NEW The Enterprise AI Readiness Guide 2026 is here — download the free report →
Home SEOconvert Privacy Policy

SEOconvert Privacy Policy

SEOConvert (“the App”) is an AI-powered SEO and content automation assistant for Shopify stores, operated by Progryss (“we”, “us”, “our”).

This policy explains what the App collects, why, who it is shared with, and how long it is kept. By installing or using the App you agree to this policy.

What we collect

From merchants

  • Store identity — your myshopify.com domain, Shopify store ID, store name, store contact email, customer-facing domain, currency, timezone and Shopify plan name, read from the Shopify Admin API when you install.
  • Copies of the store content you ask the App to work on — products, collections, pages and blog articles: title, handle, URL path, body text, images and their alt text, tags, meta title and description, and heading counts.
  • Settings you enter — brand voice and writing preferences, blog defaults and author names, target keywords, schedule cadences and times, structured-data settings, search-engine verification codes and competitor URLs.
  • Content the App generates for you — meta titles and descriptions, image alt text, blog drafts and topic suggestions, and FAQ and How-To extractions.
  • Operational records — scan and optimisation runs, image-optimisation history, broken-link records, speed reports, your credit ledger, subscription state, coupon redemptions and job schedules.
  • Google Search Console details, only if you connect an account — the Google account email, the site you select, the list of sites that account can access, and performance metrics for your pages (queries, clicks, impressions, average position). The OAuth refresh and access tokens are encrypted at rest.
  • Shopify access tokens and sessions, so the App can act on your store on your behalf.

From shoppers and customers

Nothing. The App holds no customer names, email addresses, phone numbers, postal addresses or order data. It does not request Shopify’s customer or order permissions at all — the permissions it asks for cover products, content, online-store pages and navigation, themes and files, and nothing else.

One item is worth stating precisely, because it does run on your storefront. The App’s theme extension places a 1×1 pixel image only on your 404 page, so that broken URLs nothing links to any more can still be found. When a visitor lands on a page that does not exist, that pixel reports:

  • the path that returned 404, and
  • where the visitor came from, only when that was another page on your own store — a referrer from any other site is discarded and never stored.

It sends no cookies, and it records no IP address, no browser or device information, and nothing that identifies the visitor. It runs on no other page of your store.

From the public web

  • Your own storefront — pages are fetched to check for broken links, read robots.txt and your sitemaps, verify structured data, and read the markup your theme already publishes.
  • Competitor pages you name — if you enter competitor URLs, those pages are fetched and their headings stored, so topic suggestions can fill the gaps they reveal.
  • Google PageSpeed Insights is asked to measure your store URLs when you run a speed check.

How we use it

  • To run the features you switch on: audits and scores, meta and alt-text generation, structured data, sitemaps and llms.txt, broken-link detection and redirects, image optimisation, blog writing and scheduling, and speed measurement.
  • To run the schedules you set, and to stop running them when your plan no longer includes them.
  • To meter and bill usage — the credit ledger records what each action cost, so the number on your screen can be checked against the movements behind it.
  • To operate, secure and debug the App, and to show your store in our own admin panel for support (store name, domain, plan, install status and usage totals).

We do not sell your data, use it for advertising, or use it to build products for anyone other than you.

AI processing (OpenAI)

Text generation and extraction run on OpenAI’s API. What is sent is the material the task needs and no more: the page title and body text, your brand voice and writing settings, target keywords, and — for topic suggestions — the headings of competitor pages you named.

Which model each kind of work runs on is a setting we manage, so it can be changed without a release. No customer personal data is sent, because the App holds none. OpenAI does not use data submitted through its API to train its models.

Sharing & sub-processors

We share data only with the services needed to run the App:

  • Shopify — the source of your store data and the destination of every change the App writes back. Shopify also handles all billing.
  • OpenAI — text generation and extraction, as described above.
  • Google — Search Console (read-only, and only if you connect an account) and PageSpeed Insights.
  • Our hosting and database provider — where the App runs and stores the data described above.

We may also disclose data where we are legally required to.

Google user data — Limited Use

SEOConvert’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We request a single, read-only Google scope (https://www.googleapis.com/auth/webmasters.readonly) plus your account email. Search Console data is used only to display your store’s search performance inside the app. We never write to Search Console, never sell or transfer this data, never use it for advertising, and no human reads it except where required for security or to comply with law.

Retention & deletion

While the App is installed, your store content copies, settings, generated content and operational records are retained so the App can work.

When you uninstall:

  • Your Shopify access tokens and sessions are deleted immediately, in the uninstall webhook. A token for a store that has removed the App is a live credential, and it is not kept.
  • All scheduled work stops immediately.
  • Everything else is kept for seven days, and then permanently deleted. This is deliberate: a merchant who uninstalls to try something else, or who uninstalls from the wrong store, can reinstall inside that window and find their settings, credits, history and connections intact. Reinstalling within seven days restores them; after seven days they are gone and cannot be recovered.
  • If you connected Google Search Console, we revoke that grant at Google before deleting our copy, so no authorisation is left behind in your Google account.
  • After deletion we keep a minimal record of the store — domain, store name, and the install and uninstall dates — so we can see that a store installed and left. It contains none of your content, settings or credentials. A shop/redact request removes this too.

Two things are stored outside our database and follow their own schedule: image backups taken before compression are written to your own Shopify Files, kept for seven days so you can restore an image, and then purged; and records of compliance requests we have received are kept as proof that each was acted on, with direct identifiers (emailphone) stripped out before storage.

Shopify compliance webhooks (GDPR)

SEOConvert implements all three of Shopify’s mandatory privacy webhooks:

  • customers/data_request — because the App stores no customer personal data, there is no customer data to export. We acknowledge every request, record it, and confirm this to the merchant within 30 days.
  • customers/redact — likewise acknowledged and recorded; the App holds no customer records to delete.
  • shop/redact — permanently deletes all data associated with the store, including the minimal record described above.

Shopify sends shop/redact 48 hours after an uninstall, and requires the action to be completed within 30 days of the request. We complete it at the end of the seven-day window described above — day five of the thirty — so the request is honoured in full while the reinstall window is preserved. If the store reinstalls before then, it is an active installation again and its data is not erased.

Security & data transfers

All traffic to and from the App is over HTTPS. Credentials held for you — your Google OAuth refresh and access tokens — are encrypted at rest. Access to production systems is limited to staff who need it, and our internal admin panel is behind its own authentication with sign-in throttling.

Our servers and the sub-processors listed above may be located outside your country, so your data may be transferred and processed internationally. We rely on the contractual protections offered by those providers for such transfers.

Your rights

Depending on where you are, you may have the right to access, correct, export or delete the data we hold about you, to object to or restrict processing, and to withdraw consent.

  • Access and correction — most of what the App holds is visible and editable inside the App itself.
  • Withdrawing a connection — you can disconnect Google Search Console at any time from the App, which revokes the grant at Google.
  • Deletion — uninstalling the App deletes your data after the seven-day window described above. If you want it deleted sooner, or want a copy of it, write to us at the address below and we will action it.

We do not discriminate against anyone for exercising these rights.

Contact

Email: progryss@gmail.com
Business: Progryss Media Private Limited, First Floor, Workspace By Innova, H-54, H Block, Sector 63, Noida, Uttar Pradesh 201301
Governing law: India

Recent Posts

    Recent Comments

    No comments to show.

    Archives

    No archives to show.

    Categories

    • No categories