Privacy Policy for Descrivo

Last updated: 12 August 2026

This Privacy Policy explains what data the Descrivo Shopify app ("Descrivo", "the App", "we", "us") collects, how it is used, and the rights merchants and their customers have regarding that data. Descrivo is a Shopify app that generates AI-assisted product description suggestions for merchants using their own store data.

1. Who this applies to

This policy applies to:

2. Data the App collects

Data Source Purpose
Shop domain (*.myshopify.com) Shopify OAuth Identify the store and route API requests
Shopify access token (session) Shopify OAuth Authenticate Admin API requests on the merchant's behalf
Shop's primary locale (shop.primaryLocale) Shopify Admin API Determine which language to generate AI product descriptions in
Product titles and existing product descriptions Shopify Admin API Sent to the AI provider to generate a rewritten description; displayed to the merchant for review before saving
Updated product descriptions Merchant input (via the App's UI) Written back to the product via the Shopify Admin API when the merchant confirms

Session data (shop domain, access token, and related OAuth metadata) is stored in the App's own database for as long as the app remains installed.

3. What the App does not collect

Descrivo does not access, request, or store:

Because the App does not process customer-level personal data, most customer-facing GDPR data requests will have "no data held" as the accurate response — see Section 6.

4. How data is used

5. Third-party data processors

Processor What is shared Purpose Their privacy policy
Shopify, Inc. Shop domain, access tokens, product data (via Admin API) Core app functionality https://www.shopify.com/legal/privacy
Anthropic, PBC (Claude API) Product title and existing description text Generating rewritten product description suggestions https://www.anthropic.com/legal/privacy
Vercel Inc. Session data, application logs Hosting the app's server (application runtime) https://vercel.com/legal/privacy-notice
Neon, Inc. Session data PostgreSQL database storage https://neon.com/privacy-guide

No customer-level personal data is sent to any of the above processors, because the App does not collect or hold customer-level data in the first place (see Section 3).

6. Mandatory GDPR compliance webhooks

In line with Shopify's requirements for apps distributed through the Shopify App Store, Descrivo implements the three mandatory privacy webhooks:

Each webhook is verified using Shopify's HMAC signature scheme before being processed.

7. Data retention

8. Data security

Shopify access tokens are stored in the App's database and are not exposed to the client/browser. Communication with Shopify and Anthropic APIs occurs over HTTPS/TLS. Data is encrypted in transit (HTTPS/TLS) and at rest (Neon PostgreSQL encryption). Keys and secrets are stored as encrypted environment variables (Vercel). Access to production systems and data is restricted to the developer. No data is shared with third parties beyond the subprocessors listed in Section 5 (Anthropic for AI generation, Vercel for hosting, Neon for database storage, and Shopify for platform integration).

9. Your rights

Merchants may uninstall the App at any time, which triggers deletion of their shop's session data as described in Section 7. Merchants or their customers who believe the App holds data about them may contact us using the details in Section 10 to request access, correction, or deletion.

10. Contact

Questions about this policy or the App's data practices can be sent to:

web.land.md@gmail.com

Marin Grigoriță Constantin Vîrnav 20, Chișinău, Republica Moldova

11. Changes to this policy

We may update this policy from time to time. Any change is reflected by updating the "Last updated" date above. For significant changes, merchants will be notified by email or via an in-app notice.