Recommendo Privacy Policy

Recommendo Privacy Policy

Effective Date: 30th July 2026

Welcome to Recommendo ("Recommendo", "we", "our", or "us"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you install, access, or use the Recommendo application (the "App") and any related AI product recommendation, guided shopping, image search, analytics, and storefront assistant services (collectively, the "Services").

We are committed to complying with global data-protection and privacy laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK Data Protection Act 2018, the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), the Singapore Personal Data Protection Act (PDPA), the India Digital Personal Data Protection Act 2023 (DPDP Act), the Australian Privacy Act 1988, and other applicable regional legislation across the United States (US), Europe (EU & UK), and Asia-Pacific (APAC).

If you have any questions or concerns, please contact us at apps@seventhtriangle.com


1. Who We Are

Recommendo is a Shopify application developed and maintained by Seventh Triangle Consulting. We act as a data processor when processing information on behalf of Shopify merchants ("Merchants") and as a data controller for information we collect about visitors to our marketing site, prospective customers, or Merchants who contact us directly.


2. Information We Collect

Category

Examples

Source

Purpose

Merchant Account Data

Store name, store URL, contact email, Shopify plan, billing status, Shopify access tokens, granted scopes, locale, currency, and app installation/session details

Directly from Merchant via Shopify OAuth and Shopify APIs

• Provide, maintain & improve the App

• Authenticate Merchant access

• Billing and subscription management

Storefront Assistant Data

Shop domain, shopper text queries, guided search choices, optional uploaded image attributes, product page context, collection context, cart item count, cart total, product IDs, product handles, variant IDs, product titles, product images, product URLs, and add-to-cart activity

Automatically from shopper interactions with the Recommendo storefront assistant, Shopify storefront pages, and app proxy requests

• Understand shopper intent and return relevant product recommendations

• Support text search, guided product advisor, image-based discovery, and add-to-cart functionality

• Keep product recommendations tied to Shopify catalog data

Merchant Usage Data

App settings, onboarding status, theme extension status, widget configuration, enabled recommendation modes, catalog health metadata, usage counters, event type, mode, status, search query, result count, product keys, and recommendation analytics

Automatically via in-App events, Merchant configuration, Shopify APIs, and storefront app embed activity

• Operate & optimize recommendation functionality

• Provide Merchant dashboards and catalog health insights

• Product analytics, roadmap planning, fraud prevention, and abuse detection

AI Provider & BYOK Data

Merchant-selected AI provider, encrypted API key, key hint, key test status, prompts or shopper inputs needed for intent parsing, recommendation explanations, query shaping, and image attribute extraction

Directly from Merchants for BYOK setup and automatically from recommendation requests processed through supported AI providers

• Route AI requests through the configured provider

• Generate product-search queries and recommendation explanations

• Extract image attributes for visual product discovery

Support & Communications Data

Name, email address, store domain, support messages, issue details, screenshots, and related diagnostic information voluntarily provided to us

Directly from Merchants or their authorized users

• Respond to support requests

• Troubleshoot and improve the Services

Sensitive data: We do not intentionally collect or process special categories of personal data (e.g. health, biometric, or children's data). Cardholder data is handled exclusively by Shopify's PCI-DSS-compliant infrastructure and is not processed by Recommendo. Shoppers should not submit sensitive personal information in chat messages or image uploads.


3. Cookies & Similar Technologies

We use necessary Shopify cookies, app session storage, and browser local storage to:

  • Authenticate Merchants into the App dashboard.
  • Remember preferences and storefront widget configuration.
  • Preserve the shopper's current Recommendo conversation state locally in the browser for a short period.
  • Cache assistant state and product recommendation results temporarily to improve storefront performance.

Where consent is required (e.g., under GDPR or ePrivacy Directive), Merchants are responsible for presenting any required consent notice on their storefront. Recommendo supports use of necessary storage for product recommendation and storefront assistant functionality.


4. Legal Bases for Processing (GDPR/UK GDPR)

We rely on the following legal grounds:

  1. Contractual Necessity - to provide the Services requested by installing and using the App.
  2. Legitimate Interests - to improve and secure our Services, communicate with you, provide recommendation analytics, support catalog health features, and prevent fraud.
  3. Consent - for optional cookies, marketing communications, image uploads, and any processing that requires explicit consent.
  4. Legal Obligation - to comply with applicable law, tax, accounting, and Shopify platform requirements.

5. How We Use Your Information

  • To deliver, operate, maintain, and update the App.
  • To authenticate access and secure Merchant accounts.
  • To enable shoppers to ask product questions, use guided flows, upload product-reference images where enabled, and receive product recommendations.
  • To fetch product details needed to display recommendations correctly, including names, prices, images, URLs, availability, tags, and metafields.
  • To provide Merchants with recommendation performance analytics, usage counters, catalog health insights, and setup status.
  • To process invoicing and collect fees via Shopify's Billing API, where applicable.
  • To answer support requests and resolve issues.
  • To comply with legal obligations, Shopify mandatory privacy webhooks, and enforce our Terms of Service.

6. How We Share Information

We do not sell personal data. We only share information:

  • Within Seventh Triangle Consulting and its subsidiaries on a need-to-know basis;
  • With Service Providers acting on our behalf (e.g., AWS for hosting and managed database providers such as MongoDB for app, session, store setting, catalog metadata, and recommendation analytics data storage) under data-processing agreements and appropriate safeguards;
  • With AI Providers selected or enabled for the App, such as OpenAI, Google Gemini, or Anthropic, for limited purposes including intent parsing, query shaping, recommendation explanations, and image attribute extraction;
  • With Shopify as required by the Shopify App Store Partner Program, Shopify API terms, app proxy operation, billing, authentication, catalog access, and mandatory privacy webhook requirements;
  • With Merchants through the App dashboard in the form of store-level recommendation analytics, catalog health information, usage data, and configuration data;
  • For Legal Reasons such as responding to lawful requests from regulators or to protect our rights, property, or users.

Where data is transferred outside the EEA/UK, we rely on approved transfer mechanisms such as Standard Contractual Clauses (SCCs) or an adequacy decision.


7. International Data Transfers

Our application infrastructure is hosted using Amazon Web Services (AWS), including infrastructure in Mumbai (AP-South-1). Depending on your location, your personal data may be transferred to and processed in countries other than your own, including where Shopify, AI providers, or other service providers process data. We implement safeguards including:

  • ISO 27001-certified data centres.
  • Encryption in transit (TLS 1.2+) and at rest where supported by the underlying infrastructure.
  • Appropriate contractual safeguards with service providers where required by applicable law.

8. Data Subject & Consumer Rights

Depending on where you reside, you may have rights to:

  • Access, correct, or delete personal data;
  • Object to or restrict processing;
  • Data portability;
  • Opt-out of marketing communications;
  • Withdraw consent at any time without affecting the lawfulness of prior processing;
  • Lodge a complaint with a supervisory authority (e.g., ICO in the UK, DPA in your EU member state, or local privacy regulator).

To exercise these rights, email apps@seventhtriangle.com. If your request relates to a Shopify Merchant's customer account or storefront interaction data, we may direct you to the relevant Merchant or process the request through Shopify's mandatory privacy webhooks. We will respond within the deadlines mandated by applicable law (e.g., 30 days under GDPR).


9. Security Measures

  • TLS encryption (HTTPS) for data in transit.
  • Encryption at rest where supported by AWS and database infrastructure.
  • Encryption of Merchant BYOK API keys before storage.
  • Principle of least privilege & role-based access controls.
  • Shopify OAuth, app proxy signature validation, and Shopify mandatory privacy webhook handling.
  • Monitoring, logging, and issue investigation for operational security.

Although we implement industry-standard safeguards, no system is 100% secure. Please keep your Shopify credentials and any connected AI provider API keys confidential and immediately notify us of any security incidents.


10. Data Retention

We retain Merchant, storefront configuration, catalog health metadata, recommendation analytics, usage counters, encrypted BYOK key records, and related shop-scoped records for as long as the Merchant's store uses the App or as needed to provide the Services. Storefront conversation state may be preserved locally in the shopper's browser for a short period and can be cleared by the shopper through browser storage controls. We may retain limited records for legal, accounting, security, dispute-resolution, and backup purposes where permitted by law. When a Merchant uninstalls the App or Shopify sends a customer or shop redaction request, we take steps to delete or anonymize applicable data in accordance with Shopify requirements and applicable law.


11. Children's Privacy

Our Services are not directed to children under 16. We do not knowingly collect personal data from minors. If you become aware that a child has provided us with personal information, please contact us and we will take steps to delete such data.


12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version with an updated "Last Updated" date and, where required, provide notice (e.g., via the App dashboard or email). Continued use of the Services after such changes constitutes acceptance.


13. Contact Us

If you have any questions, requests, or complaints regarding this Privacy Policy or our privacy practices, please contact:

Privacy Team
Recommendo / Seventh Triangle Consulting
Second Floor, The Berry Coworks, Plot No 15, Sector-142, Noida, Uttar Pradesh - 201304
Email: apps@seventhtriangle.com
Data Protection Officer (EU/UK): Sushant Gupta, sushant@seventhtriangle.com


© 2026 Seventh Triangle Consulting. All rights reserved.