Privacy Policy
Aervo LLC ("Aervo," "we," "us," or "our") is committed to protecting the
privacy and security of your data. This Privacy Policy explains how we
collect, use, store, and protect information when you use the Aervo app
(the "App") for Shopify.
By installing and using Aervo, you agree to the collection and use of
information in accordance with this Privacy Policy.
When you install and use Aervo, we collect and process the following
types of data from your Shopify store:
Store Data
-
Sales Data: Orders, transactions, revenue, refunds,
and payment information
-
Product Data: Product listings, inventory levels,
SKUs, pricing, variants, and product descriptions
-
Customer Data: Customer names, email addresses,
purchase history, order frequency, and customer segments
-
Store Analytics: Traffic data, conversion rates,
shopping behavior, and performance metrics
-
Store Information: Store name, domain, currency,
timezone, and store settings
Usage Data
We may also collect information about how you interact with the App,
including:
- Features used
- Time spent in the App
- Frequency of use
- Error logs and diagnostic information
2. How We Use Your Information
We use the collected data solely to provide and improve the Aervo
service:
Primary Uses
-
Generate Business Insights: Analyze your store data
to create actionable business intelligence and recommendations
-
Real-Time Analytics: Process sales, inventory, and
customer trends to deliver timely insights
-
Smart Recommendations: Use AI to identify
opportunities and provide strategic guidance
-
Dashboard & Reporting: Present your data in clear,
easy-to-understand visualizations
-
Performance Monitoring: Track key metrics and alert
you to important changes
Secondary Uses
-
Service Improvement: Understand how merchants use
Aervo to enhance features and user experience
-
Technical Support: Diagnose and resolve technical
issues
-
Security: Detect and prevent fraud, abuse, or
security vulnerabilities
3. Data Storage and Security
Where We Store Data
Your data is stored securely using:
-
Cloud Infrastructure: Render (cloud hosting platform)
- Database: Hosted PostgreSQL database
- Data Center Locations: United States
Security Measures
We implement industry-standard security practices to protect your data:
-
Encryption: Data is encrypted in transit (TLS/SSL)
and at rest
-
Access Controls: Strict authentication and
authorization protocols
-
Regular Security Audits: Ongoing monitoring and
vulnerability assessments
-
Secure Infrastructure: Use of SOC 2 compliant hosting
providers
-
Limited Access: Only authorized personnel have access
to merchant data, and only as necessary to provide the service
4. Third-Party Service Providers
We share data with the following categories of third-party service
providers to operate and improve Aervo:
Infrastructure & Hosting
-
Render: Cloud hosting and infrastructure services
-
PostgreSQL Hosting Provider: Database storage and
management
AI & Machine Learning Services
-
OpenAI: AI-powered analysis and natural language
processing for generating insights
-
Anthropic (Claude): AI-powered analysis and
recommendation generation
Analytics & Monitoring
We may use analytics tools to understand App usage and performance
(e.g., error tracking, performance monitoring).
Data Protection
All third-party service providers:
- Are contractually obligated to protect your data
-
Only have access to data necessary to perform their specific functions
- Are prohibited from using your data for their own purposes
- Comply with applicable privacy laws and regulations
Important: We do NOT sell your data to third parties
for marketing or advertising purposes.
5. Data Retention
Active Merchants
We retain your store data for as long as you actively use the Aervo App.
This allows us to:
- Maintain historical trends and analytics
- Provide accurate insights over time
- Preserve your custom settings and preferences
After Uninstallation
When you uninstall Aervo:
- We stop collecting new data immediately
-
We retain your data for up to 30 days to allow for:
- Reactivation of your account if you reinstall
- Final report generation
- Backup and disaster recovery purposes
-
After 30 days, we permanently delete all your store data from our
systems
You may request immediate deletion of your data at any time by
contacting us at
aervoadmin@aervoapp.com.
6. Your Rights (GDPR & CCPA Compliance)
You have the following rights regarding your data:
Right to Access
You can request a copy of all data we have collected about your store.
Right to Deletion
You can request that we delete all your store data from our systems at
any time.
Right to Correction
You can request that we correct any inaccurate information.
Right to Data Portability
You can request your data in a structured, machine-readable format.
Right to Object
You can object to certain types of data processing.
How to Exercise Your Rights
To exercise any of these rights, please contact us at
aervoadmin@aervoapp.com with:
- Your store name and domain
- The specific right you wish to exercise
- Any additional details about your request
We will respond to your request within 30 days.
7. GDPR Webhook Compliance
Aervo complies with Shopify's mandatory GDPR webhooks:
Customer Data Request
If a customer requests their data from your store, we will provide all
data we hold about that customer within 30 days.
Customer Redaction
If a customer requests deletion of their data, we will permanently
delete all personal information associated with that customer within 30
days.
Shop Redaction
When you uninstall Aervo or delete your Shopify store, we will
permanently delete all your store data within 30 days.
To initiate any GDPR request, contact us at
aervoadmin@aervoapp.com.
8. Cookies and Tracking
Aervo may use cookies and similar tracking technologies to:
- Maintain your session and keep you logged in
- Remember your preferences and settings
- Analyze App usage and performance
You can control cookies through your browser settings, but disabling
cookies may affect the functionality of the App.
9. Children's Privacy
Aervo is not intended for use by anyone under the age of 13. We do not
knowingly collect personal information from children under 13. If we
become aware that we have collected data from a child under 13, we will
take steps to delete that information promptly.
10. International Data Transfers
Your data may be transferred to and processed in countries other than
your own, including the United States. We ensure appropriate safeguards
are in place to protect your data in accordance with this Privacy Policy
and applicable laws.
11. Data Breach Notification
In the unlikely event of a data breach that affects your information, we
will:
-
Notify you within 72 hours of becoming aware of the
breach
- Describe the nature of the breach and data affected
- Provide guidance on steps you can take to protect yourself
- Report the breach to relevant authorities as required by law
12. Your Responsibilities
As a merchant using Aervo, you are responsible for:
-
Obtaining proper consent from your customers for data collection and
processing
- Complying with applicable privacy laws in your jurisdiction
- Maintaining the security of your Shopify admin credentials
-
Informing your customers about third-party apps you use (including
Aervo)
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes
in:
- Our data practices
- Legal requirements
- New features or services
When we make changes:
-
We will update the "Last Updated" date at the top of this policy
-
We will notify you via email at your Shopify admin email address
-
For material changes, we will provide at least
30 days' notice before the changes take effect
-
Continued use of Aervo after changes take effect constitutes
acceptance of the updated policy
14. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), our legal basis for
processing your data is:
-
Contractual Necessity: Processing is necessary to
provide the Aervo service you've requested
-
Legitimate Interests: We have a legitimate interest
in improving our service and ensuring security
-
Consent: Where required, we obtain your explicit
consent for specific data processing activities
15. Third-Party Links
The App may contain links to third-party websites or services. We are
not responsible for the privacy practices of these third parties. We
encourage you to review their privacy policies before providing any
information.
16. Dispute Resolution
If you have concerns about how we handle your data:
-
Contact us first at
aervoadmin@aervoapp.com
- We will investigate and respond within 30 days
-
If unresolved, you may file a complaint with your local data
protection authority
17. Compliance with Shopify Policies
Aervo complies with:
- Shopify Partner Program Agreement
- Shopify API License and Terms of Use
- All applicable Shopify App Store requirements