Who we are
Arbling provides an AI-readiness layer for e-commerce catalogs. This policy explains what data we process when you install or use the Arbling app (including the Shopify embedded app) and how we protect it.
Data we access
When you connect a store, we access only what is needed to score and enrich your catalog:
- Product catalog data — titles, descriptions, images, prices, variants, product metadata.
- Store profile — shop domain and basic store settings.
- Order events (optional) — order id and value, used solely to attribute AI-assisted sales. We do not store customer payment details.
We request the minimum Shopify scopes required (read products, read product listings, write script tags, and — only to attribute AI-assisted sales — read orders).
How we use it
- Compute your AI Sales Readiness score and eligibility buckets.
- Extract and verify product facts, and (with your approval) publish verified data and JSON-LD back to your store.
- Power your AI Seller widget, WhatsApp assistant, and agent-readiness checks.
- Measure AI citation and revenue attribution for your store only.
We never sell your data and never use it to train third-party foundation models.
Sub-processors
We use trusted processors strictly to deliver the service: cloud hosting and database providers, and LLM providers (e.g., OpenAI) for text extraction and the AI Seller. Data sent to LLM providers is limited to your catalog content needed for the request.
Data retention & deletion (GDPR)
We honor Shopify's mandatory GDPR webhooks. On shop/redact — triggered automatically ~48 hours after you uninstall the app — we immediately delete the records tied specifically to your store: connector state, score reports, webhook history, and any AI-attributed order that was never invoiced.
Two categories are retained rather than deleted — by design, not by delay:
- Invoiced orders. If an AI shopping agent purchased from your store and we attempted to bill (or already billed) the usage fee on that order, the order record is kept permanently for financial recordkeeping, dispute defense, and reconciliation of any charge attempt whose outcome is still being confirmed with our payment provider — the same reason any billing platform retains transaction history.
- Shared account data, if you have other connected stores. AI Seller widget settings and chat logs, WhatsApp bindings, semantic search vectors, and the store's AI-attribution trails (the records generated when an AI shopping agent visited your store) live at your Arbling account level, not per store. This includes the attribution/session record linking a visit to a specific order, which can outlive that same order's own record — even for a never-invoiced order deleted immediately on this shop's redact — until your last connected store is removed, at which point all of it is deleted automatically.
On customers/redact we delete any record we hold that identifies the named customer. Some traffic records — such as an anonymized visitor or session identifier logged before a purchase — carry no reversible link back to a specific person, so a customer-level request cannot selectively reach those rows; they are removed as part of your store's own shop/redact instead. On customers/data_request we provide the identifiable data we hold. You can also request deletion any time by emailing us.
Security
Access tokens are encrypted at rest. All traffic is over HTTPS. Webhooks are verified with Shopify HMAC signatures.
Contact
Questions or data requests: privacy@arbling.com.
