📌 Key Architectural Note
SellyGUIDE is built on a Bring Your Own AI (BYOAI) model. Your Shopify store data and connected tool data (Meta Ads, Google Ads, Klaviyo, etc.) are NOT stored on SellyGUIDE servers — they flow directly to your AI provider via MCP (Model Context Protocol). Our VDS backend handles orchestration only: it stores your API key (encrypted), verifies your subscription plan, and manages the skills router. No store, advertising, or customer data is ever held on our backend.

1. Introduction and Scope

This Privacy Policy describes how SellyGUIDE ('we', 'us', 'our') collects, uses, and protects data through sellyguide.com and the Shopify App Store application.

This policy is prepared in compliance with the Turkish Personal Data Protection Law (KVKK — Law No. 6698), the EU General Data Protection Regulation (GDPR), and UK GDPR.

2. Data Controller

  • Company: SellyGUIDE
  • Contact: Ahmed Selim URUNCA — Founder / CEO
  • Email: contact@sellyguide.com
  • Website: sellyguide.com/privacy

3. Data We Collect

3.1 Account Information

  • Email address and store name — collected during onboarding
  • Shopify plan information and store region
  • Subscription record — via Shopify Billing API or Stripe

3.2 Shopify Store Data (via GraphQL API)

The following data is accessed via MCP solely to deliver SellyGUIDE's features. It is NOT stored on SellyGUIDE servers.

  • Orders: totals, line items, dates, fulfillment status — for anomaly detection
  • Inventory: stock levels, variant data — for stockout alerts
  • Products: titles, descriptions, tags — for product performance analysis
  • Sales metrics: revenue and conversion data via ShopifyQL — for analytics

⚠️ Customer Personal Data: We do not access customer names, addresses, emails, or payment details unless explicitly approved for protected customer data access. This data never reaches SellyGUIDE servers.

3.3 Google Ads & Google Analytics Data (via OAuth/MCP)

When a merchant explicitly connects their Google Ads and/or Google Analytics 4 (GA4) account via OAuth 2.0, SellyGUIDE accesses the following data solely to power the AI assistant's chat-based responses. This data is NOT stored on SellyGUIDE servers — it is retrieved in real-time and passed directly to the merchant's connected AI provider to generate answers.

Google Ads data accessed (scope: adwords):

  • Campaign names, status, and structure
  • Ad spend, impressions, clicks, and conversion metrics
  • Account-level performance summaries

Google Analytics data accessed (scope: analytics.readonly):

  • Website traffic and session data
  • Page-level performance metrics
  • User engagement and conversion metrics

How this data is used: Solely to answer the merchant's natural-language questions within the SellyGUIDE chat interface (e.g. "What's my ad spend this month?"). No dashboard is built from this data; it is consumed contextually by the AI to generate a direct response to the merchant's own question.

How this data is shared: This data is passed via MCP directly to the merchant's own chosen AI provider (Anthropic/Claude, OpenAI/ChatGPT, or Google/Gemini) for the sole purpose of generating the merchant's response. It is not shared with, sold to, or transferred to any other third party. It is not used for advertising or profiling.

How this data is protected: All data in transit is encrypted via TLS/HTTPS. Google OAuth access and refresh tokens are stored encrypted on our backend, are never logged, and are never shared with any third party. Access is scoped to the minimum permissions required (read-only for Analytics).

Retention & deletion: Google user data is not persisted on SellyGUIDE servers; it exists only transiently during the API request/response cycle. OAuth tokens are deleted immediately when the merchant disconnects the integration or closes their account.

Revoking access: Merchants can disconnect Google Ads or GA4 at any time from the Settings page, or revoke SellyGUIDE's access directly at myaccount.google.com/permissions.

Limited Use disclosure: SellyGUIDE's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not used to develop, improve, or train generalized AI/ML models.

3.4 Data Stored on VDS Backend

The following data is stored encrypted on our VDS backend:

  • Your AI API key (never logged under any circumstances)
  • Subscription plan record
  • Skills router configuration

No store, advertising, or customer data is stored on our backend.

3.5 Technical & Usage Data

  • Platform interactions and feature usage
  • IP address and browser type for security and error logging
  • Automated logs generated during app operation

4. AI API Key and Data Flow

4.1 Bring Your Own AI (BYOAI)

SellyGUIDE is built on an architecture where users connect their own AI provider account (Anthropic/Claude, OpenAI/ChatGPT, or Google/Gemini):

  • Your API key is stored encrypted, never logged, and never shared with any third party.
  • Token costs are billed directly to your AI provider — we are entirely outside that payment flow.
  • Store and tool data is not stored on SellyGUIDE backend servers — it flows to your AI provider via MCP.
  • Skills files are e-commerce instructions containing no store-specific data; they are sent as system prompts to your AI provider.
  • Your AI provider's own privacy policy applies to data received on their end.

4.2 MCP Integration Connections

For MCP connections with Meta Ads, Google Ads, Klaviyo, Google Analytics, Gmail, Stripe, ShipStation, and others:

  • Every connection is established only with your explicit consent.
  • Data from connected tools is not stored on SellyGUIDE servers.
  • You can disconnect any integration at any time from the Settings page.

5. How We Use Data

  • To detect anomalies in sales, inventory, and product performance
  • To perform root cause analysis and generate prioritized action recommendations
  • To provide real-time low-stock and stockout alerts
  • To maintain and improve the SellyGUIDE platform
  • To provide customer support and meet legal obligations

✓ What we do NOT do: We do not use your store data for advertising, profiling, selling to other users, or any purpose beyond what is described above.

6. Storage & Security

  • All communication uses TLS/HTTPS encryption.
  • Our VDS backend runs on our own infrastructure — no third-party cloud storage is used.
  • Shopify connection is established securely via OAuth 2.0.
  • AI API keys are encrypted, never logged, never shared.
  • Session tokens (JWT) are used for authentication; no third-party cookies are used.
  • Test and production environments are strictly separated.

7. Data Sharing

  • We do not sell, rent, or trade your personal or store data to third parties.
  • AI model inference: your store and tool data flows via MCP directly to your chosen AI provider, bypassing SellyGUIDE servers entirely.
  • We may disclose data if required by law or to comply with a valid legal process.

8. Data Retention

  • Account information and subscription records are retained while your account is active.
  • Upon uninstallation or account closure, this data is permanently deleted within 30 days.
  • To request immediate deletion: contact@sellyguide.com
  • Anonymized, aggregated platform data may be retained longer but cannot be linked back to your store.

9. Your Rights

Under KVKK (Turkey) — Article 11

  • Right to learn whether your personal data is being processed
  • Right to request information if it is being processed
  • Right to know the purpose of processing and whether it is used accordingly
  • Right to know third parties to whom data is transferred domestically or abroad
  • Right to request correction of incomplete or inaccurate data
  • Right to request deletion or destruction under Article 7
  • Right to object to results arising from automated processing
  • Right to claim compensation for damages resulting from unlawful processing

Under GDPR (EU / UK)

  • Access — request a copy of data we hold
  • Rectification — request correction of inaccurate data
  • Erasure — 'right to be forgotten'
  • Restriction of processing
  • Data portability
  • Right to object
  • Right not to be subject to solely automated decision-making

To exercise any of these rights: contact@sellyguide.com — We respond within 30 days.

10. KVKK & GDPR Compliance

Shopify Mandatory Privacy Webhooks

WebhookPurpose
customers/redactProcesses customer data deletion requests from merchants.
shop/redactDeletes all store data within 48 hours after app uninstallation.
customers/data_requestProcesses customer data access requests submitted by merchants.
  • Privacy by Design: data minimization, purpose limitation, and security by default.
  • Data Protection Impact Assessments (DPIAs) are conducted for high-risk processing activities.
  • Data Processing Agreements (DPAs) are maintained with all sub-processors.
  • For cross-border transfers under Article 9 of the KVKK, Standard Contractual Clauses are used, and the legal notification is submitted within 5 business days.

11. Cookies & Session Tokens

  • JWT session tokens are used for authentication; no third-party cookies are used.
  • The app functions correctly in browsers with third-party cookie restrictions, including incognito mode.
  • Session tokens expire after one minute and are automatically renewed via Shopify App Bridge.
  • No tracking cookies or advertising pixels are used within the application.

12. Contact

We reserve the right to update this Privacy Policy at any time. Changes will be posted on this page with an updated date. Continued use after changes constitutes acceptance of the updated policy.