Privacy Policy

EL AI Collection Sort – Shopify app by ESSYLABS

1. Controller

Lukas Zimmermann
Clara-Schumann-Str. 15
74889 Sinsheim, Germany
E-mail: lukastz@icloud.com

2. Categories of data processed

3. Purposes of processing

4. Legal bases

5. Processing activities

5.1 Shopify admin app (OAuth & sessions)

During installation and login we obtain Shopify access tokens via OAuth, store a session with shop domain, token, validity, and granted scopes, and delete these after app uninstallation through the uninstall webhook.

5.2 Collection management & sync

We read collection and product data to compute rankings and write ordering, metafields, and publications back to Shopify when you save or publish. For A/B tests we may duplicate collections and keep snapshot history.

5.3 Storefront analytics (Shopify Web Pixel)

Performance events (views, clicks, add-to-cart, purchases) are collected through Shopify Web Pixels. We honor Shopify Customer Privacy and consent signals; events are only processed after consent and may be replayed per Shopify rules.

5.4 Admin analytics (PostHog, EU)

Pseudonymous usage analytics (screen views, clicks, feature flags, errors) are processed in PostHog Cloud EU. No storefront customer data is sent. Identifiers are pseudonymous session/client IDs. You can request disabling admin analytics via support.

5.5 AI Strategy and monitoring

If you use AI Strategy, we process your collection goal, selected catalog context, product and collection metadata, and generated strategy output to provide reviewable sorting and filtering suggestions. AI requests are sent to our AI provider OpenAI. We do not intentionally send storefront customer names, email addresses, payment data, or full order records in AI prompts. AI changes are applied only to drafts after merchant review.

We also send limited AI reliability events to PostHog Cloud EU, such as generation success/failure, quota exhaustion, plan/quota category, and collection identifiers. Merchant prompt text and generated strategy text are not sent to PostHog monitoring events.

5.6 Billing

Subscriptions are handled via Shopify Billing. We receive plan status and billing events (e.g., app_subscriptions/update) but no payment card details.

5.7 Grucky support and feedback

When you open the app, we synchronize your shop identity, available shop contact emails, locale, timezone, plan status, and app activity with Grucky, a support and feedback product operated by ESSYLABS. This lets you send and receive support messages in the app and helps us provide relevant onboarding and product updates. Contact emails are not treated as marketing consent by default. Marketing or product emails require a separate valid legal basis and the applicable unsubscribe controls.

6. Recipients

7. International transfers

Where providers outside the EU/EEA are used, transfers rely on appropriate safeguards such as EU Standard Contractual Clauses (SCCs) or equivalent mechanisms. PostHog is used with an EU host; Shopify may process data globally under its own safeguards.

8. Storage periods

9. Data subject rights

You have the right of access, rectification, erasure, restriction of processing, data portability, and to object where legal requirements are met. You can lodge a complaint with a competent supervisory authority. For customer data from the Shopify storefront, requests are handled through Shopify’s mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact). Store owners or their customers can also email support@advanced-collections.app or lukastz@icloud.com with the shop domain and request type; we will respond using the same webhooks and confirm completion.

10. Obligation to provide data

Providing the data in Section 5.1 is necessary to use the app. Without these data the app cannot function.

11. No sale or targeted advertising

We do not sell or share personal data for targeted advertising. Storefront pixel events are used solely for ranking, analytics, and A/B testing within the merchant’s shop. If you disable analytics or uninstall the app, processing stops and data is erased per Section 8.

12. Contact

Email: support@advanced-collections.app
Controller: lukastz@icloud.com

For Shopify’s own processing as a separate controller, see the Shopify Privacy Policy.


Imprint

Responsible entity (service provider) for EL AI Collection Sort.

ESSYLABS (Lukas Zimmermann) Attn: Legal / Imprint Clara-Schumann-Str. 15, 74889 Sinsheim, Germany Email: support@advanced-collections.app

Note: This page is intended for public reference and can be linked from the Shopify App Store listing.