Who we are
Attravo (“Attravo,” “we,” “us,” or “our”) builds Shopify apps, runs done-for-you services for Shopify brands, and is developing AI agents for Shopify stores. This policy explains how we handle data across all of them.
Our apps are listed on the Shopify App Store and operate under the scopes verified and approved by Shopify. Our services engagements involve direct, scoped access to a customer’s Shopify store and connected tools under signed agreements.
Attravo
3072 Washington Rd, Atlanta, GA 30344, USA
support@attravo.io
Our commitments
Four promises govern everything below. Where any other section could be read as narrowing them, these win.
- We do not keep your data after you leave. Uninstall an app or end a services engagement and your sessions, orders, and customer records are deleted. We do not hold a copy for later.
- We do not sell or share it. We do not sell personal data, share it with advertising networks, or trade it with anyone. Data goes only to the sub-processors we name publicly, and only to run the service you are paying for.
- We do not use it for unrelated work. Your data is used to deliver your service. It is not repurposed for another customer, sold as benchmarks, or mined for anything you did not ask for.
- We do not train AI models on it. Neither we nor our model providers use your store data or your shoppers’ data to train or fine-tune models.
Scope of this policy
This policy covers:
- Apps: Drawer Cart, Bundle Builder, Product Quiz, and any future app published under the Attravo developer account.
- Services: Conversion Rate Optimization, Retention Marketing, Theme Development, and custom work.
- Agents: the AI agents described on our agents page. These are in development and not yet generally available. The disclosures here apply from the day they are.
- Website: attravo.com, waitlists, newsletters, and contact forms.
All three App Store listings link here, so the app sections apply to you whether or not you ever engage us for services.
Data we collect through our apps
When a Shopify merchant installs one of our apps, we receive only the data permitted by the scopes the merchant approves during installation. Every scope is reviewed and verified by Shopify before our apps are published, and we request the minimum each app needs to function.
Store data
- Shop name, domain, primary email, plan, currency, and timezone.
- Products, collections, variants, and inventory levels required to render bundles, cart upsells, and quiz recommendations.
- Order data used for analytics, attribution, and revenue reporting back to the merchant.
- Discount codes and promotions created by the app.
Shopper-facing app data
- Device and activity data (approximate location, IP address, browser, operating system) used for app analytics scoped to the shop.
- Cart and bundle session state, so shoppers do not lose progress on refresh.
- Quiz answers, and email or phone numbers a shopper explicitly submits through Product Quiz. Where a merchant connects an email or SMS platform, those contacts sync to the merchant’s own account there.
Merchant staff data
- Store owner contact details (name, email, address) used for billing and support.
For app data the merchant is the controller and Attravo is the processor. Merchants are responsible for having a lawful basis to collect shopper data through our apps and for disclosing it in their own store privacy policy.
Data we collect through services
Services engagements involve direct, scoped access to the customer’s tooling under a signed Master Services Agreement and the associated DPA.
- Shopify admin access with role-based permissions, limited to what the engagement requires.
- Read or read/write access to your email and SMS platform, analytics, and testing tools, as relevant to the engagement and as you grant it.
- Customer and order data used for cohort analysis, retention modeling, and CRO test design. We aggregate wherever the analysis allows it.
- Stakeholder contact data (name, email, role) for project communication.
Access is revoked at engagement close, and any data we extracted during the engagement is deleted then too. The “Retention and deletion” section below gives the timing.
Data processed by our AI agents
Our AI agents are in development. When they launch they will read store data to spot conversion leaks, watch retention signals, and flag operational anomalies. This section states how they will handle data so the commitment exists before the product does.
What agents read
- Store, product, order, and analytics data already covered above, under the scopes you approve.
- The outputs of previous agent runs, so an agent can build on its own prior analysis for your store and only your store.
How model providers are used
- Agents send prompts to third-party model providers, listed on our sub-processors section, to generate analysis and recommendations.
- We minimize what is sent. Personal data is excluded from prompts wherever the analysis does not require it, and we aggregate or pseudonymize where it does.
- Your data is not used to train or fine-tune any model, by us or by our providers.
- Prompts and outputs are retained only as long as needed to run the agent and show you its reasoning, and are deleted on the same schedule as the rest of your data.
Automated decisions and human oversight
Agents produce recommendations and, where you explicitly enable it, take actions inside scopes you have granted. You control which actions an agent may take without approval, and you can require review for any of them. We do not use agents to make decisions producing legal or similarly significant effects about individual shoppers. Agent output can be wrong, so material changes should be reviewed by a person before they ship.
Data we collect on the website
- Contact form submissions: name, work email, store URL, interest area, and message body.
- Waitlist signups: email and any context you submit.
- Analytics: page views, referrer, device, and approximate location via Google Analytics. We do not run advertising or remarketing pixels, and we do not sell or share this data with advertising networks.
Website analytics is entirely separate from app and store data. For details on cookies and how to opt out, see our cookies policy.
How we store and secure data
Our apps run on Google Cloud Platform, with application data in a managed MongoDB database. Data is encrypted in transit with TLS and encrypted at rest by our infrastructure providers.
- Production data is logically isolated per Shopify shop.
- Access to production systems is restricted by role and protected by multi-factor authentication.
- Backups are encrypted and rotated on a fixed schedule, so a deleted shop’s data ages out of backups rather than persisting indefinitely.
- Source code is version controlled. Customer data is never committed to a repository.
- We follow least-privilege access, dependency scanning, and a documented incident response process.
We are not currently certified under SOC 2 or ISO 27001. We describe the controls we actually operate rather than claiming an audit we have not completed. Ask us at support@attravo.io for a written summary of current controls.
Sub-processors
A sub-processor is a third party we engage to process personal data on a customer’s behalf. This section is the authoritative list, and our DPA incorporates it by reference. Each provider is bound by written terms no less protective than this policy.
We keep the list short on purpose. Every entry is a party we actually use today. We do not list providers we are merely evaluating, and we do not pad it with tools that never touch customer data.
Current sub-processors
- Google Cloud Platform: Application hosting, compute, and storage for the Shopify apps.
Regions: United States, European Union, Asia-Pacific - MongoDB: Managed database holding app configuration and shop-scoped records.
Regions: United States, European Union - Shopify: App installation, OAuth, subscription billing, and order webhooks.
Regions: United States, European Union, Canada. Scope: Apps only - Stripe: Payment processing for services invoices, and the processor behind Shopify Payments.
Regions: United States, European Union - Amazon Web Services (SES): Transactional email for app and account notifications.
Regions: United States - Google Analytics: Aggregate traffic measurement on attravo.com.
Regions: United States, European Union. Scope: Website only, never app or store data - Calendly: Scheduling when you book a call with us.
Regions: United States. Scope: Website only
AI model providers
Engaged for our AI agents, which are in development and not yet generally available. Listed in advance so the disclosure is in place before the product ships rather than after.
- Anthropic: Model inference for the AI agents. Prompts are not used to train models.
Regions: United States. Scope: Agents only, not yet generally available - OpenAI: Model inference for the AI agents. Prompts are not used to train models.
Regions: United States. Scope: Agents only, not yet generally available
Neither provider uses your data to train or fine-tune models. Agents send the minimum data an analysis requires, aggregated or pseudonymized wherever that is possible.
What is not on this list
Some tools we use never process customer personal data, so they are not sub-processors: source control and code review, where customer data is never committed to a repository, and internal team communication and project tracking, which carry project notes rather than store or shopper data.
During a services engagement we also work inside tools that you own and control, such as your Shopify admin, your email and SMS platform, and your analytics. Those remain your vendors under your own agreements. We are a user of them, not a processor behind them.
Changes and notice
Before a new sub-processor begins processing personal data, we give customers at least 30 days notice. Customers may object on reasonable data protection grounds. If we cannot find a workable resolution, the customer may terminate the affected service. To be notified of changes, email support@attravo.io and ask to be added to the sub-processor notification list.
Retention and deletion
We retain data only while we are actively providing the service. There is no post-relationship archive.
When you uninstall an app
- Deletion is triggered automatically by Shopify’s uninstall webhook and completes within 48 hours.
- Everything shop-scoped goes: sessions, order records, quiz responses, bundle and cart configurations, and analytics records.
- Residual copies inside encrypted backups age out on the next rotation, within 30 days. They are not restorable into production and are not used for any purpose in the meantime.
When a services engagement ends
- All access we were granted is revoked at engagement close.
- Data we extracted for analysis is deleted within 30 days of close, unless you ask us in writing to hold it for a follow-on sprint.
- Deliverables you paid for remain yours. Working copies on our side are removed.
What we keep and why we keep it
Two narrow exceptions, neither of which includes your shoppers’ personal data: billing and tax records we are legally required to retain, and ordinary business correspondence such as the email thread you started with us. Anything under a legal hold is retained until the hold lifts.
Shopify mandatory webhooks
We implement Shopify’s required privacy webhooks: customers/data_request, customers/redact, and shop/redact. Requests sent directly to us are honored within 30 days.
Your rights
Depending on your jurisdiction (GDPR, UK GDPR, CCPA and CPRA, LGPD, and similar laws), you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your personal data.
- Request a portable copy of your data.
- Object to or restrict certain processing.
- Withdraw consent where processing relies on consent.
- Be free from discrimination for exercising any of these rights.
- Lodge a complaint with a supervisory authority in your jurisdiction.
We do not sell personal data and we do not share it for cross-context behavioral advertising, as those terms are defined under California law.
Shoppers: we process your data on behalf of the store you bought from, so start with that merchant. Email us at support@attravo.io and we will route your request to them and assist. Merchants and customers: email support@attravo.io directly. We respond within 30 days.
International data transfers
We are based in the United States and our sub-processors operate in the regions listed on the sub-processors section. Where personal data is transferred out of the EU, UK, or Switzerland, we rely on Standard Contractual Clauses or another legally recognized transfer mechanism.
Children
Our apps, services, and agents are sold to businesses and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact support@attravo.io and we will delete it.
Changes to this policy
We update this policy as our products, sub-processors, or applicable laws change. Material changes are announced in the app dashboard and by email to active customers at least 30 days before they take effect. The “Last updated” date above reflects the most recent revision.
Contact
For privacy questions, data requests, or to report a concern:
Attravo
3072 Washington Rd, Atlanta, GA 30344, USA
support@attravo.io
We respond within 24 business hours.