The short version
- We request access to your products and content only. We do not request, receive or store your customers or your orders.
- Product fixes are generated on our own servers by deterministic rules — your product data is not sent to an AI provider to produce them.
- Uninstalling revokes our access immediately and erases your store's data.
1. Who we are
Yieldso ("we", "us") provides SEO and answer-engine optimisation software for Shopify stores. This policy covers the Yieldso Shopify app, the Yieldso web application, and this website.
2. What we access from your Shopify store
When you install the app you grant these Shopify access scopes, and no others:
read_products, write_products, read_content, write_content, write_online_store_navigation.
We read, for each product:
- Title, handle, description, vendor, product type and tags
- SEO title and meta description
- Featured image URL and its alt text
- Price range and currency, and the first variant's SKU and barcode
- Publication status and storefront URL
We write back only the fields you explicitly approve — SEO title, meta description, tags, image alt text, and a structured-data metafield.
We never request access to customers, orders, checkouts, payments, fulfilment or financial data. Shopify enforces this: without those scopes the data is not available to us even if we asked for it.
3. What we store about you
- Store record — your myshopify domain, shop name, primary domain, contact email, country and currency, taken from Shopify at install.
- Account — an email address and display name, used to identify you.
- Catalogue mirror — the product fields listed above, so scoring runs without repeatedly calling Shopify.
- Change history — for every fix: the original value, the new value, who approved it and when.
- Search Console metrics — only if you connect it (see section 5).
- Operational logs — errors and request diagnostics, retained short-term for debugging.
4. Access tokens
Your Shopify access token is encrypted before it is written to our database, using a key held outside the database. It is decrypted in memory only for the duration of a call to Shopify, and is never written to logs. On uninstall the token is deleted.
5. Google Search Console (optional)
If you choose to connect Search Console, we request read-only access
(webmasters.readonly) and store daily click, impression, position and query totals for
your site so we can show whether a change improved traffic. We never modify your Search Console
property. Disconnect at any time from inside the app; the stored metrics are deleted with your
account. Google's handling of your data is governed by
Google's privacy policy.
6. Artificial intelligence
The fixes Yieldso proposes for your products — meta titles, descriptions, alt text, tags and structured data — are produced by deterministic rules running on our servers. No product data is sent to an AI provider to generate them.
Some optional features outside the product workflow (site profiling, content assistance and written explanations) do call a large language model, hosted on Microsoft Azure OpenAI in a business tier where inputs are not used to train models. Those features run only when you invoke them.
7. Sub-processors
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | The platform your store runs on | Product and shop data |
| Microsoft Azure | AI processing for optional features | Page and site content you submit |
| Search Console metrics, if connected | Aggregated search statistics |
Application data is stored on servers we operate. We do not sell data, and we do not share it for advertising.
8. Retention and deletion
- On uninstall — Shopify notifies us, we mark the store uninstalled and delete the access token immediately.
- 48 hours after uninstall — Shopify sends a shop redaction request. We then permanently delete the store record, its catalogue mirror, its change history, its stored credentials and, where the account exists only for that store, the account itself.
- Customer redaction requests — we hold no customer records, so there is nothing to erase. We acknowledge and log every such request.
9. Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data, and to object to or restrict processing. Contact us and we will respond within the period required by law. You can also exercise deletion directly by uninstalling the app.
10. Cookies and local storage
This website uses no advertising or third-party tracking cookies. The web application stores a session token and interface preferences in your browser's local storage so you stay signed in; that data never leaves your device except as the authentication token sent to our API. Inside the Shopify admin, authentication uses short-lived session tokens issued by Shopify.
11. Security
Traffic is encrypted in transit. Access tokens are encrypted at rest. Each store's data is isolated by a tenant boundary enforced centrally in our data layer, so one store's data cannot be returned to another. No system is perfectly secure, and we do not claim otherwise.
12. Children
Yieldso is a business tool and is not directed at anyone under 16.
13. Changes to this policy
If we make a material change we will update the date at the top of this page and, where the change meaningfully affects you, notify you in the app.
14. Contact
Privacy questions or requests: privacy@yieldso.com.
