Privacy Policy

How UFUQTECHS handles your data on the ufuqseo.com platform.

Last updated: September 2, 2026

1. Introduction & Scope

This Privacy Policy explains how UFUQTECHS ("UFUQTECHS", "we", "us") collects, uses, discloses, and safeguards information when you use the UFUQ SEO platform at ufuqseo.com (the "Service"), an AI-powered catalog and SEO optimization tool for Shopify merchants.

This policy applies to merchants and authorized users who create an account and connect a Shopify store. It does not govern Shopify's own handling of your data, which is covered by Shopify's privacy policy, nor the practices of your own storefront toward your shoppers.

For users in the European Economic Area and the United Kingdom, UFUQTECHS acts as a data controller for account data and as a data processor for the store catalog metadata you instruct us to analyze. For residents of California, this policy is intended to satisfy disclosure requirements under the CCPA/CPRA.

2. Data We Collect

We collect only what the Service needs to function:

  • Account information — your email address, display name, and profile avatar, supplied directly or through Google or GitHub sign-in.
  • Store connection data — your Shopify store URL, shop name, shop email, and the Admin API access token you provide. Tokens are used exclusively server-side and are never exposed to the browser.
  • Product catalog metadata snapshots — product titles, handles, descriptions, meta titles, meta descriptions, tags, vendor, product type, image URLs and alt text, variant prices and SKUs, and computed SEO scores.
  • Optimization history — the before and after values of content you generate and sync, retained so you can review or roll back a change.
  • Billing records — subscription status and plan tier. Payment instruments are handled by Paddle, not by us (see section 3).
  • Basic technical logs — IP address, timestamp, and error diagnostics generated when the Service is used, retained for security and debugging.

Legal bases for processing under the GDPR are: performance of a contract (operating the Service you signed up for), legitimate interests (securing and improving the Service), and consent where required.

3. Data We Do NOT Collect

We want to be explicit about what never touches our systems:

  • We do not store or process credit card numbers, CVV codes, or bank details. All payment data is collected and processed directly by Paddle.com, which acts as our Merchant of Record.
  • We do not access, request, or store your end customers' personal data — names, shipping addresses, email addresses, or order histories of the shoppers who buy from your store.
  • We do not read your Shopify orders, customers, or financial reports. Our API scope is limited to product catalog read and write operations.
  • We do not sell, rent, or share personal information with third parties for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA.

4. How We Use Data

Data collected is used strictly to deliver the functionality you request:

  • To compute SEO health scores and identify catalog gaps such as missing meta descriptions or image alt text.
  • To generate AI copywriting — optimized titles, meta descriptions, product descriptions, keyword tags, and image alt text — by sending the relevant product metadata to our AI provider.
  • To sync approved content back to your Shopify store through the Admin API.
  • To produce the audit reports, competitor keyword analyses, and JSON-LD schema you generate in the Service.
  • To administer your account, process subscriptions, provide support, and secure the platform against abuse.

We do not use your catalog data to train foundation models. Content sent to our AI provider is transmitted for the purpose of generating your output only.

5. Third-Party Sub-Processors

The Service depends on the following sub-processors. Each processes data only as needed to provide its function:

  • Supabase — authentication, database hosting, and storage of account records, store connections, catalog snapshots, and optimization history.
  • Paddle — Merchant of Record for all subscriptions. Paddle collects and processes payment details, billing addresses, and tax information directly.
  • OpenRouter — routes product metadata to the large language model that generates optimized SEO copy.
  • Netlify — application hosting, content delivery, and edge routing.

Where data is transferred outside the EEA or UK, transfers are made under Standard Contractual Clauses or an equivalent lawful transfer mechanism operated by the relevant sub-processor.

6. Data Retention & Your Rights

Catalog snapshots and optimization history are retained while your store remains connected, so that scores stay comparable over time and rollback remains available.

You may exercise the following controls at any time:

  • Disconnect a store — from Settings → Stores. This revokes our use of the associated Admin API token immediately.
  • Purge snapshots — request deletion of catalog snapshots and optimization history for any store you have connected.
  • Access and portability — request a copy of the personal data we hold about you in a machine-readable format.
  • Rectification — correct inaccurate account information.
  • Erasure — request deletion of your account and associated records. We will complete verified requests within 30 days, except where retention is required by law.
  • Objection and restriction — object to or request restriction of processing based on legitimate interests.
  • Non-discrimination — we will not degrade the Service because you exercised a privacy right.

You may also revoke access independently at any time by deleting the custom app from your Shopify admin. EEA and UK users have the right to lodge a complaint with their local supervisory authority.

7. Contact for Privacy Inquiries

Direct any privacy question, data subject request, or complaint to privacy@ufuqseo.com. Please include the email address associated with your account so we can verify the request.

We aim to acknowledge privacy requests within 72 hours and to resolve them within 30 days. If we make material changes to this policy, we will update the "Last updated" date above and notify account holders by email before the changes take effect.