Legal

Privacy Policy

How OfferOptics handles information across our website, Shopify application, commerce intelligence platform, shopper experiences, and connected providers.

Last updated August 11, 2026

Scope and privacy roles

This Privacy Policy explains how OfferOptics, Inc. ("OfferOptics," "we," "us," or "our") handles personal information through our websites, Shopify application, commerce intelligence services, shopper experiences, integrations, and support.

A retailer generally decides why and how its store and shopper information is used. For that information, the retailer is typically the controller or business and OfferOptics acts as its processor or service provider. OfferOptics acts as a controller for website visitors, business contacts, account administration, security, and our own legal and operational records.

Information we handle

The information available to OfferOptics depends on the products a retailer enables.

  • Retailer and account information: store domain, Shopify installation and session records, administrator identity and role, billing status, configuration, support requests, and evaluation or referral details.
  • Commerce information: catalog, collection, inventory, cart, checkout, order, refund, promotion, and fulfillment signals needed for enabled functionality.
  • Shopper and interaction information:consented or otherwise permitted storefront events, pseudonymous identifiers, conversation messages, product requests, recommendation outcomes, and support handoff context. Direct identifiers are minimized and hashed or pseudonymized where the product does not require the original value.
  • Integration information: connection settings, provider account references, scopes, health records, and encrypted OAuth or API credentials supplied by an authorized retailer administrator.
  • Technical information: request and device metadata, diagnostics, performance measurements, audit events, security events, and usage records.

Where information comes from

  • Retailers and their authorized administrators.
  • Shopify APIs, webhooks, app pixels, storefront surfaces, and billing services.
  • Shoppers using an enabled OfferOptics experience.
  • Providers a retailer chooses to connect, such as support, marketing, CRM, reviews, loyalty, subscription, analytics, or recommendation services.
  • Service, security, and infrastructure telemetry generated while operating OfferOptics.

How we use information

  • Provide, configure, secure, support, and improve enabled OfferOptics products.
  • Find conversion friction, support product discovery, generate retailer-facing analysis, prepare approval-ready actions, and measure experiments and outcomes.
  • Answer shopper questions and perform expressly enabled actions such as alerts or governed support handoffs.
  • Authenticate users, enforce permissions, prevent abuse, and maintain audit records.
  • Administer evaluation access, subscriptions, usage limits, and Shopify billing.
  • Meet legal obligations and respond to valid privacy or security requests.

AI and automated processing

OfferOptics uses deterministic software, statistical methods, embeddings, and bounded AI services to classify requests, retrieve relevant information, summarize authorized context, and prepare recommendations. Retailer controls, permissions, data-source authority, product validation, and action parameters are enforced by application code.

The retailer decides which customer-facing or operational features to enable. OfferOptics does not silently apply retailer storefront changes merely because a model recommends them. Supported administrative changes require the permissions and approval workflow presented in the application.

When information is disclosed

We disclose information only as needed for the purposes described in this policy:

  • To Shopify and providers a retailer directs OfferOptics to connect or act through.
  • To infrastructure, hosting, AI, email, monitoring, and professional service providers operating under contractual and confidentiality obligations.
  • To comply with law, protect rights and safety, investigate abuse, or complete a corporate transaction subject to appropriate safeguards.

We do not sell personal information for money. We do not give one retailer access to another retailer's identifiable store or shopper data.

Retention and deletion

We retain information for the period needed to provide enabled services, maintain security and auditability, satisfy contractual or legal obligations, and resolve disputes. Several OfferOptics products let retailers configure bounded retention periods. Backup and legal-hold records can remain for a limited additional period before deletion.

OfferOptics handles Shopify's mandatory customer data request, customer redaction, and shop redaction webhooks. Uninstall disables active intelligence and provider connections and revokes stored integration credentials; Shopify's shop-redaction lifecycle triggers deletion of the associated shop data unless retention is legally required.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted transport, encrypted production storage, tenant-scoped access, role and permission checks, audit records, and tenant-bound envelope encryption for supported integration credentials. No system is completely secure. Read our Security page for the current public security posture.

Privacy rights and choices

Depending on applicable law, an individual may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information. A shopper should normally submit a request to the retailer that controls the relevant Shopify store. OfferOptics supports retailers through Shopify's privacy request process.

Website visitors and business contacts can send a request to support@offeroptics.com. We may need to verify identity and authority before completing a request.

International processing and children

OfferOptics and its providers may process information in the United States and other locations where they operate. Where required, transfers are governed by contractual or other recognized safeguards.

OfferOptics is a business commerce service and is not directed to children. Retailers are responsible for configuring their stores and enabled services consistently with the laws that apply to their shoppers.

Changes and contact

We may update this policy as the platform, providers, or legal requirements change. The date above identifies the current version. Material changes will be communicated as required by law or contract.

Questions or privacy requests can be sent to support@offeroptics.com. Shopper opt-out requests may also be sent to optout@offeroptics.com.