Legal
Privacy policy
StoreMind AI is built by Northflow Apps. This page explains exactly what the app processes when it is installed on a Shopify store, who else sees it, and for how long.
Last updated: 1 August 2026
Two groups of people are covered here. Merchants install StoreMind AI on their Shopify store. Shoppersuse the assistant on that merchant’s storefront. For shopper data, the merchant is the controller and Northflow Apps is the processor: we handle it on the merchant’s behalf and under their instructions.
What the app processes#
- Store and catalog data
- Product titles, descriptions, images, handles, prices and stock status, read from the Shopify Admin API and indexed so the assistant can answer questions about them. Only active, published products are indexed.
- Shopper questions and answers
- The text a shopper types or speaks, and the reply the assistant gave. These are stored so merchants can review conversations and see which questions come up most.
- Voice recordings
- When a shopper uses the microphone, the audio is sent for transcription and converted to text. The audio is not stored — only the resulting text is kept, exactly as if it had been typed.
- Order lookups
- An order number and the email address on that order, supplied by the shopper. Both are required together: an order number alone would let anyone look up someone else’s order. These are used to fetch the order’s status and are not retained afterwards.
- Widget interaction events
- Anonymous counts of when the assistant was shown, opened or clicked, and an anonymous visitor identifier used to connect a click to a later order. No name, email or address is attached to it.
- Merchant account data
- The store domain, the shop owner’s name and email address, and the access token Shopify issues at install. Used for authentication, billing and support email.
What we do not collect
StoreMind AI does not request access to customer records, does not read your customer list, and does not collect payment card details. Shoppers are never asked to create an account or log in.
Why we process it#
- To answer shopper questions using the merchant’s own catalog and the answers the merchant has written.
- To let a shopper check the status of an order they placed with that merchant.
- To show the merchant what shoppers asked, which answers were rated helpful, and how the assistant is performing.
- To provide support, to bill correctly, and to keep the service running.
We do not sell data, and we do not use shopper questions or merchant catalog data to train our own models or anyone else’s.
Who else sees it#
The app relies on a small number of subprocessors. Each receives only what it needs to perform its function.
- Google (Gemini)
- Generates answers and transcribes voice questions. Receives the shopper's question and the relevant catalog excerpts.
- Pinecone
- Stores the numeric representation of catalog text used for search. Receives product text, kept in a namespace isolated per store.
- ElevenLabs
- Converts the assistant's written reply to speech when a shopper uses voice. Receives the reply text only.
- Resend
- Delivers transactional email to merchants. Receives the merchant's email address and the message.
- Railway
- Hosts the application and its database in the United States.
Data is processed in the United States and may be transferred there from your country. We do not share data with advertisers or data brokers.
Separation between stores#
Every record is stored against the store it belongs to, and every query is filtered by store. Catalog vectors live in a namespace unique to each store. One merchant’s catalog, conversations and analytics are never visible to another merchant.
How long it is kept#
- Conversations and widget events — retained while the app is installed, so merchants can review them.
- Voice audio — not retained. Discarded once transcribed.
- Order lookup details — not retained after the status is returned.
- Catalog index — deleted when the app is uninstalled.
- Everything else — deleted within 48 hours of uninstall, except where we are required to keep billing records.
The app implements Shopify’s mandatory privacy webhooks. When Shopify sends a customer data request, a customer redaction request or a shop redaction request, we act on it automatically.
Your rights#
Depending on where you live, you may have the right to access, correct, export or delete personal data we hold, and to object to or restrict its processing.
Shoppers: contact the store you were shopping with. They control the data and can pass the request to us. You may also write to us directly and we will route it to the merchant.
Merchants: email us and we will respond within 30 days. Uninstalling the app also triggers deletion as described above.
Security#
All traffic is encrypted in transit with TLS. Access tokens and API keys are stored hashed or encrypted, and API keys are shown to merchants once and never again. Access to production systems is limited to the people who maintain the service.
No system is perfectly secure. If a breach affects your data, we will notify affected merchants and, where required, the relevant supervisory authority.
Children#
StoreMind AI is a business tool sold to merchants and is not directed at children. We do not knowingly collect data from children.
Changes to this policy#
If we change how data is handled, we will update this page and revise the date at the top. Material changes affecting merchants will also be sent by email.
Contact#
Northflow Apps — support@northflow.online
Write to us for any privacy question, data request or complaint. We answer privacy requests from the same address.