Shopigent — Privacy Policy
Last updated: 2026-07-24 | Controller: Greek Nous | Contact: shopigent@greeknous.com
1. What Shopigent is
Shopigent is a Shopify app that lets merchants operate their store through AI agents (any MCP-compatible client, e.g. Hermes, Claude, Cursor). It exposes a curated set of read and write operations ("tools") over the Shopify Admin API, gated by the merchant's chosen plan and the scopes they grant at install time.
2. Data we access
At install, the merchant authorizes Shopify OAuth scopes. Shopigent only accesses data required by the tools the merchant enables. Possible scope categories: products, orders, customers, discounts, inventory, fulfillments, online store content, and themes. We access store data only to fulfill a tool call the merchant (or their agent, on their behalf) explicitly triggers.
We do not access: payment instrument numbers, passwords, or any data outside the authorized Shopify scopes.
3. Data we store
- Shop connection metadata (store domain, granted scopes, current plan).
- API key hashes — we store only a salted SHA-256 hash of the MCP API key. The plaintext key is shown once at creation and never stored.
- Tool-call audit logs — for every tool call we record: shop, tool key, operation type, input arguments, result status, and latency.
- Plan / billing events — subscription status and Shopify charge IDs (received via Shopify webhooks), not card numbers.
4. Data we share
We do not sell or share merchant data with third parties except:
- with Shopify, necessarily, to perform the requested operations;
- with the merchant's chosen AI client, only the data needed to answer the specific request they made.
5. Data retention
Audit logs and connection metadata are retained while the app is installed. Uninstalling the app triggers deletion of store-specific records.
6. Security
MCP API keys are hashed (never stored in plaintext). All Admin API calls use the store's OAuth access token, transmitted only to Shopify over TLS. Destructive tools require an explicit confirmation step before they run.
7. Your rights
Merchants may request deletion of their data at any time via shopigent@greeknous.com or by uninstalling the app from their Shopify admin.
8. Changes
Material changes to this policy will be communicated via the support email.