Privacy & data
Protected Customer Data: Level 0
Page Proof never accesses orders or customers. It reads only public page markup and your own catalog handles to build the URLs it audits.
What we access
Page Proof requests these Shopify scopes: read_products, write_products, read_content, write_content, read_online_store_pages and write_online_store_pages. We use them to list your product and page URLs, read public page markup for the audit, and (only when you explicitly approve) write an improved copy snippet back to a product or page description.
What we do NOT access
- No orders, line items, transactions or fulfillment data.
- No customers, contact details or any personally identifiable information.
- No payment data.
Because Page Proof requests no read_orders / read_customers scope, it is classified as Protected Customer Data Level 0.
Data we store
We store your shop domain, your plan/billing status, the CRO audits you run (the audited URL, the predicted score, and the per-check findings), and a record of each AI copy-fix (the page it addressed and a snapshot of the prior text, so the change is reversible). None of this contains customer PII. On uninstall and on Shopify's shop/redact webhook, all of your shop's rows are deleted.
AI fixes & sub-processors
The optional AI copy-fix sends your own product/page title and description to Anthropic (our LLM provider) to generate a grounded reassurance block, under zero-data-retention terms. No orders or customers are ever sent, because we never have them. AI fixes run on our own managed Anthropic key under your plan's credit quota — you never supply an API key. Page Proof is hosted on our own server infrastructure (syncerp.work).
GDPR compliance webhooks
We implement Shopify's mandatory privacy webhooks. customers/data_request and customers/redact truthfully report that we hold no customer data; shop/redact cascade-deletes your shop's data.