PositionBirdPrivacy policy
PositionBird measures how often AI answer engines mention and cite your store. This policy explains what data the app collects from your Shopify store, how it is used, who it is shared with, and how it is deleted.
Data we collect
- Store details: your myshopify.com domain, brand name, and any brand aliases you enter during onboarding.
- Product catalog basics: titles, product types, and tags of your products (read via the Shopify Admin API with the
read_productsscope), used only to suggest buyer-intent prompts. - App configuration: your tracked prompts, competitors, scan settings, and plan.
- Scan results: the answers AI engines return for your prompts, including whether your store and competitors were mentioned or cited.
Data we do not collect
PositionBird does not read, store, or process your customers' personal information. We do not access orders, customer records, checkout data, or payment information. Billing for the app itself is handled entirely by Shopify.
Sharing with third-party AI engines
To measure your visibility, PositionBird sends your tracked prompts (for example, "best soy candles for sleep") to the AI engines you enable — Perplexity, OpenAI, Google Gemini, and Anthropic — and records their answers. Prompts describe shopping questions; they never contain customer data. Each engine processes these requests under its own terms and privacy policy.
Data retention and deletion
- When you uninstall PositionBird, your login sessions are deleted immediately.
- 48 hours after uninstall, Shopify sends us a deletion request and we erase all remaining data for your store — profile, prompts, competitors, scan history, and recommendations.
- We honor Shopify's mandatory privacy webhooks (customer data requests, customer redaction, and shop redaction). Because we hold no customer-level data, customer requests have nothing to return or redact.
Service providers
We host the app and its database on Render (render.com), a cloud infrastructure provider; your data is stored in Render-managed PostgreSQL and processed only to operate the service. We do not sell your data, use it to train AI models, or share it with anyone beyond the AI engines described above and our hosting provider.
Security
All traffic between your browser, Shopify, and PositionBird is encrypted with TLS. Access to your store's data is authorized through Shopify's OAuth and session tokens; we never see or store your Shopify password.
Changes to this policy
If we make material changes, we will update this page and the "last updated" date below. Continued use of the app after changes take effect constitutes acceptance.
Contact
Questions or data requests: support@positionbird.io.
This policy was last updated on August 10, 2026.