Privacy Policy
Last updated: July 19, 2026
AskTrail (“we”, “us”) is a Shopify app that helps merchants understand which orders were influenced by AI assistants (such as ChatGPT, Perplexity, and Gemini) and what buyers asked those assistants. This policy explains what data we process and why.
What we access
Through Shopify’s official OAuth we request access to orders (read_orders, write_orders). We process order-level attribution fields only — referrer, UTM parameters, and source name — plus order identifiers, in order to classify AI-referred orders. Write access is used for a single purpose: adding attribution tags (AI-influenced, AI-source:…) to orders we detect as AI-referred. We modify no other field, and we request no product or customer scopes. We do not request or store your customers’ names, emails, phone numbers, or addresses.
Our post-purchase survey collects a buyer’s voluntary answer to “how did you find us” and, optionally, what they asked an AI assistant. This is submitted by the buyer and is not linked to their personal identity.
How we use it
Solely to provide the app’s features to the merchant: attributing orders to AI sources, showing which buyer questions your store appears for, and sending the merchant a weekly report. We do not sell this data, and we share it only with the subprocessors below, who process it on our behalf.
Subprocessors
- Vercel — application hosting (United States).
- Supabase — database storage.
- OpenAI — prompt probing. When a merchant runs a probe, the buyer’s survey question text is sent to the OpenAI API to test whether the store surfaces in an AI answer. This is the only feature that transmits buyer-written text outside our infrastructure, it runs only when the merchant triggers it, and it is available on paid plans only.
- Resend — delivery of the weekly report email to the merchant.
Retention and deletion
Data is retained while the app is installed. When you uninstall AskTrail, we delete your store’s attribution records, survey responses, probe results, and session credentials — triggered by Shopify’s app/uninstalled webhook. We also implement Shopify’s mandatory GDPR webhooks (customers/redact, customers/data_request, shop/redact) and act on each verified request.
Security
Data is encrypted in transit (TLS) and at rest by our hosting provider. Access is limited to the app operator under least-privilege credentials.
Contact
Questions about this policy? Email thoopring@gmail.com.