AI Forecast Agent — Privacy Policy
Last updated: October 1, 2026
AI Forecast Agent ("the app") is a Shopify app that forecasts inventory demand
from your store's own order history. This policy explains exactly what data the app
processes, and what it deliberately never touches.
Data we collect
- Shop-level identifiers: your shop domain and Shopify session/access
tokens, used only to authenticate API calls back to your own store.
- Product usage data: SKU, quantity sold, and order date, aggregated
per day per SKU from Shopify's Orders API. To avoid counting an edited or re-sent
order twice, we also keep each order's ID together with the SKU quantities we
recorded for it. We never store order totals, line-item prices, or anything beyond
order ID, SKU, quantity, and date.
- Store settings you enter: per-SKU or shop-wide reorder lead times,
and the AI provider (Google Gemini or Anthropic Claude) and API key you choose to add
in Settings. Your API key is encrypted at rest; only its last four characters are ever
displayed back to you, for confirmation.
- AI usage metering: number of questions asked and estimated token
cost per request, used only to enforce a rate limit and show you your own usage in
Settings.
- Store contact details: when you install the app, we read your store
name, owner name, store email, plan name, and country once via Shopify's Admin API,
and refresh them periodically. We use this only to provide support, respond to issues
with your AI key or forecasts, and — only if you've ticked the opt-in checkbox in
Settings — to occasionally reach out for feedback or about custom Shopify development
work. You can untick that box at any time, and we never send feedback or custom-work
messages to a store that hasn't opted in.
- Feedback: if you submit a rating or comment from Settings, we store
it to improve the app. It's never linked to your customers' data and is deleted
along with the rest of your shop's data after you uninstall (see below).
What we never collect
We do not store customer names, emails, phone numbers, shipping or billing addresses, or
any other personally identifying information about your customers. The app reads only
the SKU and quantity of each order's line items, and the forecasting math works from
per-SKU quantities — never from customer records.
How your data is used
- The forecasting engine computes reorder points and days of cover from your
store's own inventory and order-quantity history. This runs entirely on our
server.
- If you use the "Ask the forecast agent" chat, the app sends your question
and the forecast snapshot (SKU, product title, stock per location and location name,
daily usage, reorder point, days of cover, and stock status — no customer data) to the
AI provider you've configured, using the API key you supplied yourself. That
request goes out directly under your own key, not a shared account, and is governed by
that provider's own privacy policy.
- We never use your data for advertising, and never sell or share it with anyone other
than the AI provider you've explicitly configured.
Data retention and deletion
- Uninstalling the app deletes your session credentials immediately.
- Forecast history, lead-time settings, AI provider settings, store contact details,
and feedback are kept briefly in case you reinstall, then permanently deleted — in line with Shopify's mandatory
shop/redact webhook, typically ~48 hours after uninstall.
- Because we never store customer-identifying data, there is nothing to export or erase
when Shopify's
customers/data_request or
customers/redact webhooks fire; our handlers for both simply confirm no
customer data is on file.
Security
- Your AI provider API key is encrypted at rest using an application-level encryption
key stored separately from the encrypted data.
- All traffic between your store, our servers, and Shopify's Admin API is
encrypted in transit (HTTPS/TLS).
- Our production database runs on managed hosting with encryption at rest.
Contact
Questions about this policy, or a request to delete your shop's data sooner than the
automatic window: arsalanarshad.dev@gmail.com.