Legal

Privacy Policy

What Yieldso reads from your store, what we keep, and how to get it deleted. Written to be specific rather than reassuring.

Last updated 6 September 2026

The short version

  • We request access to your products and content only. We do not request, receive or store your customers or your orders.
  • Product fixes are generated on our own servers by deterministic rules — your product data is not sent to an AI provider to produce them.
  • Uninstalling revokes our access immediately and erases your store's data.

1. Who we are

Yieldso ("we", "us") provides SEO and answer-engine optimisation software for Shopify stores. This policy covers the Yieldso Shopify app, the Yieldso web application, and this website.

2. What we access from your Shopify store

When you install the app you grant these Shopify access scopes, and no others: read_products, write_products, read_content, write_content, write_online_store_navigation.

We read, for each product:

  • Title, handle, description, vendor, product type and tags
  • SEO title and meta description
  • Featured image URL and its alt text
  • Price range and currency, and the first variant's SKU and barcode
  • Publication status and storefront URL

We write back only the fields you explicitly approve — SEO title, meta description, tags, image alt text, and a structured-data metafield.

We never request access to customers, orders, checkouts, payments, fulfilment or financial data. Shopify enforces this: without those scopes the data is not available to us even if we asked for it.

3. What we store about you

  • Store record — your myshopify domain, shop name, primary domain, contact email, country and currency, taken from Shopify at install.
  • Account — an email address and display name, used to identify you.
  • Catalogue mirror — the product fields listed above, so scoring runs without repeatedly calling Shopify.
  • Change history — for every fix: the original value, the new value, who approved it and when.
  • Search Console metrics — only if you connect it (see section 5).
  • Operational logs — errors and request diagnostics, retained short-term for debugging.

4. Access tokens

Your Shopify access token is encrypted before it is written to our database, using a key held outside the database. It is decrypted in memory only for the duration of a call to Shopify, and is never written to logs. On uninstall the token is deleted.

5. Google Search Console (optional)

If you choose to connect Search Console, we request read-only access (webmasters.readonly) and store daily click, impression, position and query totals for your site so we can show whether a change improved traffic. We never modify your Search Console property. Disconnect at any time from inside the app; the stored metrics are deleted with your account. Google's handling of your data is governed by Google's privacy policy.

6. Artificial intelligence

The fixes Yieldso proposes for your products — meta titles, descriptions, alt text, tags and structured data — are produced by deterministic rules running on our servers. No product data is sent to an AI provider to generate them.

Some optional features outside the product workflow (site profiling, content assistance and written explanations) do call a large language model, hosted on Microsoft Azure OpenAI in a business tier where inputs are not used to train models. Those features run only when you invoke them.

7. Sub-processors

ProviderPurposeData involved
ShopifyThe platform your store runs onProduct and shop data
Microsoft AzureAI processing for optional featuresPage and site content you submit
GoogleSearch Console metrics, if connectedAggregated search statistics

Application data is stored on servers we operate. We do not sell data, and we do not share it for advertising.

8. Retention and deletion

  • On uninstall — Shopify notifies us, we mark the store uninstalled and delete the access token immediately.
  • 48 hours after uninstall — Shopify sends a shop redaction request. We then permanently delete the store record, its catalogue mirror, its change history, its stored credentials and, where the account exists only for that store, the account itself.
  • Customer redaction requests — we hold no customer records, so there is nothing to erase. We acknowledge and log every such request.

9. Your rights

Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing. Contact us and we will respond within the period required by law. You can also exercise deletion directly by uninstalling the app.

10. Cookies and local storage

This website uses no advertising or third-party tracking cookies. The web application stores a session token and interface preferences in your browser's local storage so you stay signed in; that data never leaves your device except as the authentication token sent to our API. Inside the Shopify admin, authentication uses short-lived session tokens issued by Shopify.

11. Security

Traffic is encrypted in transit. Access tokens are encrypted at rest. Each store's data is isolated by a tenant boundary enforced centrally in our data layer, so one store's data cannot be returned to another. No system is perfectly secure, and we do not claim otherwise.

12. Children

Yieldso is a business tool and is not directed at anyone under 16.

13. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change meaningfully affects you, notify you in the app.

14. Contact

Privacy questions or requests: privacy@yieldso.com.