Skip to main content
FilterIQRequest access
Menu

Legal

Privacy Policy

Last updated: April 2026. This policy explains what data we collect, how we use it, and your rights under GDPR, CCPA, and other data protection regulations.

1. Who We Are

FilterIQ ("we," "us," or "our") provides AI-powered product search, filtering, merchandising, and analytics services for Shopify stores. This Privacy Policy applies to all merchants and their shoppers who interact with our services. Our website is filteriq.app.

2. Data We Collect Through Shopify APIs

When you install FilterIQ, we access your Shopify store data through Shopify's authenticated APIs. Specifically:

  • Product data: Titles, descriptions, prices, images, tags, variants, collections, and metafields. This data is used to build and maintain your search index in Meilisearch.
  • Collection data: Collection titles, descriptions, and product memberships, used to configure collection-level filters and merchandising rules.
  • Store information: Your myshopify domain, store name, and contact email for account management, billing, and support.

3. Data We Collect Directly

  • Search analytics: Anonymized search queries, click events, filter usage, and zero-result queries from your store's shoppers. We do not collect personally identifiable information (PII) from shoppers. This data powers your analytics dashboard and helps us improve search relevance.
  • Merchant preferences: Filter configurations, merchandising rules, synonym settings, and theme customizations you create within the FilterIQ admin dashboard.
  • Dashboard usage: Page views and feature interactions within the FilterIQ admin, used to improve the product experience.

4. How We Use Meilisearch to Index and Serve Search Results

Your product data is indexed in Meilisearch, an open-source search engine, to power fast and relevant search results on your storefront. Specifically:

  • Each store gets a dedicated, isolated search index identified by your myshopify domain.
  • Product data is synced to your index on install and kept up-to-date via Shopify webhooks (product/create, product/update, product/delete).
  • Search queries from your shoppers are sent to Meilisearch to retrieve results. We apply typo tolerance, synonyms, and merchandising rules at query time.
  • Your search index is deleted within 48 hours of app uninstallation.

5. Data Storage and Infrastructure

We use the following third-party infrastructure providers to operate FilterIQ:

ProviderPurposeData Stored
Supabase (PostgreSQL)Primary databaseMerchant accounts, configurations, analytics, billing state
Meilisearch CloudSearch engineProduct index (titles, descriptions, prices, images, tags, variants, metafields)
Upstash RedisCaching & rate limitingSession tokens, rate-limit counters, ephemeral cache entries
RenderBackend hostingApplication logs (retained for 30 days, no PII)
VercelFrontend hostingStatic assets and edge function logs (no PII)
OpenAI (GPT API)AI suggestion generationCatalog context (product titles, descriptions, tags, variants) submitted during AI Setup, Data Health scans, and AI Assistant queries. Minimized and redacted before submission. Configured per our data-processing agreement and OpenAI's retention controls where available.
Anthropic (Claude API)AI suggestion generationCatalog context (product titles, descriptions, tags, variants) submitted during AI Setup, Data Health scans, and AI Assistant queries. Minimized and redacted before submission. Configured per our data-processing agreement and Anthropic's retention controls where available.
SentryApplication error monitoringStack traces, request metadata excluding bodies/headers/cookies/IP, and performance traces sampled at <= 0.2 (transactions) and <= 0.05 (profiles) per AGENT_HARD_RULES §1.4.

All providers are bound by data processing agreements. Data is encrypted in transit (TLS 1.3) and at rest (AES-256). AI subprocessors (Anthropic, OpenAI) receive only the catalog context required to generate a suggestion; we do not authorize them to use submitted merchant data to train public models.

6. Data Retention and Deletion

  • Product data: Retained in your search index while the app is installed. Deleted within 48 hours of uninstallation.
  • Search analytics: Retained for 12 months, then aggregated and anonymized. Raw event data is purged after aggregation.
  • Account information: Retained while your account is active. Deleted within 30 days of app uninstallation or account closure.
  • Redis cache: Ephemeral data with automatic TTL expiry (typically 1-24 hours). No manual deletion required.

7. Shopify Compliance Webhooks

We implement all mandatory Shopify compliance webhooks:

  • customers/data_request — When a merchant receives a data subject request from a customer, we respond with all data we hold related to that customer (if any). Since we do not collect shopper PII, this typically returns an empty dataset.
  • customers/redact — When a merchant requests erasure of customer data, we delete any records associated with the specified customer identifier within 48 hours.
  • shop/redact — When a store uninstalls the app, we delete all data associated with the store — including the search index, configurations, analytics, and account information — within 48 hours.

8. GDPR Rights (European Economic Area)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of all personal data we hold about you or your store.
  • Right to rectification: Request correction of inaccurate or incomplete personal data.
  • Right to erasure: Request deletion of your personal data. This also happens automatically when you uninstall the app.
  • Right to data portability: Request your data in a structured, machine-readable format (JSON or CSV).
  • Right to restrict processing: Request that we limit how we process your data while a complaint is being resolved.
  • Right to object: Object to processing of your personal data that you believe is unnecessary for the service.

We respond to all GDPR requests within 30 days. Contact privacy@filteriq.app to exercise any of these rights.

9. CCPA Compliance (California)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to know: You can request details about the categories of personal information we collect and how it is used.
  • Right to delete: You can request deletion of your personal information.
  • Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
  • No sale of data: We do not sell personal information. We do not share personal information with third parties for their own marketing purposes.

10. How We Use Your Data

We use your data exclusively to provide and improve our services:

  • Indexing your products in Meilisearch to power search and filter functionality
  • Generating analytics reports about search and filter usage in your store
  • Improving our AI configuration engine based on aggregate, anonymized patterns
  • Sending account-related emails (billing, support, product updates)
  • Providing customer support when you contact us

We never sell your data to third parties. We never use your product data to benefit competing stores. We never share individual store data without your explicit consent.

11. Cookies and Tracking

The FilterIQ admin dashboard uses essential cookies for session management and authentication. We do not use third-party tracking cookies or advertising pixels. The storefront search widget stores a session identifier in your shoppers' browser localStorage so that events fired during a single browsing session can be associated together. The session identifier expires after 30 minutes of inactivity or 24 hours, whichever comes first. We additionally store a single returning-visitor flag (one bit, no identity) so we can distinguish first-time from repeat shoppers in aggregate analytics — the flag carries no personal data and cannot be tied back to an individual. All of these writes only occur after the shopper grants consent via Shopify's Customer Privacy API, and are blocked entirely when the browser sends Global Privacy Control (GPC) or Do Not Track (DNT) signals. No personally identifying information is stored on the device.

12. Changes to This Policy

We may update this Privacy Policy from time to time. Significant changes will be communicated via email or in-app notification at least 30 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

13. Contact

For privacy-related questions or to exercise your data rights, contact us at privacy@filteriq.app. We respond to all privacy requests within 30 days.

For general support inquiries, contact support@filteriq.app.