Updated August 11, 2026
Privacy Policy
Qosmic audits Shopify storefronts and makes the improvements merchants approve. This explains what we collect to do that, who we share it with, how long we keep it, and the rights you have over it.
Introduction
This policy applies to the Qosmic website, the Qosmic Shopify app, and the services behind them (together, the “Services”).
If you are a merchant — a store owner or a member of their team — this describes what we hold about you and your store. We are the controller of that information.
If you are a shopper on a store that uses Qosmic, the merchant decides what is collected and why. We act on their instructions as their processor, and they are your first point of contact. See “Shoppers on our merchants’ stores”.
If we contacted you about Qosmic without you having signed up, see “Prospects and marketing”.
Questions, requests and complaints: hello@qosmic.ai.
Information you give us
- Account and workspace details — name, email address, store domain, your login identity, and the team members you invite.
- Billing details — subscription status and plan. Card details go directly to our payment processor and are never stored by us.
- Support and correspondence — what you send us and what we send back.
- What you ask the product to do — briefs, notes, goals and instructions about what you want changed.
Information from your Shopify store
Installing Qosmic grants a set of permissions through Shopify’s OAuth flow. Under them we read:
- orders and full order history, and aggregate reports;
- customer records, inventory levels and locations;
- products, variants, collections and their publication status;
- theme files, templates, sections and settings;
- customer events exposed by Shopify.
We also hold write permissions — themes, products, publications, discounts, inventory, Online Store pages, files, web pixels and the app proxy. Those exist so Qosmic can make the changes you approve, and they are set out in full in our Terms of Service. We act on your store at your direction.
We also collect what your storefront already shows the public: page content, screenshots, structured data, and the audit findings we generate from them.
Shopify Protected Customer Data
Shopify classifies certain data as Protected Customer Data and reviews any app that asks for it. Our access was reviewed and approved on 14 July 2026.
Shopify treats customer name, email address, phone number and street address as optional protected fields an app must separately justify. Qosmic does not request any of them. We work from order totals, timestamps, product identifiers, pseudonymous customer identifiers and aggregate purchase behaviour.
Storefront events
Where a shopper has given analytics consent, our web pixel collects page, product, search, cart and checkout events; a session identifier; the path visited; the referring domain; and UTM parameters. This is what makes before-and-after measurement possible.
Where a shopper has not consented, we collect none of it.
A/B testing identifiers
If you run a test, and only with the same consent our storefront events require, two things are stored:
- a first-party identifier on the visitor’s own device, so they see the same version of your store on each visit rather than flickering between them;
- a marker naming the test and which version was shown, attached to that visitor’s cart and to the resulting order.
The marker records the version only. The device identifier is never attached to a cart, an order, or anything Qosmic receives from your store — the two are deliberately kept apart. A visitor who has not consented is excluded from the test and sees your storefront unchanged.
Information collected automatically
When you use our website or app we collect technical information: IP address, browser and operating system, device characteristics, language and time zone, referring and exit pages, pages viewed, and timestamps. We use it to run the Services, diagnose faults and prevent abuse.
Cookies and similar technologies
Cookies are small files placed on your device. Similar technologies include local storage and web beacons — also called clear GIFs, pixel tags or single-pixel GIFs — small files that record that a page was viewed. We use:
- Strictly necessary — sign-in, session integrity and security. The Services do not work without these.
- Preference — remembering choices so you are not asked twice.
- Analytics and performance — counting visits and understanding which parts of the product get used. Ours is configured to record page views and specific events we have chosen; broad automatic capture of clicks and text is switched off.
We use no advertising or interest-based tracking cookies. We run no ad-network tags, build no advertising profiles, and share no hashed email or user identifier with advertising partners.
Most browsers let you refuse or delete cookies in their settings. Blocking strictly necessary ones will break parts of the Services. Browser controls are per-browser and per-device, so a choice made in one place does not follow you to another. Some browsers send a “Do Not Track” or Global Privacy Control signal; we do not engage in the cross-site tracking those signals exist to stop.
Prospects and marketing
We contact ecommerce businesses about Qosmic who have not signed up. If that is how you heard from us, this is what we hold and why.
- What. Business contact details — name, role, company, work email address, company website and public professional profile.
- Where from. Publicly available sources, and third-party business data providers who represent to us that they collected it lawfully.
- Why. To tell you about Qosmic and, if you reply, to follow up. We hold it in a customer relationship system and send through email tools.
- Basis. Our legitimate interest in reaching businesses likely to want the product, balanced against your interests — and consent where the law where you are requires it.
Every message we send carries an unsubscribe option. You can also email hello@qosmic.ai and ask us to stop contacting you, to tell you where your details came from, or to delete them. We will do all three, and suppressing your address means keeping the minimum record needed to make sure we do not contact you again.
Google sign-in and page speed
Sign in with Google. If you choose it, Google tells us your name, email address and a stable account identifier so we can create or match your account. We do not receive your Google password, and we do not request access to Gmail, Drive, Google Analytics, Search Console or any other Google service.
Page speed measurement. To report how fast your storefront loads, we submit your public storefront URL to Google’s PageSpeed Insights API. Only the URL is sent — the same address anyone can visit — and no merchant or shopper personal data goes with it.
How we use information
- Audit your storefront and produce Opportunities, analytics and benchmarks.
- Make the changes you approve, and measure whether they worked.
- Run tests and report their results.
- Provide, maintain, secure and improve the Services.
- Diagnose faults, investigate incidents and prevent abuse or fraud.
- Support you and respond to what you send us.
- Send service messages about your account, and marketing where you have not opted out.
- Meet our legal, tax and contractual obligations, and establish or defend legal claims.
AI processing and automated decisions
Qosmic uses AI models to generate recommendations, copy, code and analysis. To do that we send store context — product and page content, metrics, and audit findings — to OpenAI and Anthropic, who process it for us under their business and API terms.
Under those terms, your data is not used to train their general-purpose models, and both providers delete API inputs and outputs within approximately 30 days by default. We do not train models of our own on merchant data either.
Qosmic does not make decisions about an individual on a solely automated basis that produce legal or similarly significant effects. Its output is a recommendation to a merchant, and a person decides whether to accept it.
Consent on your storefront
Our pixel runs through Shopify’s customer privacy API and follows the consent state your store collects. Where a visitor has not given analytics consent, we do not collect their storefront events and do not include them in tests.
Presenting your shoppers with a consent banner that satisfies the law in every market you sell into is your responsibility as the merchant and the controller of that data, not ours.
How we share information
- Service providers who perform services on our behalf, bound to protect the information and use it only to provide that service. They are named individually in the next section.
- Shopify, the platform your store runs on and the source of most store data we hold.
- Within your organisation — where you use Qosmic in a professional capacity, your use may be visible to the workspace owner and your team.
- Legal and regulatory — where required by law, court order, subpoena or regulator; to enforce our Terms of Service; or to protect the rights, property or safety of Qosmic, our merchants or others.
- Corporate transactions — to a buyer or successor in a merger, acquisition, financing or sale of assets. This policy keeps applying until it is replaced with notice to you.
- Anywhere you direct us to send it.
We do not sell personal information, and we do not share it for cross-context behavioural advertising as California law defines those terms. We have not done so in the preceding twelve months.
Who processes your data
The providers below process data on our behalf, and each is bound to protect it and to use it only to provide their service to us. This is our principal set of providers as at August 11, 2026.
- Shopify — the platform your store runs on, and the source of the store data we hold.
- Supabase — our primary database and authentication. Holds account and store data.
- Vercel — hosting for our website and web app.
- Fly.io — hosting for the Shopify app.
- Cloudflare — network, delivery and protection.
- Upstash — caching and rate limiting.
- OpenAI and Anthropic — AI models. Receive store context to generate recommendations; see “AI processing”.
- LangChain / LangSmith — orchestration and tracing for our agents. Traces can include the store context sent to a model.
- Sentry — error monitoring. Receives diagnostic data, which can include identifiers present when a fault occurs.
- PostHog — product analytics for our own site and app.
- Stripe — payment processing. Card details go to Stripe directly and are never stored by us.
- Resend — transactional email, such as team invitations.
- Google — sign-in identity if you use it, and the PageSpeed Insights API, which receives only your public storefront URL.
- HubSpot — our customer relationship system. Holds merchant contact details and audit status, and prospect details from outreach.
- Sanity — the content system behind our blog. Holds no merchant or shopper data.
That list is illustrative rather than exhaustive, and is accurate as at the date shown rather than continuously. Our infrastructure changes, and we may add, replace or remove a provider at any time without updating this page first.
What does not change is the categories of provider we use and the terms they are held to. We use, and may in future use, providers for: cloud hosting and infrastructure; databases and storage; caching and rate limiting; network delivery and protection; error, performance and security monitoring; product analytics; AI model providers and agent orchestration; transactional and marketing email; customer relationship management; payment processing; content management; and customer support.
Any provider we use, named here or not, is bound by contract to protect your information, to use it only to provide their service to us, and to obligations no less protective than those in this policy. If you need to know exactly who processes your data at a particular moment — for a security review, for example — email hello@qosmic.ai and we will tell you.
Aggregated and de-identified information
We produce aggregated and de-identified information — held in a form not reasonably capable of being associated with or linked to an individual, a merchant or a store. Benchmarks are the example: a conversion-rate range across a sector says nothing about who contributed to it.
We may use and publish that information to run, improve and market the Services, and we maintain it in de-identified form rather than attempting to re-identify it.
Where your information is held
We are based in the United States and your information is stored and processed there, and in other countries where our service providers operate. We do not currently offer regional data residency.
If you are outside the United States, data protection there may differ from, and be less protective than, the law where you live. Where personal data moves out of the UK, EEA or Switzerland we rely on the transfer mechanisms available to us, including the European Commission’s Standard Contractual Clauses.
How long we keep information
We keep personal information for as long as we reasonably need it to provide the Services and maintain our relationship with you; to meet our legal, tax and contractual obligations; and to establish, exercise or defend legal claims.
When you uninstall the app your access token is revoked immediately and we stop collecting. We then delete, anonymise or restrict access to the associated data once it is no longer needed for the purposes above. Backups, security logs and legal records may persist for a limited further period before ageing out on their normal cycle.
We implement Shopify’s mandatory privacy webhooks and act on customer data requests, customer redaction requests and shop redaction requests when Shopify sends them.
Security
We take reasonable steps to protect personal information from loss, misuse and unauthorised access, disclosure, alteration or destruction, taking into account the risks involved and the nature of the information.
Because Qosmic can write to your live store, the questions worth answering plainly are what it can reach and what happens when you stop using it:
- What we can access. Only what the Shopify permissions you granted allow, listed above and in our Terms. Nothing outside your store, and nothing on any other merchant’s.
- What we do not ask for. Shopper name, email address, phone number and street address. Those are optional protected fields in Shopify and we decline them.
- Nothing changes without your approval. Write access exists so we can act on changes you accept. Qosmic proposes; you decide.
- Encryption. Data is encrypted in transit and at rest by our infrastructure providers.
- Who can see it. Access to merchant data is limited to the people who need it to operate the Services and is not shared between merchants.
- On uninstall. Your access token is revoked immediately and we stop collecting. Retention of what we already hold is covered above.
- If something goes wrong. We investigate security incidents, and where a breach affects your data we will notify you and take the steps the law requires.
No application, internet or email transmission is ever fully secure or error-free, and we cannot guarantee the security of any personal information. You are responsible for keeping your credentials confidential and for who on your team you grant access to.
Merchants running a security review can write to us at hello@qosmic.ai.
Your privacy rights
Depending on where you live, you may have some or all of the following rights. California residents have all of them; residents of other US states with comprehensive privacy laws have most; and we extend the same process to everyone who asks.
- to know what personal information we collect and how we use it;
- to access a copy of it;
- to have inaccurate information corrected;
- to have it deleted;
- to receive it in a portable format;
- to opt out of the sale or sharing of personal information — we do neither;
- to limit the use of sensitive personal information;
- to opt out of marketing at any time;
- to withdraw consent you previously gave;
- to object to or restrict processing, including for direct marketing;
- not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects;
- to complain to your data protection or consumer protection authority.
To exercise any of these, email hello@qosmic.ai. We respond as soon as reasonably possible and within the period the applicable law allows. We may need to verify your identity first, and an authorised agent may make a request for you with proof of their authority.
We will not discriminate against you for exercising any of these rights. We will not deny you the Services, charge a different price, provide a different quality of service, or suggest that we will, because you exercised one.
Where the UK or EU GDPR applies to you, our legal bases are performing our contract with you, your consent for storefront event collection, our legitimate interests in security, debugging, improving the product and business outreach, and compliance with the law.
Shoppers on our merchants’ stores
If you shopped on a store that uses Qosmic, that merchant is the controller of your data. They decide what is collected and why; we process it on their instructions.
Send access, correction or deletion requests to the merchant. They can pass the request to us through Shopify or directly and we will act on it. You can also email us and we will route it to them.
Data protection requirements
Merchants with specific data protection requirements — a data processing agreement, a security review, or questions about how we handle a particular category of data — can contact us at hello@qosmic.ai and we will work through them with you.
Third-party services and links
The Services link to and work alongside third-party services, including Shopify and the other apps you have installed. This policy does not cover them. What they do with your information is governed by their own policies, and we are not responsible for their practices.
Children
The Services are a business tool and are not intended for anyone under 18, or under the age of majority where you live. We do not knowingly collect personal information from children. If you believe a child has given us information, email hello@qosmic.ai and we will delete it.
Changes to this policy
We may update this policy as the Services or the law change. The date at the top changes when we do, and for material changes we will give notice in the app or by email before they take effect. Continuing to use the Services afterwards means you accept the update.
Contact
Privacy questions, data requests and complaints: hello@qosmic.ai.
