Privacy Policy for 1tm AI Product Info
Last Updated: September 3, 2026
Introduction
1tm AI Product Info ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Shopify application.
Information We Collect
Store Information
When you install 1tm AI Product Info, we collect:
- Shop Domain: Your Shopify store URL (e.g., yourstore.myshopify.com)
- Access Tokens: OAuth tokens provided by Shopify for API access
Product Data
To provide our AI analysis service, we access:
- Product Information: Titles, descriptions, images, vendors, product types, tags, assigned Shopify categories, product options and variant information such as SKUs and barcodes
- Product Metafields and Features: Available category metafields in the
shopifynamespace, their referenced values, existing and AI-generated metafields in theki_produktinfonamespace, and product-linked feature metaobjects
Usage Data
We track:
- Analysis Jobs: Product IDs, generated suggestions, timestamps, model confidence scores, and processing status
- Usage Records: Analysis counts and Shopify billing event references
- Shop Settings: Your selected languages, writing style, confidence thresholds, auto-apply choice, and product highlight
- Operational Data: Request, error, and performance logs needed to secure and operate the service
Information We Do NOT Collect
The app does not request Shopify customer or order scopes and does not persist:
- Customer profiles, email addresses, phone numbers, or shipping addresses
- Order data
- Payment card or bank information
Shopify's mandatory privacy webhooks can contain customer identifiers and contact details. We authenticate and acknowledge those requests but do not persist their customer payload because the app has no customer-level records.
How We Use Your Information
Service Provision
- Process your products through our AI analysis engine
- Generate product descriptions, attributes, and enrichment suggestions
- Store analysis results and confidence scores as product metafields
Billing
- Track the number of product analyses for usage-based billing
- Process payments through Shopify App Pricing (usage-based billing)
Service Improvement
- Monitor security, system performance, and error rates
- Diagnose failed analyses and support requests
AI-Generated Content
The app generates product titles and descriptions with a large language model. Because that text is published to your public storefront, we mark it as artificially generated in line with EU AI Act Art. 50(2):
- Generated descriptions carry a hidden HTML marker (
data-ai-generated="trainedAlgorithmicMedia"). It renders nothing and does not change how your storefront looks. - Generated titles cannot carry an in-content marker — Shopify's title is plain text — so they are recorded in metafields instead.
- Both are recorded in the
ki_produktinfometafieldsai_generated_fieldsanddigital_source_type(the IPTCtrainedAlgorithmicMediaterm).
Only text the model *composed* is marked. Attributes it *extracts* from your images or from the web — GTIN, material, dimensions, vendor — are facts read from a source, not generated text, and are not marked.
This marking is applied automatically at the moment you apply a suggestion. It is not optional and there is no setting for it. If you later rewrite a generated description yourself, remove the marker with it.
Data Storage and Security
Storage Locations
- App-managed data: OAuth sessions, settings, analysis jobs and results, subscription status, and usage records are stored in Supabase (PostgreSQL)
- Applied Shopify content: Selected suggestions, including those qualifying for automatic apply when you enable it, are written to your Shopify store as product fields, translations, product metafields and merchant-owned feature metaobjects linked to the product
- Application processing: The app is hosted on Vercel and sends product inputs to the service providers listed below when needed for an analysis
Security Measures
- Data is encrypted in transit using TLS
- API access is authenticated through Shopify's OAuth system
- We do not store Shopify API secrets in client-side code
Data Retention
| Data Type | Retention Period |
|---|---|
| OAuth sessions | For the installation; deleted when the app is uninstalled |
| Settings, analysis jobs and results, subscription status, and app-side usage records | For the installation and until Shopify sends the shop/redact event, normally 48 hours after uninstall |
| Content and provenance written to your Shopify store | Remain in your Shopify store until you edit or delete them; uninstalling the app does not remove merchant-approved product content |
| Infrastructure security and error logs | According to the configured retention of Vercel, Supabase, and the relevant processing provider; they are used only to operate and secure the service |
Data Sharing
We do not sell, rent, or share your data with third parties except:
Service Providers
- Google AI (Gemini): Product images and text are processed by Google's AI for analysis. Google's privacy policy applies to this processing.
- Google Cloud Vision: When web detection is enabled, product images are sent to Google Cloud Vision for reverse image search.
- SerpAPI (Google Lens): When the SerpAPI provider is enabled, product images are sent to SerpApi for reverse image search.
- Cloud Infrastructure: Application hosting on Vercel and database storage on Supabase (PostgreSQL)
These providers process data under their applicable terms and privacy commitments. Depending on the selected service and processing region, data can be processed outside the European Economic Area using the safeguards applicable to that provider relationship.
Legal Requirements
We may disclose information if required by law or to protect our legal rights.
Your Rights Under GDPR
If you are in the European Economic Area (EEA), you have the right to:
Access
Request a copy of all data we hold about your store.
Rectification
Request correction of any inaccurate data.
Erasure ("Right to be Forgotten")
Request deletion of all your data. We will comply within 30 days.
Data Portability
Receive your data in a machine-readable format.
Restriction
Request that we limit processing of your data.
Objection
Object to processing of your data for certain purposes.
How to Exercise Your Rights
To exercise any of these rights, please:
- Email us at: contact@1tm.solutions
- Include: Your shop domain and the specific request
- We will respond within 30 days
Automatic Data Deletion
When you uninstall 1tm AI Product Info:
- Immediately: Your session data is deleted
- After 48 hours: Shopify sends a
shop/redactwebhook - Upon that webhook: The app deletes its remaining settings, analysis, subscription, usage, and session records from its database
Product content, translations, metafields, and metaobjects that you previously approved remain in your Shopify store. You control and can edit or delete that Shopify-hosted content.
Children's Privacy
1tm AI Product Info is designed for business use and does not knowingly collect information from children under 13 years of age.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new policy on our website
- Updating the "Last Updated" date above
Continued use of the app after changes constitutes acceptance of the new policy.
Contact Us
For privacy-related questions or concerns:
Email: contact@1tm.solutions
Address: 1tm solutions GmbH Insel 17 89231 Neu-Ulm Germany
Managing Director: Martin Schubert · Commercial register: HRB 19074, Amtsgericht Memmingen · VAT ID: DE339167478
Shopify Privacy Requests
The app authenticates and handles Shopify's mandatory customers/data_request, customers/redact, and shop/redact webhooks. Requests sent to contact@1tm.solutions are handled within the time required by applicable law.
Summary
| What We Do | What We Don't Do |
|---|---|
| Analyze your product data with AI | Request Shopify customer or order access |
| Store analysis results as metafields | Sell or share your data |
| Track usage for billing | Access order or payment data |
| Delete app-managed records after uninstall | Remove product content you approved in Shopify |