Privacy, explained plainly.

Redirect 301 AI is built to repair store paths, not profile shoppers. This policy explains what the app handles, what it deliberately leaves out, and how merchants can control their data.

Effective August 12, 2026 Last updated August 12, 2026

Short version: the storefront detector sends only the information needed to understand a broken path. Application code does not request or store visitor IP addresses, query strings, URL fragments, full referrer URLs, or user-agent values. We do not sell personal data or use it for advertising.

1. Scope and roles

This Privacy Policy applies to the Redirect 301 AI Shopify application, its Theme App Embed, its app-proxy endpoint, and this marketing website (together, the “Service”). The provider of Redirect 301 AI is referred to as “we,” “us,” or “our.”

For store data processed to provide the app, the Shopify merchant determines how the app is used for that store. Shopify has its own privacy practices and terms. A storefront visitor should contact the relevant merchant about the merchant’s privacy practices.

The supplied static marketing website does not include analytics, advertising pixels, account forms, or tracking cookies. Hosting providers may process ordinary request data, such as network logs, under their own policies.

2. Data we handle

The app handles the following categories only as needed to provide its features:

Category Examples Why it is needed
Shop and authentication data Shop domain, Shopify shop ID, OAuth session and access token, permitted merchant-user session fields Install the app, authenticate requests, access approved Shopify APIs, and keep tenant data separated
Catalog and store configuration Published product, collection, article, blog, page, navigation, and existing URL redirect information Find eligible live destinations, scan links, detect conflicts, and synchronize Shopify redirects
Storefront 404 observations Normalized pathname, random event ID, referrer hostname, day-level human or bot counts, first and last seen timestamps Populate the 404 Inbox, measure path frequency, prevent duplicate events, and suggest repairs
Link Scanner data Scanned page URLs, destinations, HTTP outcomes, redirect chains, link context, and suggested repairs Report broken internal or external links, orphan pages, and weak internal linking
App settings and work records Plan, usage counters, pattern rules, simulations, redirect jobs, audit events, worker state, and feature preferences Apply plan limits, run approved work, provide status, preserve merchant choices, and troubleshoot failures
Billing status Shopify-managed subscription status, plan handle, billing period, and trial state Confirm Free or Pro entitlements. Payment details remain with Shopify

The detector may receive a truncated user-agent string for in-memory bot classification. The user-agent string itself is not persisted. Test events are kept out of normal traffic analytics and plan quotas.

3. Data we deliberately avoid

Application code is designed not to request or persist:

  • storefront visitor IP addresses;
  • query strings or URL fragments from 404 page visits;
  • full referrer URLs (only an eligible hostname may be stored);
  • visitor user-agent values after bot classification;
  • customer IDs, order IDs, customer accounts, or customer sessions; or
  • payment card or bank information.

Before a 404 observation becomes a stored path, its segments are screened for sensitive-looking shapes. Email addresses, UUIDs, JWT-like strings, long hexadecimal strings, and other token-like values cause that observation to be discarded.

4. How data is used

We use the data described above to:

  • authenticate the merchant and provide the embedded Shopify app;
  • collect and aggregate eligible storefront 404 observations;
  • mirror relevant published catalog paths and existing Shopify redirects;
  • suggest, verify, simulate, review, create, retry, and report exact redirects;
  • scan storefront links and report repair opportunities;
  • enforce plan allowances, retention windows, and safety settings;
  • maintain security, prevent duplicate or abusive events, and diagnose failures;
  • honor Shopify compliance webhooks, merchant exports, and deletion requests; and
  • comply with applicable law and protect the Service, merchants, and others.

We do not sell data, build advertising profiles, or use storefront observations for cross-store advertising.

5. Optional AI processing

Deterministic target suggestions do not require OpenAI. If a merchant explicitly enables AI pattern proposals and an API key is configured, the app may send already-stored source paths, suggested target paths, and path-level hit samples to OpenAI to propose a restricted mapping.

  • AI processing is opt-in for the merchant.
  • The app does not add visitor IPs, full referrers, customer IDs, or customer sessions to the prompt.
  • Requests are configured with store: false.
  • A provider response cannot activate a pattern or write a Shopify redirect directly.
  • Every proposal must pass the app’s compiler, simulation, and deterministic safety checks.
  • If AI is disabled or unavailable, deterministic pattern discovery remains available.

OpenAI processes any submitted data under the merchant’s configuration and OpenAI’s applicable terms and privacy commitments.

6. When data is shared

We disclose data only as needed for the following purposes:

  • Shopify: authentication, approved Admin API actions, managed billing status, app-proxy delivery, and compliance webhooks.
  • Infrastructure providers: hosting, managed databases, backups, content delivery, logging, and security operations required to run the Service.
  • OpenAI: only for optional merchant-enabled pattern proposals, as described above.
  • Legal and safety: when required by law or reasonably necessary to protect rights, safety, security, or the integrity of the Service.
  • Business changes: as part of a merger, acquisition, financing, reorganization, or sale, subject to appropriate confidentiality and notice requirements.

We do not disclose storefront observation data to data brokers or advertising networks.

7. Retention and deletion

Observation detail

Day-level observation history, completed link scans, old simulations, and eligible terminal jobs use the store’s current plan retention window: 7 days on Free and 365 days on Pro. Expired duplicate-event receipts and rate-limit windows are deleted according to their shorter expiry periods. A path-level lifetime summary—such as the normalized path, status, and first/last seen timestamps—may remain while the app is installed so the merchant retains a resolution ledger.

Operational and account data

Catalog records, redirect ownership records, active or retryable jobs, audit records, shop configuration, and Shopify sessions are not governed by the ordinary observation-history window. They are kept while needed to operate the app, preserve merchant choices, maintain security, meet legal obligations, or resolve disputes.

Uninstall and Shopify redaction

When the app is uninstalled, active processing and automation are disabled, pending work is stopped, and Shopify sessions are removed. Tenant data is deleted when Shopify sends the required shop/redact compliance webhook, or earlier when a valid deletion request is fulfilled. Customer data-request and customer-redaction webhooks are acknowledged without retaining their payloads because the app does not collect customer IDs, order IDs, or customer sessions.

Backup copies may persist for a limited recovery cycle before being overwritten, unless longer retention is legally required.

8. Security

The Service uses Shopify authentication, signed webhooks and app-proxy requests, per-store data separation, HTTPS in production, access controls, rate limits, payload-size limits, path normalization, live target checks, and auditable redirect jobs. Secrets and production database access are restricted to the systems that need them.

No method of transmission or storage is completely secure. Merchants are responsible for securing their Shopify accounts, choosing appropriate app permissions, controlling staff access, and reviewing redirects before activation.

9. Merchant choices and privacy rights

Depending on location and applicable law, a merchant may have rights to access, correct, export, delete, restrict, or object to certain processing.

  • The app’s Settings area provides a tenant data export.
  • AI processing, Safe Autopilot, approved-pattern automation, and first-hit rescue are configurable and can be disabled.
  • The Theme App Embed can be disabled in the Shopify Theme Editor.
  • Uninstalling the app stops app activity and initiates Shopify’s uninstall and redaction lifecycle.
  • A merchant can use the support channel shown in the app or its Shopify App Store listing to request assistance or earlier deletion.

We may need to verify that a requester is authorized for the relevant shop. If a request concerns a storefront visitor, the visitor should first contact the merchant that operates the store.

Children

The Service is a business tool for Shopify merchants and is not directed to children. We do not knowingly use it to collect children’s personal data.

International processing

Shopify, infrastructure providers, and optional AI providers may process data in countries other than where a merchant or visitor is located. Where required, appropriate contractual or legal transfer mechanisms should be used by the relevant provider.

10. Changes and contact

We may update this policy as the product, providers, or legal requirements change. The “Last updated” date above shows the latest revision. Material changes will be communicated through the app, the Shopify App Store listing, or another appropriate channel.

For privacy questions or requests, use the support contact published inside Redirect 301 AI or on its Shopify App Store listing. Include your .myshopify.com domain and do not send passwords, access tokens, customer records, or other secrets.