BeAgents Privacy Policy
---
Last updated: 21 May 2026
This Privacy Policy describes how the BeAgents AI Shopify application ("the App", "we", "us") collects, uses and protects information when a Shopify merchant installs and uses the App. It is separate from the sametsalik.com store privacy policy, which describes how the public-facing online store handles customer purchases.
1. Who we are
BeAgents AI is operated by Samet Salık (sole trader), sametsalik@gmail.com. The App runs on Cloudflare Workers infrastructure, with aggregate data stored on Supabase (EU region).
2. What information we access
When a merchant installs the App, Shopify grants the App the following read-only API scopes:
-
read_orders— used to compute paid revenue totals, order counts and average order value over rolling 7- and 14-day windows. -
read_products— used to display product titles for contextual labels in the dashboard. No product editing is performed. -
read_analytics— used to read shop-level aggregate analytics where available.
The App does not request, read, store or transmit the following customer data: name, email, phone number, billing address, shipping address, customer note, IP address, browsing behaviour, payment method or any per-customer record.
3. What we store
For each connected store the App stores only:
- The store's
.myshopify.comdomain - The Shopify-issued offline access token (expiring; rotated by Shopify)
- The store's currency code (e.g.
USD,TRY) - Aggregate daily totals: revenue, orders, average order value
No customer-level data leaves the Shopify platform.
4. How we use the information
Aggregate metrics are used solely to render the merchant's own performance dashboard. Data is not used for advertising, profiling, automated decision-making, machine-learning training, or resale to any third party.
5. Sharing with third parties
We do not sell or share merchant data with third parties for marketing or analytics purposes. The App relies on two subprocessors that act purely as infrastructure providers:
- Cloudflare, Inc. — application runtime (Workers, edge TLS termination).
- Supabase — managed Postgres database (EU region, AES-256 at rest).
If the merchant chooses to connect optional Meta Ads or Google Ads accounts inside the wider BeAgents AI dashboard (set up separately, outside this Shopify App), those connections are governed by their own provider-specific consent screens. This Shopify App neither initiates nor controls those connections.
6. Security
All data in transit is encrypted with TLS 1.2 or higher. Tokens are stored in the Supabase database with row-level access policies and are never logged. The App uses Shopify's HMAC verification on every webhook payload (App-uninstalled, GDPR webhooks) to ensure authenticity.
7. Data retention and deletion
Aggregate metrics are retained for up to 24 months. When the merchant uninstalls the App, Shopify dispatches an app/uninstalled webhook; the App immediately clears the merchant's stored access token and expiry timestamp.
Shopify's mandatory GDPR webhooks are honoured as follows:
-
customers/data_request— returns 200 OK with the response "no customer PII held". No data is exported because none is stored. -
customers/redact— returns 200 OK with the same response. No deletion is required because no per-customer record exists. -
shop/redact— the merchant's integration row and all aggregate daily metrics for that shop are deleted from our database within 48 hours of the webhook being received.
8. Merchant rights
The merchant can at any time:
- Uninstall the App from the Shopify admin to immediately revoke access.
- Email sametsalik@gmail.com to request an explicit shop-redact even before uninstalling.
- Request a copy or summary of the aggregate data we hold for their store.
9. International transfers
Data is processed in EU regions (Cloudflare global edge + Supabase EU-West). No transfer outside the EU/EEA takes place. If this changes, this page will be updated and merchants will be notified by email at the address Shopify holds for the store owner.
10. Changes to this policy
If we make a material change to this policy, we will update the "Last updated" date at the top and, where the change affects merchant data handling, notify merchants by email.
11. Contact
For any privacy question or data-rights request, please contact: sametsalik@gmail.com. We respond within 7 calendar days.