Effective July 28, 2026

AgentReady Privacy Policy

AgentReady ("the App", "the Service") helps businesses understand and improve how AI assistants and search engines talk about them. You may use AgentReady by installing the Shopify app on a Shopify-supported store, and/or by signing up for an any-website (standalone) workspace that monitors one or more sites you own or operate. This Privacy Policy describes how personal information is collected, used, and shared when you use either path.

Personal Information the App Collects

Account information (all users): your name, email address, hashed password (if you signed up with email), and an optional Google account identifier (if you signed in with Google). We never store the raw password — only a one-way bcrypt hash used to verify future logins. Workspace membership records (role, invite status) identify who can access a workspace on your behalf.

Shopify stores. When you install the App from Shopify, we are automatically able to access certain types of information from your Shopify account, scoped to what the App needs to do its job:

  • Products (read_products, write_products) — to read your product catalog and write product-level metafields containing the AgentReady JSON your storefront serves.
  • Content (read_content, write_content) — to read your blog posts, articles, and pages, and to write metafields on those resources.
  • Online Store Pages (read_online_store_pages, write_online_store_pages) — to read pages via the dedicated Online Store Pages GraphQL API and write FAQ structured-data metafields.
  • Online Store Navigation (read_online_store_navigation, write_online_store_navigation) — to read your store's primary navigation so we can emit accurate BreadcrumbList JSON-LD.
  • Themes (read_themes) — to verify whether you've enabled our theme app embed (which injects the JSON-LD into your storefront) so we can guide you through the setup if it's off.
  • Legal Policies (read_legal_policies) — to read your store's refund, shipping, privacy, and terms-of-service policy URLs so we can reference them correctly in your storefront's structured data. We never modify these.

Additionally, for Shopify installs we collect:

  • Store metadata, including your shop's myshopify domain, primary domain, currency, and locale — read once on install and refreshed when you trigger a sync.
  • Sync history and audit results: timestamps of background jobs we ran for your store, the count and status of products / pages / collections we processed, and the readiness scores we computed against your store's structured data. Job history is retained while you use the App and is deleted when you uninstall.
  • AI usage counters: a per-store, per-month integer count of the AI extraction operations you've used (e.g. FAQ generation, recipe extraction). We do not log the AI prompts or responses themselves beyond the cache described below.
  • AI cache: when you use an AI feature, we hash the input content (e.g. the page body we send to an AI provider for FAQ extraction) and store the AI's response keyed by that hash. This avoids re-sending the same content for the same query and lowers your AI quota usage. The cache stores no personally identifying customer information; it stores merchant-facing content (page text, policy text) that is already publicly visible on your storefront.
  • Order attribution data (when the Revenue sources feature is enabled for your store): for each new order we record the order identifier, order total and currency, the order timestamp, and the marketing context Shopify reports for that order: the referring site's hostname, UTM campaign values, and the landing page path. We use this solely to show you which channels (search, AI assistants, social, email, paid, direct) your own orders come from. We never receive or store your customers' names, email addresses, phone numbers, or shipping/billing addresses, and this data is never shared or sold. Raw attribution rows are deleted after 90 days.
  • Review data (when you import or manage reviews): the rating, review title and text, reviewer display name, encrypted reviewer email, country and locale, review date, verification and source status, merchant replies, and image or video URLs included with the review. We keep a keyed, non-reversible email lookup solely so a Shopify customer access or deletion request can find records for that merchant without decrypting every reviewer address. Review records are never sent to AI providers. Approved review content is projected to Shopify metafields so your theme can render it without an AgentReady request on initial page load.
  • Review request data (only when a merchant explicitly enables verified-purchase review collection): the Shopify order identifier and date, purchased product and variant facts, locale, and customer email. The email is encrypted before it is stored, with a separate keyed, non-reversible lookup used for suppression and privacy requests. We use this data only to schedule and deliver the merchant-authorized review request. We do not collect the customer's name, phone number, shipping address, billing address, or payment details for this purpose, and we never send review-request data to an AI provider. An unsubmitted request and its encrypted contact data expire no later than 90 days after its scheduled send date.

Standalone (any-website) accounts. When you add a site without installing via Shopify, we collect:

  • Site metadata: the domain you claim, verification status, and optional profile details you provide or that we extract from publicly reachable pages (brand name, offerings, platform signals).
  • Public crawl content: HTML and text from pages we fetch during onboarding and periodic refreshes, used only to ground prompts and recommendations about your own site. We do not intentionally collect personal data of your site visitors via the crawl.
  • AI answer monitoring data: the questions we ask about your brand or category, the public answers returned by third-party AI assistants, mention rates, citations, competitors surfaced in those answers, and recommendation status you set in the dashboard.
  • Billing records for Stripe-billed workspaces: Stripe customer and subscription identifiers, plan, and payment status. Card numbers are handled by Stripe and are not stored on our servers.

We collect personal information directly from you, through your Shopify account, or using the following technologies:

  • "Cookies" — we use a single first-party session cookie (better-auth.session) to keep you signed in to the AgentReady dashboard at app.joinagentready.com. We do not use third-party advertising cookies or cross-site tracking technologies. For more information about cookies, and how to disable them, visit allaboutcookies.org.
  • "Log files" — our hosting provider records standard server logs including IP address, browser type, request paths, and timestamps. These logs are used for security, abuse prevention, and operational debugging, and are retained for up to 30 days unless required for legal compliance.
  • Product analytics — we may record first-party product events (for example signup, scan completed, checkout started) scoped to your account or workspace, without advertising cookies. Separately, if GA_MEASUREMENT_ID is configured on our marketing/app surfaces, Google Analytics 4 may load on non-embedded pages to measure aggregate funnel events. We do not sell this data.

We do not use third-party advertising pixels or cross-site tracking for behavioral advertising on merchant-facing App surfaces. Optional site-visitor tracking you may install later (see “Optional site visitor analytics”) is separate and only runs on properties you choose to instrument.

How Do We Use Your Personal Information?

We use the personal information we collect from you, your store, and/or your sites in order to provide the Service and to operate the App. Specifically, we use this personal information to:

  • Authenticate you when you sign in to the AgentReady dashboard.
  • For Shopify installs: read product, page, collection, blog post, and policy data from your Shopify store, generate Schema.org JSON-LD and AI-agent-readable JSON, and write that data back to your store's metafields so it appears on your storefront.
  • When a Shopify merchant explicitly enables verified-purchase review collection: use the minimum order and encrypted email data to schedule and deliver that merchant's review request, apply suppression, and process the shopper's response or privacy request.
  • For standalone sites: crawl publicly reachable pages, generate prompts, run AI answer monitoring, and show recommendations about your brand or category.
  • Send you transactional email about your account, billing, and the App's status (e.g. "first sync complete", "plan upgraded", payment recovery).
  • Process subscriptions and invoices via Shopify Billing and/or Stripe, depending on how you signed up.
  • Aggregate anonymized operational metrics (job durations, error rates, cache hit rates) to monitor and improve the App's reliability.
  • If (and only if) you turn on the optional benchmark setting, include your Search Console trend in anonymized, aggregated benchmarks — see the Google Search Console section below.
  • Comply with our legal obligations and enforce our Terms of Service.

We do not use your personal information for advertising, behavioral targeting, or to train any general-purpose machine-learning model. Your data is used to power the Service you use, and nothing else.

AI Providers and Answer Monitoring

AgentReady uses third-party AI systems in two distinct ways:

  • Content / extraction features (primarily Shopify): when you run FAQ generation, recipe extraction, policy summarization, alt text, or similar tools, we send relevant published or about-to-publish content snippets to providers such as xAI, Anthropic, OpenAI, and/or Google Gemini, and receive a structured response. We do not send your customers' personal information.
  • AI answer monitoring (Shopify and standalone): we submit brand- and category-level questions to public AI assistants / search APIs (for example ChatGPT, Perplexity, Gemini, and similar engines) and store the answers so we can show you mention rates, citations, and recommendations. Those queries contain your brand name, category, and related public context — not passwords, payment details, or private customer records.

AI calls happen only when you (or a job you started / a paid monitoring schedule you enabled) run a feature. For billing and abuse prevention we keep per-generation or per-run spend records (feature, model, token or credit counts, cache hit). Provider privacy policies:

Google Search Console and Limited Use

If you connect Google Search Console, the App can show you your own property's search trend (impressions, clicks, queries, and related Search Console metrics) in your dashboard, and may attach dated annotations when you complete recommended improvements. That data is yours and is used to power features that are visible in the App.

AgentReady's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we use Search Console data only to provide or improve user-facing features in AgentReady; we do not sell it; we do not use it for advertising; we do not allow humans to read it except for security, legal compliance, or with your affirmative agreement for a specific support case; and we do not transfer it to third parties except as needed to operate the Service under this policy.

Separately, you may opt in to include your property in anonymized, aggregated benchmarks we may publish. This setting is off by default; nothing is included unless you turn it on. When you do:

  • We only ever use indexed, bucketed trends computed across many properties — medians and ranges, never one property's raw numbers.
  • We never publish your domain, your store or site name, your absolute impression or click counts, or anything that identifies you.
  • We only publish a breakdown when enough properties are included that no single property can be inferred from it.
  • You can turn the setting off at any time, which removes your property from the next benchmark we compute.

Optional Site Visitor Analytics

AgentReady may offer an optional first-party tracking script you can install on your own website to measure page views, referrers, UTM parameters, and AI-referral classification (for example traffic from chatgpt.com or perplexity.ai). When that feature is enabled for your site:

  • Default mode is designed to avoid advertising cookies and cross-visit identifiers; a visit id may be scoped to session storage.
  • We do not intend to collect names, emails, or other direct identifiers of your visitors via that script.
  • You remain responsible for your own privacy notices and any consent requirements that apply to your site and audience.
  • Until you install and enable that script, we do not collect visitor analytics from your website through AgentReady.

Sharing Your Personal Information

We share your personal information only with the third-party service providers we rely on to operate the App. Each provider has access only to the data they need to perform their function, and is contractually obligated to keep it confidential:

  • Shopify (the platform you installed the App from) — receives the API requests we make to read your store data and write metafields. Shopify's privacy practices are described at shopify.com/legal/privacy.
  • Vercel (United States) — hosts the AgentReady web application and processes incoming HTTP requests. See vercel.com/legal/privacy-policy.
  • Neon (United States) — hosts the Postgres database where your account record, store record, and operational data are stored. See neon.com/privacy-policy.
  • Inngest (United States) — runs our background job queue (product sync, content sync, audit). Receives job payloads which may include Shopify resource IDs and short metadata strings (handles, titles). See inngest.com/privacy.
  • Resend (United States) — delivers transactional email (welcome, receipt, status notifications and, only when a merchant enables the feature, verified-purchase review requests). Receives the recipient email address and message body required for delivery. See resend.com/legal/privacy-policy.
  • Stripe (United States) — processes payments for standalone (non-Shopify Billing) subscriptions. Receives billing email, plan selection, and payment method details you enter on Stripe Checkout. See stripe.com/privacy.
  • Google — when you sign in with Google and/or connect Google Search Console, Google authenticates you and (for Search Console) provides the Search Console metrics described above. See policies.google.com/privacy.
  • AI providers and AI assistants — as described in “AI Providers and Answer Monitoring” above. Content-generation calls may go to xAI, Anthropic, OpenAI, and/or Google; answer-monitoring queries may go to public AI assistants / search APIs. We never send your customers' personal information to these providers for monitoring or content features.

We do not sell, rent, or trade your personal information to any other party. We may also share your personal information to comply with applicable laws and regulations, to respond to a subpoena, search warrant, or other lawful request for information we receive, or to otherwise protect our rights.

Behavioural Advertising

AgentReady does not use your personal information for behavioral advertising or targeted marketing, and we do not share your data with any advertising network. There is therefore nothing to opt out of in this regard.

Your Rights

If you are a European resident (or a resident of any jurisdiction granting similar rights, including the United Kingdom, California, and Canada), you have the right to access personal information we hold about you, and to ask that your personal information be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information below.

Additionally, if you are a European resident we note that we are processing your information in order to fulfill contracts we might have with you (specifically, the App services you have installed and use), or otherwise to pursue our legitimate business interests listed above. Please note that your information will be transferred outside of Europe, including to Canada and the United States, where our hosting and AI providers operate.

Data Retention

We retain your account record, workspace membership, store and/or site records, and operational data for as long as your account is active.

Shopify's mandatory privacy webhooks cover customer and shop data separately. A customers/data_request request includes matching imported review records in the merchant response. A customers/redact request permanently deletes that customer's review rows and media for the requesting shop, pseudonymizes applicable service-email audit rows, and rebuilds the affected Shopify review snapshots. When Shopify later sends shop/redact, deleting the Store cascades through all Reviews, review media, import receipts, job history, sync records, and AI cache entries owned by that shop.

Unsubmitted verified-purchase review requests, including their encrypted customer email and bounded order context, expire no later than 90 days after their scheduled send date. A review a shopper deliberately submits becomes a merchant-owned review record and follows the review deletion and privacy-webhook rules above.

For standalone workspaces and sites, email privacy@joinagentready.com to request export or deletion of your workspace, sites, answer-monitoring history, and account. We will complete deletion requests within 30 days except where we must retain records for legal, security, or billing compliance (for example Stripe invoice history held by Stripe).

You may also delete your AgentReady account at any time by emailing us at the address below or using in-app account deletion where available.

Changes

We may update this Privacy Policy from time to time in order to reflect, for example, changes to our practices or for other operational, legal, or regulatory reasons. The "Effective" date at the top of this page indicates when the policy was last revised. Material changes will be communicated to active App users via email.

Contact Us

For more information about our privacy practices, if you have questions, or if you would like to make a complaint, please contact us by email at privacy@joinagentready.com.

AgentReady is operated by CaffeineCommerce. Mailing address available on request to the email above.