Privacy Policy
AgentChannel (“we,” “us,” “our”), operated by LAN Holdings LLC, is a Shopify app that audits how your store appears to AI agents and shows you what to fix. This policy covers what we collect, how we use it, how long we keep it, and your rights.
In short: we read your catalog and content settings to run the audit, and — when the order-data features are enabled for your store — we read your order data for two things: to show which AI agent referred an order, and to rank your products by recent sales so you fix the ones that matter most. We do not read your customers’ names, email addresses, phone numbers, or addresses. On the paid plan, when you ask us to fix a store policy or product description, we use AI (Anthropic and OpenAI, via Vercel) to draft it from your store’s own business content — never your customers’ personal data — and we never use your data to train AI models. Shopify handles all payments, so we never see card details. On the paid plan, after you grant an optional permission, we can apply a fix you ask for, such as setting an unlisted product to active. That change writes only product settings; it never touches personal data and is usually reversible from the app.
1. What we collect
When you install AgentChannel on your Shopify store, we read store data through the permissions you approve during install. The data we collect is:
- Catalog and content configuration. Your products, collections, pages, articles, store policies, metaobjects, publications, and theme settings — read to run the AI Readiness Audit and show you which Shopify field to change for each gap.
- Order data. When the order-data features are enabled for your store, we read your orders for two purposes. First, to show how AI shopping agents are driving sales: we look at an order’s referral and channel information (such as the publication or the website a shopper came from) to identify which AI agent, if any, sent that order. Second, to rank your products by recent revenue: once a day we add up the last 30 days of order line items into a per-product sales total, so the app can show you the highest-impact products to fix first. We do not read your customers’ names, email addresses, phone numbers, or addresses to do this. See “How long we keep it” for what we store and for how long.
- Store domain and app authorization. Your .myshopify.com domain, the encrypted Shopify access token, and the permissions you granted, so the app can call Shopify on your behalf.
- Account and contact information. The email address associated with your shop and any messages you send our support, so we can run your account and reply to you.
- Audit results. The findings each audit produces, so you can review them and track them over time.
- Free no-install audit. If you run the free audit at agentchannel.app/audit, we read your public storefront pages and query Shopify’s public agent catalog. To email you the full report, we collect the email address you enter and use it to send the report and related follow-up about your audit. Every such email has an unsubscribe link, and we keep a short suppression record so we can honor your opt-out.
- Anonymous app usage. Aggregate, non-identifying events about how the app is used, so we can improve it.
What we do not collect. We do not have access to your customers’ personal profiles: we do not read, receive, or store customer names, email addresses, phone numbers, or shipping or billing addresses. We read order data only as described above (referral and channel information, and line-item sales totals), not customer contact details. Shopify processes all payments, so we never see your customers’ payment card details, and we never move money. The optional write permissions (see “How we use it”) let us change a product’s visibility status and, if you complete the brand-voice setup, save your brand-voice settings; neither grants access to personal data.
2. Website visitors, cookies, and analytics
Our marketing website (agentchannel.app) uses analytics to understand how the site is used. Google Analytics 4 sets cookies (such as _ga) and shares aggregate visit data with Google; we also use Vercel Analytics, which is cookieless. We use these only to measure and improve the site, never to build advertising profiles, and we do not sell this data. You can opt out by blocking cookies in your browser or using Google’s opt-out add-on. If you visit from the EU or UK, we are still putting a cookie-consent mechanism in place for that traffic; until it is, please decline cookies in your browser if you do not want them. This section is about the marketing website — the app itself, inside the Shopify admin, does not set these cookies.
3. How we use it
We use the data above to run the AI Readiness Audit and show you the results: whether AI agents find your store, whether resellers outrank you, where the facts are wrong, and the exact Shopify field to fix each gap — and, on the paid plan, to apply the fixes you authorize (below). When the order-data features are enabled, we use your order data for two things: to show which AI agent referred each order, and to rank your products by recent sales so you can prioritize the highest-impact fixes. We do not use any of this data for anything else. The AI Readiness Audit is deterministic: we compute the findings directly from your store data, with no AI. Separately, on the paid plan, when you ask us to draft a store-policy or product-description fix, we send that store content (never your customers’ personal data) to an AI provider to generate a draft you review before applying — see “Service providers.” We never use your data to train AI models.
Lawful bases (EU/UK). Where we act as the controller of your own account data (such as login, billing, support, and marketing) and you are in the European Economic Area or the United Kingdom, we rely on these GDPR bases: contract, to provide the Service to you under our Terms; legitimate interests, to operate, secure, and improve the Service, balanced against your rights (you can object to processing based on legitimate interests); and legal obligation, where the law requires it. We send marketing email only with your consent, which you can withdraw at any time.
Applying a fix (paid plan). After you grant the optional edit permission (you can decline it, and revoke it later), and only when a fix is requested from your store, we apply the change you approved — for example setting an unlisted product to active, updating a product description, or publishing a store policy you reviewed — one at a time. Anyone with access to AgentChannel in your Shopify admin can request a fix, so manage that access through your Shopify staff permissions. Each change is recorded and usually reversible from the app, and writes only the product or policy content you approved; it does not write or change any order, customer, or payment data.
4. How we share it
We do not sell your data. We share it only with the infrastructure providers listed in “Service providers” below (bound by data-processing terms and acting on our instructions) and, for our marketing website, the analytics described in “Website visitors, cookies, and analytics.”
5. Where data is stored, and security
Your data is stored in a Supabase Postgres database in the us-east-1 region (Northern Virginia, USA). Each store’s data is walled off from every other store at the database level through row-level security policies. All data is encrypted in transit and at rest. If we become aware of a personal-data breach affecting your data, we will notify you without undue delay so you can meet your own notification obligations.
AgentChannel’s infrastructure is located in the United States. Where we process personal data of individuals in the EU or UK, we make that data available for transfer under an appropriate safeguard — primarily the European Commission’s Standard Contractual Clauses (with the UK International Data Transfer Addendum where UK data is involved), which we enter into with merchants as part of our data-processing terms. We do not currently rely on the EU–U.S. Data Privacy Framework.
6. How long we keep it
- Audit results, store configuration, and fix history: kept while you have AgentChannel installed, then deleted when you uninstall, as described in “Uninstall and deletion.”
- Order-derived data (AI-agent attribution and per-product sales totals): kept while you have AgentChannel installed, then deleted when you uninstall, as described in “Uninstall and deletion.” The per-product sales total is an aggregate figure; it does not identify any individual order or customer.
- Free no-install audit results: kept for 30 days, then automatically deleted. The unsubscribe suppression record is kept longer so we can keep honoring your opt-out.
- Anonymous app usage: aggregated and retained without identifying any individual.
7. Uninstall and deletion
When you uninstall, your data is immediately hidden and all background work stops. About 48 hours later Shopify sends a shop/redact signal and we permanently delete your records (the same deletion applies if we terminate your access). That 48-hour gap is a safety net: reinstall within it and your audit history returns; after it, the data is gone (encrypted backups expire on their own within about 7 days, consistent with the GDPR principle of keeping personal data no longer than necessary).
8. GDPR, CCPA, and your rights
For your customers’ personal data, you (the merchant) are normally the data controller and Shopify acts as your processor; Shopify forwards its compliance and data-subject webhooks to apps. To the limited extent AgentChannel processes any such data, it does so as a processor on your behalf and only on your instructions. We do not store your customers’ personal profiles (no names, email addresses, phone numbers, or addresses). We may hold order-level records used to attribute an order to an AI agent, which can include a Shopify order reference and the referral or channel a shopper came from. AgentChannel implements the three required Shopify compliance webhooks, and acts on each:
customers/data_request— a request to see a customer’s data. We automatically search the records we hold keyed to that customer and send the merchant any matches; requests scoped to specific orders are fulfilled manually until automated order-keyed export is in place. We confirm the result.customers/redact— a request to delete a customer’s data. We delete any matching order-attribution record we hold, by customer and by order, and confirm.shop/redact— sent about 48 hours after uninstall; we permanently delete your store’s data, including your audit history and the order-derived attribution and sales-total records.
Your responsibilities as the controller. As the data controller for your customers’ data, you are responsible for your own compliance: for telling your customers, in your store’s privacy policy, that you use AgentChannel and what it does, and for having a lawful basis for the data your store collects. AgentChannel processes data only on your documented instructions and within the scope described here, and does not change your obligations to your customers.
Depending on where you live, you may have the right to access, correct, delete, or port your personal data, to restrict or object to certain processing, to withdraw consent, and to lodge a complaint with your data protection authority. EU/UK residents have these rights under GDPR; California residents have similar (but not identical) rights under CCPA/CPRA, including to know, delete, correct, and opt out of the sale or sharing of personal information. To exercise any of them, email support@agentchannel.app and we will respond within the legal timeframe (about one month under GDPR; within 45 days under CCPA/CPRA). If your request concerns data we process on behalf of a merchant, we will refer you to that merchant as the controller.
9. Service providers
We use a small set of trusted providers (“subprocessors” in GDPR language) to run AgentChannel, each bound by data-processing terms and acting only on our instructions. They are:
- Vercel — cloud hosting that runs the AgentChannel web app.
- Inngest — background-job orchestration; receives your shop domain and job triggers (such as audit and redact events), not your catalog contents.
- Supabase — managed database storage, a Postgres database in the United States (us-east-1) where your audit and order-derived data is held, encrypted and isolated per store.
- Resend — email delivery, for compliance and operational email and to send free-audit reports; these carry the recipient’s email address and the message itself.
- Anthropic and OpenAI (routed through the Vercel AI Gateway) — AI providers that, on the paid plan, draft store-policy and product-description fixes from your store’s business content. We send only your store content for this — never your customers’ personal data — and we do not allow them to train models on it.
- Google Analytics — marketing-website analytics only, as described in “Website visitors, cookies, and analytics.”
Separately, Shopify, Inc. is the platform your store runs on and the source of the catalog and content data we read; your relationship with Shopify is governed by Shopify’s own terms and privacy policy.
On the paid plan, AgentChannel uses AI (Anthropic and OpenAI, routed through the Vercel AI Gateway) to draft store policies and product descriptions you ask us to fix. We send only your store’s business content — never your customers’ names, email addresses, phone numbers, or addresses — and we never use your data, or allow these providers to use it, to train AI models. The free AI Readiness Audit itself uses no AI. Our use of AI is also governed by our AI Addendum.
10. Children
AgentChannel is a business tool and is not directed to children. We do not knowingly collect personal data from anyone under 16.
11. Changes to this policy
We may update this policy as the product changes. Material updates are emailed to active merchants and announced on the AgentChannel admin dashboard, and the “Last updated” date above shows when we last revised it. If we add a feature that collects new data or uses a new subprocessor, we will update this page before turning it on.
12. Contact
Privacy questions, data requests, or security disclosures: support@agentchannel.app.