
Disconnecting a store. A workspace owner or administrator can disconnect Shopify from within Kivviq. The stored access and refresh tokens are destroyed immediately and the connection record is deleted, so Kivviq can no longer read anything from the store. This revokes Kivviq's copy of the credentials; it does not uninstall the app from Shopify, which is done from the Shopify admin.
Uninstalling the app. Uninstalling in Shopify revokes Kivviq's access token, and Kivviq destroys its stored copy of that store's credentials on receiving Shopify's uninstall notification. No further Shopify data can be read from that moment. An uninstall is deliberately NOT an erasure: merchants uninstall to change plan, to pause, or by accident, and Shopify's own design allows 48 hours in which a reinstall restores the account intact. The merchant's history is kept for that window.
Erasure after uninstall. Shopify sends a shop-redaction request 48 hours after an uninstall. On receiving it Kivviq deletes that store's Shopify credentials, its authorization records, its storefront analytics — in the database and in the server's own event log — and the product cost records derived from its catalogue. It does not delete the merchant's Kivviq account, their uploaded documents, their saved analyses, or data from any other service they connected: Shopify's request covers Shopify's data, and the rest is the merchant's own. A merchant who wants their whole Kivviq account erased can ask at privacy@kivviq.ca.
Deleting individual records. Merchants can delete their own saved questions, question history, dashboards and layouts from within the app. Deleting an uploaded document permanently removes the extracted text and every retrievable chunk of it; the document's filename, size and type are retained as a tombstone so that a conversation which referenced it still makes sense.
Merchant rights. Depending on where a merchant is established, they may have rights of access, correction, erasure, restriction, objection and portability over the data Kivviq holds about them. Write to the address above and we will respond within 30 days.
Shopper rights. Kivviq holds shopper data as a processor for the merchant. A shopper should direct an access or erasure request to the store they bought from; Kivviq will act on the merchant's instruction, or on a request forwarded through Shopify, and will confirm completion to the merchant. A shopper may also write to us directly at the address above and we will route the request to the merchant and act on it.
11. Shopify privacy and compliance webhooks
Shopify defines three mandatory privacy webhooks that apps receive on a merchant's or a shopper's behalf, and one lifecycle webhook that reports an uninstall:
customers/data_request— a shopper has asked the merchant for the data an app holds about them.customers/redact— a shopper has asked for their data to be erased. Shopify sends this 10 days after the request, or 6 months after their last order.shop/redact— sent 48 hours after a store uninstalls the app or closes, requesting erasure of that shop's data.app/uninstalled— sent when a merchant uninstalls the app.
All four are implemented. Each delivery's signature is verified against the application's own secret before anything is read from it, and an unsigned or mis-signed request is refused. A request arriving through any of these channels is actioned within the deadline Shopify sets. Because these requests concern shopper data that Kivviq holds only as a pseudonymous pixel record, the erasure performed is the removal of the storefront events, sessions and journeys associated with the identifiers named in the request, together with any hashed email derived from them.
A merchant who wants confirmation that a specific request has been completed can ask at privacy@kivviq.ca and will receive a written response.
12. Security
These are the controls the application actually implements:
- Transport encryption. The service is served over HTTPS; every outbound call to Shopify, Google, Meta, Omnisend, Anthropic and Supabase is over TLS.
- Encrypted credentials at rest. Provider tokens are sealed with AES-256-GCM and bound to their workspace, provider and field, as described in section 8.
- Authentication. Dashboard access requires a Google account on an explicit allowlist. Google's ID token is verified against the application's own client id and a verified email is required; the Google token itself is never stored. The session is an HTTP-only,
Secure,SameSite=Laxsigned cookie that expires after seven days. - Tenant isolation. Every request resolves its workspace from server-side membership records, never from a value the client sends. A user with no membership is refused outright, and data routes additionally refuse a workspace whose data sources are not provisioned. This boundary is covered by an automated audit that boots the real server and probes every API route as four different identities.
- Database access control. Row-level security is enabled on every table with no anonymous or authenticated policies; only the backend service role can read or write, and the browser has no database connection.
- Private object storage. Uploaded documents live in a private bucket. No public URL and no signed URL is ever minted; bytes reach a browser only through an API route that re-resolves the workspace from the session first.
- OAuth integrity. Shopify callbacks are HMAC-verified in constant time, shop domains are validated against Shopify's own hostname format before any credential is sent, and each authorisation uses a single-use, expiring state nonce.
- Secrets are never logged. Tokens, API keys, authorization codes and provider error bodies are excluded from logs by construction, because provider error responses can echo the request parameters back.
- Rate limiting and CORS. AI endpoints are rate limited per user, and browser origins are restricted to an explicit allowlist.
No system is perfectly secure. If you believe you have found a vulnerability in Kivviq, please write to privacy@kivviq.ca rather than disclosing it publicly, and we will respond.
13. International data transfers
Kivviq is operated from Canada. Its subprocessors — Railway, Supabase, Anthropic, Google and Vercel — operate infrastructure in the United States and other countries. Data processed by Kivviq will therefore be transferred to and stored in jurisdictions outside the merchant's own, including the United States.
Where a merchant or their shoppers are in the European Economic Area, the United Kingdom or Switzerland, such transfers are made on the basis of the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism offered by the subprocessor concerned. A merchant who needs the specific hosting region for a record of processing activities can request it at privacy@kivviq.ca.
14. Children
Kivviq is a business tool sold to merchants. It is not directed at children, and it does not knowingly collect data from anyone it knows to be a child. It has no mechanism for determining a storefront visitor's age, and it collects no data from storefront visitors beyond the pseudonymous analytics described in section 4.
15. Changes to this policy
This policy will be updated when what Kivviq does with data changes — a new connected service, a new subprocessor, or a change to what is stored or for how long. The revision date at the top of this page changes with it. Material changes will be communicated to connected merchants directly.
16. Contact
For any question about this policy, or to make an access, correction or deletion request:
We aim to acknowledge within five business days and to complete a verified request within 30 days.