AAgentShelf

Legal

Privacy Policy

Last updated: August 16, 2026

This Privacy Policy explains how NOVA NORTH CONSULTING LLP ("AgentShelf", "we", "us") collects, uses, and protects information when you use AgentShelf, our agent-readiness audit and analytics service for online stores.

1. Information we collect

Account data: When you create an account, we collect your email address and a display name. We use Supabase Auth to manage sign-in.

Store data: When you run an audit or connect a store, we fetch publicly available pages (products feed, robots.txt, llms.txt, agents.md, homepage HTML) and, if you authorize Shopify, read catalog and product data via the Shopify Admin API.

Traffic analytics: If you install the AgentShelf Pixel, we collect pageview and event metadata (referrer, URL, timestamp, anonymized session ID) to measure AI-agent-driven traffic. We do not collect the names, email addresses or payment details of your shoppers, and we do not build advertising profiles or sell this data.

Payment data: Billing is processed by Paddle, our merchant of record. We receive your subscription status and customer ID, but Paddle holds your card details — we never store payment instrument data.

2. Shopper data and our role

For your own account and store data, we are the data controller. For data collected by the AgentShelf Pixel about visitors to your storefront, we act as a processor on your behalf — you decide to install the Pixel and you remain the controller of that data.

As the controller, you are responsible for disclosing this collection in your own privacy notice and for obtaining visitor consent where your jurisdiction requires it. We process shopper data only to produce your analytics, never for our own purposes, and never resell it. If you require a Data Processing Agreement, contact us at vmehta2401@gmail.com.

3. How we use your data

  • Generate audit reports and readiness scores for your store.
  • Run full-catalog audits and apply fixes you approve.
  • Track AI-agent traffic and alert you when agent access breaks.
  • Deliver audit reports and access alerts by email (opt-out at any time).
  • Process subscriptions and manage your Growth plan.

4. Data sharing

We do not sell your data. We share data only with the sub-processors needed to operate the service:

  • Supabase — authentication and database hosting.
  • Paddle — subscription billing and tax compliance.
  • Shopify — when you connect a store via OAuth or API token.
  • Resend — transactional email delivery.
  • AI providers (OpenAI, Google, Perplexity) — we send only the shopping questions you choose to track, in order to record the answers returned. We do not send your customer data or store credentials, and we use API tiers that are not trained on submitted content by default; their handling is governed by their own terms.

Our providers operate in several countries, so your data may be processed outside the country you live in, including outside India, the EU and the UK. Where required we rely on appropriate safeguards such as standard contractual clauses.

5. Data retention and deletion

Audit reports and analytics data are retained while your store is connected and your account is active. Disconnecting a store deletes its record along with the associated audits, findings, rank history and analytics.

If you uninstall our Shopify app, we clear the stored credentials for that store immediately on receiving Shopify's app/uninstalled notification, and we delete the store's data on receipt of Shopify's shop/redact request, which Shopify sends approximately 48 hours after uninstall. To delete your account entirely, email vmehta2401@gmail.com.

6. Security

We encrypt Shopify access tokens at rest using AES-256-GCM. Database access is governed by row-level security policies. Payment data is never stored on our servers.

7. Your rights

You may request access to, correction of, or deletion of your personal data, and may object to or request restriction of processing. Email vmehta2401@gmail.com to exercise these rights and we will respond within the period your law requires. If you are in the EU, UK, or California, you have additional rights under GDPR/CCPA, including the right to complain to a supervisory authority.

8. Cookies & tracking

We use essential cookies for authentication. The AgentShelf Pixel uses local storage and beacon requests for analytics only — no third-party advertising cookies.

9. Contact

For privacy questions, data requests or a Data Processing Agreement, contact NOVA NORTH CONSULTING LLP at vmehta2401@gmail.com.