Shopify app privacy
How Zens AI handles Shopify storefront data
Last updated: September 21, 2026
This notice applies to the Zens AI Shopify app and supplements the general Zens AI Privacy Policy. Contact hello@zens.ai with a privacy request or question.
Shopify permissions
The first release requests no Shopify Admin API scopes for customers, orders, discounts, product administration, or theme files. The embedded setup page uses an online Shopify session to read the current shop name, save the public Site ID on this app installation, and check theme-extension activation. Shopify authenticates these requests through App Bridge; Zens does not store an Admin API access token. Zens verifies the mandatory Shopify privacy webhooks but stores no Shopify customer or order record for those requests to locate.
Storefront context the app can send
When a merchant saves a Zens Site ID and enables the app embed, the extension loads the Zens browser SDK. The Site ID is stored in the app installation's private app-data metafield and can be read by the app's theme extension. The SDK can receive the public page URL and title, referrer, browser language, anonymous visitor and session identifiers, chat messages, attachments, and an email address a visitor chooses to provide. If public product context is enabled, the extension also sends the current Shopify template, store domain, product or collection title and handle, vendor, public price, availability, and cart item count.
The extension does not send the logged-in Shopify customer object. Public Liquid context is used to make a conversation relevant to the page a shopper is viewing, not to build a hidden customer profile. Session recording is off by default and runs only when the merchant enables it in both Shopify and the corresponding Zens site.
Use, security, and retention
Zens uses the data to provide AI customer support, conversation history, human handoff, product-context troubleshooting, and service security. Zens does not sell Shopify data, use it for targeted advertising, or use Shopify integration data to train general AI models. Data is retained according to the merchant’s Zens plan, configuration, and applicable law.
The Site ID is a public widget identifier. It is validated against the store origin by Zens. Shopify compliance requests are accepted only after HMAC verification with the app secret. The app secret and any Zens signing secret remain server-side and must never be pasted into the theme editor.
Merchant and visitor choices
Merchants can disable product context, visitor email follow-up, the floating launcher, or session recording in the theme editor. They can disable the app embed or uninstall the app to stop future collection. Existing Zens conversations are not automatically deleted when the Shopify app is removed because merchants may need the support record for continuity, disputes, or legal retention duties.
An authorized merchant can request access, export, correction, or deletion by emailing hello@zens.ai with the store domain and Zens Site ID. Visitors should contact the store first because the merchant is responsible for its storefront support data. Zens will assist the merchant with verified requests within applicable legal timelines.
Contact and support
Email hello@zens.ai for privacy questions. For installation help, open the Shopify app support page.