Sofenx AI Store Auditor
Privacy policy
Last updated August 4, 2026. Sofenx operates Sofenx AI Store Auditor. This policy explains how we handle information when a Shopify merchant installs and uses the app.
Information we process
The app processes the shop domain, store name, merchant contact email, currency, public domain, products, collections, online-store navigation, and public homepage content needed to produce an audit. We store app settings, the merchant’s configured revenue baseline, audit scores, evidence, findings, recommendations, subscription status, and operational email-delivery timestamps.
The app does not request access to customers, orders, payments, or checkout data. Do not submit customer personal data, passwords, access tokens, or other secrets through app settings or support requests.
How we use information
We use this information to authenticate the Shopify installation, operate and improve audits, show evidence-backed recommendations, enforce plan allowances, deliver service emails, provide support, prevent abuse, and maintain the security and reliability of the service. We do not sell merchant or store data.
AI processing
For paid-plan guidance, selected finding titles, public resource titles, deterministic explanations, recommendations, and supporting evidence may be sent to OpenAI to improve the wording and implementation guidance. Customer and order data is not included. Requests are configured not to be stored by the model provider for application state, and AI output cannot create findings or change audit scores.
Service providers
We use Shopify for installation, store data, and billing; OpenAI for optional AI-assisted guidance; Amazon Web Services Simple Email Service for transactional email; Cloudflare for DNS, TLS, and network protection; and infrastructure hosting, database, backup, and monitoring providers needed to operate the service. These providers process information only to provide their contracted services and under their own security and privacy obligations.
Deletion and retention
Primary shop records, settings, audits, findings, and Shopify access tokens are deleted when an app-uninstall or Shopify shop-redaction request is processed. Encrypted operational backups may retain deleted data for up to 30 days before rotation. Limited security, delivery, and infrastructure logs may be retained for up to 90 days, unless a longer period is required to investigate abuse, comply with law, or resolve a dispute.
Your choices and rights
Merchants can uninstall the app to stop collection and initiate deletion. Shopify may also send us customer data-access and redaction requests. Because the app does not request customer or order scopes, we normally hold no buyer records to return or redact. You may contact us to request access, correction, or deletion of information associated with your shop, subject to applicable law.
Security and international processing
We use HTTPS, access controls, encrypted credentials, isolated production services, and restricted administrative access. Information may be processed in countries where our service providers operate, with protections required by applicable agreements and law. No internet service can guarantee absolute security.
Changes
We may update this policy as the app or applicable requirements change. We will update the date above and provide additional notice when a material change requires it.
Contact
Email [email protected]. Postal address: Sofenx, House 12, Road 16, Sector 11, Uttara, Dhaka, Bangladesh.