Privacy Policy
Effective date: September 16, 2026 · Contact: privacy@storepilothq.com
This Privacy Policy explains how Zipf LLC ("Zipf," "we," "us"), operator of StorePilot (the "Service"), collects, uses, and protects information. By using the Service you agree to this Policy.
1. Our two roles
For information about you, our customer (account and billing data), we act as a data controller. For the store data we access on your behalf through your connected marketplace accounts, we act as a data processor, processing it only on your instructions under our Terms and Data Processing Agreement.
2. Information we collect
- Account information: name, work email, company name, and authentication details.
- Billing information: Shopify processes StorePilot app subscription charges through Shopify App Pricing. We do not receive or store your full payment-card number.
- Connected-store data: when you authorize a marketplace (Amazon, eBay, Walmart, Shopify, TikTok Shop), we access operational data such as orders, inventory, listings, pricing, ad spend and return requests via that platform's API, to operate the Service for you.
- Connected Google data: if you connect Google Drive or Gmail, we read the documents and recent messages described in section 4 to operate the Service for you, and — where you enable it — send reply drafts you have individually approved.
- Buyer personal data: supported operations may read buyer information from a connected marketplace. Some workflows retain bounded conversation snapshots and operational records to support customer service and case history. Access is scoped to the customer's workspace; sensitive outbound message content and recipients are redacted from action audit records.
- Usage & technical data: log data, device/browser information and product analytics used to operate, secure and improve the Service.
3. How we use information
- To provide and operate the Service, including reading store state and executing actions you approve.
- To secure the Service, prevent abuse, and maintain audit logs of actions taken.
- To communicate with you about your account, support and service updates.
- To improve the Service. We do not sell your data, and we do not use your buyers' personal data to train models.
4. Google user data (Drive and Gmail)
Connecting Google Drive or Gmail is optional. If you do, StorePilot requests read-only access and uses it only to operate the Service for you:
- Google Drive (
drive.readonly) — we read the documents in the folder you nominate (Docs, Sheets, PDFs) so the agent can answer questions from your own operating documents, and so an inventory spreadsheet you choose can be synced. We never create, modify or delete anything in your Drive. - Gmail (
gmail.readonly) — we read recent messages from the mailbox you connect, bounded to a recent time window, to produce your inbox digest and to prepare draft replies. - Sending replies (
gmail.send) — where you enable it, StorePilot prepares a draft reply and sends it from your mailbox only after you have read that specific draft and approved it. Nothing is ever sent automatically or in bulk, replies go back to the existing conversation rather than to addresses we look up, and we do not modify, label or delete mail.
Limited Use. StorePilot's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we do not use Google user data for advertising; we do not sell it; we do not use it to train generalized artificial intelligence or machine-learning models; and we do not allow humans to read it, except with your explicit consent for specific messages, where necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized.
Minimization. We request the narrowest access that supports the feature, and we fetch only a bounded, recent window rather than your whole account. For the inbox digest, only the sender, subject and a short snippet are sent to our configured AI sub-processor under a data-processing agreement — not full message bodies. Where StorePilot learns from marketplace reply history, it retains distilled common-question summaries, usual-answer guidance and closed-vocabulary writing-style attributes. You can also add, edit, or remove that summarized guidance; owner-entered guidance is stored as entered. The history-distillation process is designed to exclude raw buyer text, buyer identities and exact replies, and direct identity and contact patterns are screened before storage.
Retention and deletion. In our hosted service, message content is processed in memory to produce the digest and is not stored at rest. You can disconnect Google Drive or Gmail at any time, which revokes our access and deletes the data we derived from it. See Data deletion for step-by-step instructions, including how to revoke access from your Google Account directly.
5. Legal bases (EEA/UK)
Where GDPR applies, we rely on: performance of a contract (to provide the Service), legitimate interests (to secure and improve it), consent (where required), and legal obligations.
6. Sharing & sub-processors
We share data only with vetted sub-processors under data-processing agreements, including the configured AI model provider (Anthropic by default, or OpenAI where configured), hosting, and transactional email services. A current list is on our Security page. We may disclose information if required by law.
7. Data retention
We retain account data for as long as your account is active and as needed for legal and operational purposes. Operational store data, including any retained workflow conversation snapshots, is kept as needed to provide the Service and according to the applicable data category's retention and deletion controls. When you disconnect a store or close your account, we revoke access and delete or anonymize associated data within a commercially reasonable period.
8. Security
We encrypt data in transit and at rest, store credentials in an encrypted vault, apply least-privilege access, and control consequential actions through individual approvals or explicitly authorized recurring workflows. See our Security page.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, to object to or restrict processing, and to withdraw consent. Under the CCPA/CPRA, California residents may request access and deletion and may opt out of "sale" or "sharing" of personal information — we do not sell or share personal information as those terms are defined. To exercise any right, email privacy@storepilothq.com. For data we process on a customer's behalf, we will refer requests to that customer (the controller) and assist them.
10. International transfers
We operate in the United States. Where data is transferred internationally, we use appropriate safeguards such as Standard Contractual Clauses.
11. Children
The Service is for businesses and is not directed to children under 16.
12. Changes
We may update this Policy; we will post the new effective date and, for material changes, notify you.
13. Contact
Zipf LLC, 344 Maple Ave W, PMB 221, Vienna, VA 22180 — privacy@storepilothq.com.