Privacy Policy

Effective date: April 12, 2026

Last updated: August 23, 2026

Corvify ("we", "us", "our") is a Shopify application operated by Orbilyte. This Privacy Policy explains how we collect, use, store, and protect information when you install and use the Corvify app ("the App") on your Shopify store.

1. Information We Collect

1.1 Store Information

When you install the App, we access and store the following data through the Shopify API:

  • Shop domain (e.g., your-store.myshopify.com)
  • Shop profile data (store name, currency, locale, plan)
  • Session tokens for authenticated API access
  • Store profile from onboarding - a structural summary of your store (number of products, product types, vendors and tags, price range, names of theme sections and templates, names of metaobject definitions) together with the goals you select and any free text you add. This summary contains no personal data.

1.2 Data Accessed at Request Time (Not Stored)

When you interact with the AI agent, it may read the following data from your Shopify store in real time. This data is not persisted in our databases - it is used only to generate a response within your chat session:

  • Theme files (Liquid templates, CSS, JavaScript)
  • Product information (titles, descriptions, prices, variants, images)
  • Metaobjects and metaobject definitions
  • Online store pages, blog posts, and articles
  • Order data (order number, status, line items, totals)
  • Legal policies (Privacy Policy, Terms of Service, etc.)
  • Customer information associated with orders (name, email, address) - displayed in chat responses only, never written to disk

1.3 Chat Conversations and Agent Runs

Messages you send to the AI agent and the agent's responses are stored in our database to maintain conversation context and provide an audit trail of actions taken on your store.

Alongside each message we also store the tool calls the agent made - including their arguments - and a shortened record of each tool result. These can contain data from your store.

Paused runs. If a run reaches your daily or weekly credit limit in the middle of its work, it is paused and the complete raw conversation transcript - including every tool call and every tool result - is held so that you can resume it. This snapshot can contain store data. It is deleted automatically no later than 7 days after the pause, and immediately when you resume or discard the run.

Night runs. For a task you start as a night run, the raw transcript is deleted as soon as the run finishes. The instruction you gave, the resulting answer and the arguments of the tool calls that were executed remain with the conversation as a record until your store data is deleted (see section 5).

1.4 Usage and Credits

For each request we record four token counts (input, output, cache read and cache write), the model used, and the credits calculated from them, for billing and rate-limiting purposes. This usage record does not contain conversation content.

Separately, an action log records each agent run with the instruction you gave, a shortened excerpt of the result, which tools ran and which performance level answered. That log does contain text you wrote.

1.5 Custom Database Tables

If you use Corvify's custom data table feature, the data you create is stored in a dedicated PostgreSQL database. Every query against that database carries a mandatory store predicate, so one merchant's queries cannot reach another merchant's rows; PostgreSQL row-level security policies are in place on those tables as an additional layer.

Storefront visibility is not the only way these rows can be reached - see section 1.7.

1.6 Bring Your Own Key (BYOK)

Growth and Scale plan users may optionally provide their own Anthropic API key. If provided, this key is encrypted using AES-256-GCM before storage and is only decrypted at request time to make API calls on your behalf.

1.7 External API Access

You can issue API keys that let external systems read and write the rows of your custom tables through Corvify's external API (/api/v1). Each key is limited to the tables you select, carries either read or read-and-write permission, can be given an expiry date, and can be revoked at any time. We store only a hash of the key; the key itself is shown once when you create it and cannot be retrieved afterwards.

This access path is independent of storefront visibility. A table that is private to your storefront remains reachable with a valid key. Keys are yours to manage - anyone you hand one to can reach the data it covers.

1.8 Notifications, Emails and Connected Services

You can set up notifications that fire when a row arrives in one of your custom tables: an email, a contact or event pushed into a CRM, a signed webhook to your own endpoint, or a call to a tool on a system you have connected. What travels is the content of the triggered row - the data entered into your form, which depending on the form can include an end customer's name and email address.

Confirmation emails to the person who filled in the form. You can configure the confirmation to go to the address given in the form instead of to a fixed address of your own. In that case an end customer's address is the recipient and is passed to the email service you connected. This is switched off when a notification is created and only you can turn it on - the AI agent cannot. The field has to exist in the table's schema, the value has to look like an email address, and the number of confirmations sent per notification is capped.

None of this is preset. Without a notification you set up yourself, no row content leaves the App. Target hosts must be confirmed by you in the app settings before anything is sent there, and the credentials you store for a service are encrypted and cannot be read back afterwards - neither by you nor by us. The services you connect act as your processors, not ours: you choose them and you conclude the data processing agreement with them.

Pending deliveries. A notification that has not been delivered yet keeps its payload - the row content - so that a retry sends the same thing. As soon as the delivery has finally succeeded or finally failed, that payload is deleted; what remains is a delivery record with time, status and number of attempts, and no content.

1.9 Storefront Chat (Visitor Data)

If you activate the storefront chat, your visitors can converse with an AI assistant that answers on behalf of your shop. We process these conversations as your processor. As the shop owner you remain responsible for how you present the assistant to your visitors, including any notice in your own privacy policy, and for the lawfulness of collecting data through lead forms you switch on.

What is stored. The conversation and its messages (visitor text, the assistant's answers and any product cards shown), together with a record of which AI model answered each turn, kept as evidence for the transparency rules of the EU AI Act. Product and policy information is looked up live from your shop when a question is asked and is not stored separately.

Identification. A visitor who is not signed in is known to us only by an anonymous token stored in the visitor's own browser. If a visitor is signed in to your shop, the conversation is additionally linked to their Shopify customer id so that deletion requests can be met. Sessions are short-lived and stateless (about 30 minutes).

Retention. Conversations with no activity for 90 days are deleted automatically. Conversations of a signed-in visitor are deleted when the visitor's customer data is erased, and everything is deleted with your store data (see sections 5.1 to 5.3).

Leads. If you enable lead capture, what a visitor enters is written into the custom table you selected; the rules of section 1.5 apply to that data.

Abuse protection. Visitor requests are rate limited. Counters keyed to the visitor token or the visitor's IP address are kept briefly for this purpose, and suspicious traffic can be challenged with a bot check (Cloudflare Turnstile). The widget itself tells visitors that they are talking to an AI, as the EU AI Act requires.

2. How We Use Your Information

  • AI-Powered Store Management: Your store data is sent to the Anthropic Claude API to generate intelligent responses, code modifications, and store management actions.
  • Night Runs: Tasks you start as a night run are submitted to the same provider through its batch interface and collected the next morning.
  • Storefront Chat: Visitor questions to the storefront assistant are sent to the Anthropic Claude API together with the knowledge you configured, so the assistant can answer on behalf of your shop.
  • Conversation History: Chat messages are stored to maintain context across sessions and provide an audit trail.
  • Notifications and Confirmations: When you set them up, row content is sent to the email service, CRM, webhook endpoint or connected system you chose.
  • External Integrations: With an API key you issue, external systems can read and write your custom table rows.
  • Billing: Credit usage is tracked to enforce plan limits and calculate usage.
  • Service Improvement: Aggregated, anonymized usage patterns may be used to improve the App.

3. Third-Party Services

3.1 Services We Use to Operate Corvify

ServicePurposeData Shared
Anthropic (Claude API)AI language model for chat responses and code generation. Tasks started as night runs are submitted through the same API's batch interface and collected the next morning - same data, same provider, a different processing path with a time offset.Chat messages, store context (products, themes, etc.) as needed for the conversation
Neon (PostgreSQL)Hosting for merchant custom data tablesCustom table data created by the merchant
RailwayApplication and database hostingAll application data (encrypted in transit)
Cloudflare (Turnstile)Bot protection: challenges suspicious traffic for the storefront chat and the demo request formChallenge metadata such as the visitor's IP address and browser signals

3.2 Services You Connect Yourself

These services receive data only once you have connected them with your own credentials and set up a notification. They act as your processors.

ServicePurposeData SharedData Region
Brevo (api.brevo.com)Transactional emailRecipient address, subject, message text and the content of the triggered rowEU
Scaleway TEM (api.scaleway.com)Transactional emailRecipient address, subject, message text and the content of the triggered rowEU
Resend (api.resend.com)Transactional emailRecipient address, subject, message text and the content of the triggered rowUnited States
Klaviyo (a.klaviyo.com)CRM contacts, lists and eventsThe row fields you map - for example name, email address, phone number, event dataUnited States
Your own targetsSigned webhook to your endpoint, or a connector you define yourselfContent of the triggered rowYou decide
Your own MCP serverConnecting Corvify to a system of yoursTool arguments and tool resultsYou decide

Resend can dispatch from a European region, but account data, logs and metadata stay in the United States. If you need processing to stay within the EEA, choose a service with an EU region.

MCP servers. If you connect an MCP server, the agent's tool calls and their results travel to that server. Approval is granted per tool, never per server, and never by the agent - only by you. If the server changes a tool's description, the approval becomes invalid automatically until a person agrees to it again. Credentials are encrypted as described above.

We do not sell, rent, or trade your personal information to any third parties for marketing purposes.

4. Data Security

We implement the following security measures to protect your data:

  • Encryption in Transit: All data transmitted between your browser, our servers, and third-party APIs uses TLS encryption.
  • Encryption at Rest: BYOK API keys and the credentials for services you connect are encrypted using AES-256-GCM. External API keys are stored only as a hash.
  • Tenant Isolation: Every query against the custom table database carries a mandatory store predicate, so a query that forgets the store cannot be built. PostgreSQL row-level security policies are in place on those tables as an additional layer.
  • Parameterized Queries: All database queries use parameterized statements to prevent SQL injection.
  • Controlled Outbound Requests: Requests to services you connect go through a single audited path - HTTPS only, restricted to the hosts you approved, no redirects, with time and size limits.
  • Session Authentication: All API requests are authenticated via Shopify session tokens.

5. Data Retention and Deletion

5.1 During Active Use

Your data is retained for as long as the App is installed on your Shopify store. Three things are deleted automatically before that: the stored transcript of a paused run, no later than 7 days after the pause, the payload of a notification delivery, as soon as that delivery has finally succeeded or finally failed, and storefront chat conversations with no activity for 90 days.

5.2 Upon Uninstallation

Deletion happens in two steps.

Immediately on uninstall we delete all sessions for your store and mark it as uninstalled. The remaining data is kept during a short grace period so that reinstalling within that window preserves your state.

About 48 hours later Shopify sends the shop/redact webhook. That is the actual deletion, and it removes:

  • Custom database tables (dropped entirely)
  • Chat conversations and messages, including paused and night run records
  • Storefront chat configuration, visitor conversations and messages
  • Usage and credit records
  • Agent action logs
  • Connections to services and their stored credentials
  • External API keys and MCP server configuration
  • Notifications and delivery records
  • Packs and their contents
  • Shop profile, session data and the encrypted BYOK key

If you want your data deleted sooner than that, contact us - see section 6.

5.3 Customer Data Requests

Order details, including customer names and email addresses, are read from the Shopify API at request time and displayed only within the chat interface. They are not stored.

Rows submitted through your storefront are different. If the person submitting is signed in to your shop, the row is stored in your custom table together with their Shopify customer id. When Shopify sends a customers/data_request we compile exactly those rows so that you can answer the request; when Shopify sends a customers/redact we delete them.

Rows submitted without a signed-in customer carry no owner, cannot be attributed to anyone, and are therefore outside both request types.

Storefront chat conversations. If a signed-in visitor talks to the storefront assistant, the conversation is stored together with their Shopify customer id. When Shopify sends a customers/redact we delete those conversations together with the rows. Conversations of visitors who were not signed in carry only an anonymous token, cannot be attributed to a person, and are therefore outside both request types.

6. Your Rights

You have the right to:

  • Access: Request a copy of all data we hold about your store.
  • Deletion: Request deletion of all your data at any time by uninstalling the App or contacting us.
  • Portability: Request your data in a machine-readable format.
  • Rectification: Request correction of inaccurate data.

7. GDPR Compliance

For merchants and customers in the European Economic Area (EEA), we comply with the General Data Protection Regulation (GDPR). Our lawful basis for processing data is:

  • Contract Performance: Processing necessary to provide the App's services (Article 6(1)(b)).
  • Legitimate Interest: Aggregated usage analytics to improve the App (Article 6(1)(f)).

International transfers. Services you connect yourself may process data outside the EEA. The data region of each service in our catalogue is listed in section 3.2; if you need processing to stay within the EEA, choose a service with an EU region. You select these services and conclude the data processing agreement with them.

8. CCPA Compliance

For merchants in California, we comply with the California Consumer Privacy Act (CCPA). We do not sell personal information. You may exercise your rights under the CCPA by contacting us at the address below.

9. Children's Privacy

The App is designed for use by Shopify merchants (business users) and is not directed at children under 16. We do not knowingly collect data from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or by email. The "Last updated" date at the top of this policy indicates when the most recent changes were made.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us: