SEOConvert (“the App”) is an AI-powered SEO and content automation assistant for Shopify stores, operated by Progryss (“we”, “us”, “our”).
This policy explains what the App collects, why, who it is shared with, and how long it is kept. By installing or using the App you agree to this policy.
myshopify.com domain, Shopify store ID, store name, store contact email, customer-facing domain, currency, timezone and Shopify plan name, read from the Shopify Admin API when you install.Nothing. The App holds no customer names, email addresses, phone numbers, postal addresses or order data. It does not request Shopify’s customer or order permissions at all — the permissions it asks for cover products, content, online-store pages and navigation, themes and files, and nothing else.
One item is worth stating precisely, because it does run on your storefront. The App’s theme extension places a 1×1 pixel image only on your 404 page, so that broken URLs nothing links to any more can still be found. When a visitor lands on a page that does not exist, that pixel reports:
It sends no cookies, and it records no IP address, no browser or device information, and nothing that identifies the visitor. It runs on no other page of your store.
robots.txt and your sitemaps, verify structured data, and read the markup your theme already publishes.llms.txt, broken-link detection and redirects, image optimisation, blog writing and scheduling, and speed measurement.We do not sell your data, use it for advertising, or use it to build products for anyone other than you.
Text generation and extraction run on OpenAI’s API. What is sent is the material the task needs and no more: the page title and body text, your brand voice and writing settings, target keywords, and — for topic suggestions — the headings of competitor pages you named.
Which model each kind of work runs on is a setting we manage, so it can be changed without a release. No customer personal data is sent, because the App holds none. OpenAI does not use data submitted through its API to train its models.
We share data only with the services needed to run the App:
We may also disclose data where we are legally required to.
SEOConvert’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We request a single, read-only Google scope (https://www.googleapis.com/auth/webmasters.readonly) plus your account email. Search Console data is used only to display your store’s search performance inside the app. We never write to Search Console, never sell or transfer this data, never use it for advertising, and no human reads it except where required for security or to comply with law.
While the App is installed, your store content copies, settings, generated content and operational records are retained so the App can work.
When you uninstall:
shop/redact request removes this too.Two things are stored outside our database and follow their own schedule: image backups taken before compression are written to your own Shopify Files, kept for seven days so you can restore an image, and then purged; and records of compliance requests we have received are kept as proof that each was acted on, with direct identifiers (email, phone) stripped out before storage.
SEOConvert implements all three of Shopify’s mandatory privacy webhooks:
customers/data_request — because the App stores no customer personal data, there is no customer data to export. We acknowledge every request, record it, and confirm this to the merchant within 30 days.customers/redact — likewise acknowledged and recorded; the App holds no customer records to delete.shop/redact — permanently deletes all data associated with the store, including the minimal record described above.Shopify sends shop/redact 48 hours after an uninstall, and requires the action to be completed within 30 days of the request. We complete it at the end of the seven-day window described above — day five of the thirty — so the request is honoured in full while the reinstall window is preserved. If the store reinstalls before then, it is an active installation again and its data is not erased.
All traffic to and from the App is over HTTPS. Credentials held for you — your Google OAuth refresh and access tokens — are encrypted at rest. Access to production systems is limited to staff who need it, and our internal admin panel is behind its own authentication with sign-in throttling.
Our servers and the sub-processors listed above may be located outside your country, so your data may be transferred and processed internationally. We rely on the contractual protections offered by those providers for such transfers.
Depending on where you are, you may have the right to access, correct, export or delete the data we hold about you, to object to or restrict processing, and to withdraw consent.
We do not discriminate against anyone for exercising these rights.
Email: progryss@gmail.com
Business: Progryss Media Private Limited, First Floor, Workspace By Innova, H-54, H Block, Sector 63, Noida, Uttar Pradesh 201301
Governing law: India