Privacy Policy
Last updated: 19 July 2026
Who we are
OtoRank is a Shopify app built by otolab.ai. This policy explains what data OtoRank collects from your Shopify store, why, and how it's handled.
What OtoRank accesses
When you install OtoRank, Shopify grants it the following access, used only for the purposes below:
| read_products, write_products, read_product_listings | Reading your catalog to calculate AEO scores, and writing AI-generated descriptions, FAQs, and metafields back to your products after you review and approve them. |
| read_inventory | Factoring stock and variant completeness into the AEO score. |
| read_metaobjects | Reading store-level content (policies, brand info) used to enrich generated discovery files. |
| read_orders, read_all_orders | Detecting which orders were referred by an AI assistant, so we can show you AI-attributed revenue. We don't use order data for anything else. |
| read_customer_events | Powering the OtoRank web pixel, which detects AI-referred storefront sessions. This doesn't collect personal browsing history beyond attributing a session to an AI referrer. |
| write_content | Creating the URL redirect that points yourstore.com/llms.txt to your discovery file. |
| write_pixels | Installing the web pixel used for AI-traffic attribution. |
Data we store
- Shop information: your shop domain and API access token, used solely to make authorized requests back to your store on your behalf.
- Product content: product data needed to generate AI content, and the generated drafts themselves, stored until you approve or discard them.
- AI-referral analytics: session and order records showing which AI assistant referred a visit or sale, plus the resulting revenue, used only to power the analytics dashboard inside OtoRank.
- Billing records: your selected plan and credit usage, managed through Shopify's own billing system. OtoRank doesn't process payment details directly, that's handled entirely by Shopify.
AI processing
Generated content (product descriptions, FAQs, buyer guides) is produced using OpenAI's API. Product data sent for generation is used only to produce your draft content and is not used to train models on your behalf, beyond OpenAI's standard API data-handling terms. Every AI-generated draft is queued for your review before it's published to your store, nothing publishes without your approval.
Data retention and deletion
OtoRank implements Shopify's mandatory GDPR webhooks:
- customers/data_request: if a customer requests their data, we provide what we hold in response to Shopify's request.
- customers/redact: customer data is deleted from our systems on request.
- shop/redact: when you uninstall OtoRank, your shop's data (access tokens, generated content, analytics) is deleted from our systems within Shopify's required window. Discovery files written into your theme are also removed automatically on uninstall.
Contact
Questions about this policy or a data request: [email protected].