Privacy policy
Last updated: 2026-09-30
Agent Radar ("the app") is provided by vantezzen ("we"). This policy explains what data the app processes when a merchant installs it on their Shopify store, and how it is handled. The app is designed to work with as little data as possible. It stores no personal data about a store's shoppers.
Data we receive from Shopify about the merchant
- The store's domain, ID, timezone and currency, used to run and configure the app.
- An access token issued by Shopify, used to call the Shopify APIs on the merchant's behalf. It is stored in our database and deleted when the app is uninstalled.
- The merchant's selected pricing plan, read from Shopify to unlock paid features.
Order data
To attribute orders to AI assistants, the app reads each new order's ID, number, total, currency, sales channel, referring site, landing page, UTM parameters and cart attributes. It does not read customer names, email addresses, phone numbers or addresses. For orders attributed to AI, we store the order ID, order number, date, total and the attribution result (for example "Referred by ChatGPT"). The result is also written back to the order in the merchant's Shopify admin as a metafield and, if enabled, as order tags.
Storefront visits
If the merchant turns on the app embed, a script on the storefront detects AI agents, crawlers and visitors arriving from AI assistants. To classify a visit, our server processes the request's user agent, IP address, referring page, landing page and technical browser signals (for example whether the browser is automated). IP addresses are used only to check whether a request really comes from a known AI provider, and they are never stored. The script sets no cookies. It keeps a short-lived session state in the browser's session storage, which is cleared when the tab closes. By default the script runs only for visitors who have allowed analytics under the store's cookie consent settings.
We store only anonymous, aggregated daily counts (for example "12 visits by GPTBot on 30 September"), plus a short feed of the most recent agent events (agent type and page path). None of this can identify an individual shopper.
Checkout
The app's web pixel runs only for visitors who have allowed analytics. When a session that Agent Radar attributed to AI reaches checkout, the pixel sends the store domain and the app's own attribution label. It sends no personal data.
Data stored in the merchant's store
Daily summaries are saved as "Agent Radar daily report" metaobjects in the merchant's own Shopify store. The merchant controls this data, and it stays in their store under their control.
Retention and deletion
- Aggregated counters and attributed order records are deleted after 90 days.
- The activity feed keeps only the 100 most recent events per store.
- When the app is uninstalled, the access token is deleted immediately. All remaining data is deleted when Shopify sends its shop data erasure request (48 hours after uninstall).
- Because we store no shopper personal data, customer data and erasure requests are answered with no data found.
Sharing
We don't sell or share data with third parties. Data is processed only by our hosting and infrastructure providers on our behalf, and by Shopify as the platform. To verify AI crawlers, the app downloads the public IP range lists of AI providers (for example OpenAI and Perplexity). No store data is sent to them.
Security
All traffic is encrypted with TLS. Requests from Shopify are verified using Shopify's signatures, and access to data is limited to what the app needs to work.
Your rights
Merchants can request access to, or deletion of, their data at any time by contacting [email protected]. Shoppers should contact the store they bought from. The merchant is the controller of their store's data, and we act as their processor.
Contact
Questions about this policy: [email protected].