Privacy Policy
Last updated: July 30, 2026 · Effective for corepilotai.corewital.com
CorePilot AI (“we”, “us”, “our”), operated by CoreWital, provides a Shopify embedded app that scans and helps optimize store catalogs. This Privacy Policy explains what data we process and why.
1. Who this applies to
Merchants and staff who install or use CorePilot AI on a Shopify store, and visitors to our public website.
2. Data we collect
- Shopify store data — shop domain, plan, product / collection / image metadata, SEO fields, inventory flags, and related Admin API data needed for scans and fixes (scopes granted at install).
- Session & auth — Shopify session tokens and offline access tokens (stored securely) so the app can run scans and apply approved fixes.
- Usage & ops logs — scan results, fix queue status, API call logs, webhook receipts, and error messages for reliability.
- Admin Core accounts — email, name, and role for invited internal operators of our back office (separate from Shopify merchant login).
- Support — messages and contact details you send via support tickets or email.
- Billing — subscription status and plan via Shopify Billing API (we do not store full payment card numbers).
3. How we use data
- Provide store health scans, AI-assisted copy/SEO/alt text, and image optimization.
- Apply merchant-approved fixes to the Shopify store.
- Enforce plan limits, billing, and module access.
- Operate background jobs (scans, reports) and improve reliability.
- Respond to support requests and security incidents.
We do not sell merchant store data. We do not use store content to train public AI models for unrelated products.
4. AI processing
When you use AI Fix or the assistant, relevant product/collection text may be sent to configured AI providers (for example Google Gemini or other keys you enable in Admin) to generate suggestions. Providers process that content under their own terms. Image pixel processing for optimization is done with our image tooling (sharp), not generative image AI.
5. Sharing
We share data only as needed with:
- Shopify (platform APIs and billing).
- Hosting/database providers (e.g. Vercel, Turso) that process data on our behalf.
- AI providers when you trigger AI features.
- Legal authorities when required by law.
6. Retention & deletion
We keep store-linked data while the app is installed. After uninstall or a Shopify GDPR/redact webhook, we delete or anonymize merchant data according to Shopify’s data protection requirements. Soft-deleted records may be purged on a schedule.
7. Security
Access tokens and secrets are stored server-side. Admin Core uses a separate cookie session. We use HTTPS and restrict production database access to our live environment.
8. Your choices
- Uninstall the app from Shopify Admin to stop processing.
- Request access or deletion by contacting us (below).
- Disable AI or modules where settings allow.
9. Children
CorePilot AI is for business use and is not directed at children.
10. Changes
We may update this policy. The “Last updated” date above will change; continued use after updates means you accept the revised policy.
11. Contact
Questions about privacy or data requests:
Email: corewital@gmail.com
Website: https://corepilotai.corewital.com
