Privacy Policy
This Privacy Policy explains how Ciwi collects, uses, stores, and protects information when merchants visit our website, install our Shopify apps, or use our AI-powered ecommerce services.
Effective date: July 27, 2026
This Privacy Policy describes how BOGDA COMPANY LIMITED (“Ciwi”, “we”, “our”, or “us”) collects, uses, discloses, and protects information when you visit ciwi.ai, install a Ciwi Shopify app, contact our team, or use any related products, integrations, or services (collectively, the “Services”).
We build tools for Shopify merchants, including AI-enabled localization, content, and ecommerce workflow products. Because our Services may connect to Shopify and may process merchant or customer-related information, we aim to follow data minimization, transparency, and security principles that align with applicable privacy laws and Shopify platform requirements.
1. Scope
This Privacy Policy applies to information collected through our website, product interfaces, Shopify app listings, support channels, and related business operations. It does not apply to information processed by Shopify itself or by third-party services that maintain their own privacy notices.
2. Information we collect
The categories of information we may collect depend on how you interact with us and which Services you use.
- Merchant account and store information: store name, store domain, Shopify shop identifiers, app installation status, plan or subscription details, locale, theme or configuration metadata, and settings required to provide the Services.
- Contact and business information: name, company name, business email address, billing contact details, support history, and other information you provide when requesting demos, support, or commercial discussions.
- Content and configuration inputs: product content, translations, glossary terms, prompts, instructions, SEO content, metafield-related data, and other materials you choose to process through the Services.
- Usage and technical information: log data, browser type, device information, approximate location based on IP, pages visited, feature usage, event timestamps, crash diagnostics, and similar telemetry used to operate and secure the Services.
- Cookies and similar technologies: essential cookies or similar technologies used for session handling, security, and basic website functionality. We do not use third-party analytics tools on the website at this time.
- Protected customer data: where a feature legitimately requires access to Shopify customer-related information, we seek to access only the minimum data needed to provide that feature and only where the relevant Shopify permissions and merchant authorizations are in place.
3. How we collect information
- Directly from you, such as when you contact us, install an app, configure a feature, or submit content for processing.
- Automatically through your use of our website or Services.
- From Shopify, when a merchant installs or authorizes one of our apps and Shopify makes store data available through approved APIs and scopes.
- From service providers that help us deliver hosting, support, communications, payments, infrastructure, and AI processing.
4. How we use information
- Provide, maintain, support, and secure the Services.
- Authenticate merchants and connect authorized Shopify stores.
- Process translations, generate outputs, apply glossary rules, and perform other requested AI or automation tasks.
- Respond to support requests, onboarding questions, and commercial inquiries.
- Improve product performance, reliability, and user experience, but not by using Shopify Merchant Data or Customer Data to train general-purpose AI models unless separately agreed and lawfully permitted.
- Comply with legal obligations, enforce our terms, detect misuse, and protect our rights, users, and platform integrity.
- Send service-related messages, billing notices, and product updates. We send marketing communications only where permitted by law, and you may opt out where available.
5. Shopify data, customer data, and AI processing
If you install a Ciwi Shopify app, we may process Merchant Data and, where applicable and properly authorized, certain Customer Data made available through Shopify APIs. We aim to request and retain only the data reasonably necessary to deliver the functionality you use. Access to shop data, product data, store settings, and related activity data is based on merchant authorization and the Shopify permissions granted to the app.
We do not access protected customer data unless the merchant has authorized the relevant scopes and the applicable Shopify requirements have been satisfied. If a merchant does not grant those permissions, we do not access that data.
Our AI features use customer and merchant inputs to generate requested outputs such as translations, rewritten copy, glossary-controlled content, or related ecommerce content. We do not use merchant inputs to improve general-purpose models by default, and we do not use Shopify Merchant Data or Customer Data obtained through Shopify to train general-purpose AI or machine learning models.
6. Cookies and analytics
We may use limited cookies or similar technologies that are necessary for website operation, session continuity, and security. We do not currently use third-party analytics or advertising tracking tools on the website. Disabling essential cookies may affect website functionality.
7. How we share information
We do not sell personal information in exchange for money. We may share information in the following circumstances:
- With service providers and subprocessors that support infrastructure, hosting, communications, payment administration, customer support, and AI processing. Our current subprocessors may include Tencent Cloud for email-related services, Shopify for billing and platform operations, and AI providers such as OpenAI, Google, and DeepSeek for approved AI processing tasks.
- With Shopify as needed to operate within Shopify’s platform, comply with app requirements, manage billing, or respond to platform reviews and merchant requests.
- With your direction when you authorize integrations, exports, or other workflows.
- For legal and security reasons when reasonably necessary to investigate fraud, enforce our agreements, respond to lawful requests, or protect rights, safety, and platform integrity.
- In a business transfer such as a merger, acquisition, financing, or asset sale, subject to appropriate confidentiality and legal safeguards.
8. Data retention
We retain information only for as long as reasonably necessary to provide the Services, comply with contractual and legal obligations, resolve disputes, enforce agreements, and maintain security and business records.
- Application and technical logs: generally retained for up to 14 days.
- Billing, support, and operational records: generally retained for up to 60 days after uninstall or account termination, unless a longer period is required by law, dispute resolution, or a valid security reason.
- Merchant-related service data: if the app is uninstalled or deletion is requested, data associated with that merchant is generally deleted within 60 days, subject to lawful exceptions.
9. International transfers
Our Services may be operated from and supported in multiple jurisdictions. Data may be processed or stored outside your local jurisdiction, including on servers located in the United States. Where required, we use appropriate safeguards for cross-border data transfers.
10. Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, alteration, or disclosure. No system is perfectly secure, and we cannot guarantee absolute security.
11. Your rights and choices
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or request portability of certain personal information. You may also have the right to withdraw consent where processing is based on consent.
If you are a merchant using our Shopify apps, some requests may need to be handled in coordination with Shopify or with your own obligations to end customers. We may ask you to verify your identity before processing certain requests. To request access, correction, deletion, or other privacy support, please email support@ciwi.ai. Merchants may also use this email address to request deletion of store data.
12. Data Processing Addendum
Where required for merchant compliance or enterprise review, we can provide a Data Processing Addendum (“DPA”) describing processing roles, security commitments, subprocessors, and related data protection terms.
13. Children’s privacy
Our Services are designed for businesses and are not directed to children. We do not knowingly collect personal information from children in a manner requiring parental consent under applicable law.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our Services, legal obligations, security practices, or Shopify platform requirements. We will post the updated version on this page and revise the effective date above. Material changes may also be communicated through the Services or by email where appropriate.
15. Contact us
BOGDA COMPANY LIMITED
1A-1L Tung Choi Street, Unit 08, 15/F, Mong Kok, Hong Kong
If you have questions about this Privacy Policy, data protection matters, or requests regarding your information, please contact us at support@ciwi.ai.