Sofenx AI Store Auditor

Privacy policy

Last updated August 4, 2026. Sofenx operates Sofenx AI Store Auditor. This policy explains how we handle information when a Shopify merchant installs and uses the app.

Information we process

The app processes the shop domain, store name, merchant contact email, currency, public domain, products, collections, online-store navigation, and public homepage content needed to produce an audit. We store app settings, the merchant’s configured revenue baseline, audit scores, evidence, findings, recommendations, subscription status, and operational email-delivery timestamps.

The app does not request access to customers, orders, payments, or checkout data. Do not submit customer personal data, passwords, access tokens, or other secrets through app settings or support requests.

How we use information

We use this information to authenticate the Shopify installation, operate and improve audits, show evidence-backed recommendations, enforce plan allowances, deliver service emails, provide support, prevent abuse, and maintain the security and reliability of the service. We do not sell merchant or store data.

AI processing

For paid-plan guidance, selected finding titles, public resource titles, deterministic explanations, recommendations, and supporting evidence may be sent to OpenAI to improve the wording and implementation guidance. Customer and order data is not included. Requests are configured not to be stored by the model provider for application state, and AI output cannot create findings or change audit scores.

Service providers

We use Shopify for installation, store data, and billing; OpenAI for optional AI-assisted guidance; Amazon Web Services Simple Email Service for transactional email; Cloudflare for DNS, TLS, and network protection; and infrastructure hosting, database, backup, and monitoring providers needed to operate the service. These providers process information only to provide their contracted services and under their own security and privacy obligations.

Deletion and retention

Primary shop records, settings, audits, findings, and Shopify access tokens are deleted when an app-uninstall or Shopify shop-redaction request is processed. Encrypted operational backups may retain deleted data for up to 30 days before rotation. Limited security, delivery, and infrastructure logs may be retained for up to 90 days, unless a longer period is required to investigate abuse, comply with law, or resolve a dispute.

Your choices and rights

Merchants can uninstall the app to stop collection and initiate deletion. Shopify may also send us customer data-access and redaction requests. Because the app does not request customer or order scopes, we normally hold no buyer records to return or redact. You may contact us to request access, correction, or deletion of information associated with your shop, subject to applicable law.

Security and international processing

We use HTTPS, access controls, encrypted credentials, isolated production services, and restricted administrative access. Information may be processed in countries where our service providers operate, with protections required by applicable agreements and law. No internet service can guarantee absolute security.

Changes

We may update this policy as the app or applicable requirements change. We will update the date above and provide additional notice when a material change requires it.

Contact

Email [email protected]. Postal address: Sofenx, House 12, Road 16, Sector 11, Uttara, Dhaka, Bangladesh.