PositionBird
Privacy policy
PositionBird measures how often AI answer engines mention and cite your store. This policy explains what data the app collects from your Shopify store, how it is used, who it is shared with, and how it is deleted.
Data we collect
- Store details: your myshopify.com domain, brand name, and any brand aliases you enter during onboarding.
- Web accounts (sign-up without Shopify): the email address and password you sign up with (the password is stored only as a salted scrypt hash), your website URL, and the same configuration and scan data described here. To suggest prompts we read the public product pages, sitemap, and structured data of the site you gave us; we never log in to it. If you subscribe to a paid plan, card details go directly to Stripe, our payment processor, and never touch our servers; we keep only Stripe's customer and subscription identifiers.
- Product catalog basics: titles, product types, and tags of your products (read via the Shopify Admin API with the
read_productsscope), used only to suggest buyer-intent prompts. - App configuration: your tracked prompts, competitors, scan settings, and plan.
- Scan results: the answers AI engines return for your prompts, including whether your store and competitors were mentioned or cited.
- Anonymous AI-referral counts (optional): if you enable AI traffic tracking, we record that a storefront visit arrived from an AI engine (source and page path only). We store no IP addresses, cookies, or any information about the visitor.
- Order totals and products (optional, RevenueBird): the same web pixel reports each completed checkout to us so we can build your revenue ledger: the order total, subtotal, currency, the products and quantities bought, the checkout token or order number (used only to avoid counting an order twice), and, when the buyer first arrived from an AI engine within the last seven days, which engine. We never receive or store the buyer's name, email address, phone number, addresses, payment details, or IP address. The pixel runs only with the visitor's analytics consent where consent is required.
- Search Console data (optional): if you connect Google Search Console, we read aggregate performance data (clicks, impressions, positions, queries) for your site. You can disconnect at any time in Settings.
Free scan and launch waitlist
When you run a free scan on our marketing site (the AI shopping scan or the AI accuracy scan) and choose to receive your full results, we store the email address you provide together with the details of that scan: the brand name and website you entered, which engines mentioned or omitted your store, and the per-prompt results. We also store the exact consent wording you agreed to and the time you agreed. We use your address only to send your results and, where you opted in, to send you occasional product updates about PositionBird. We never sell this data or share it with advertisers, every email includes an unsubscribe link, and you can ask us to delete your entry at any time using the contact details below.
Data we do not collect
PositionBird does not read, store, or process your customers' personal information. We do not request access to your orders, customer records, or payment information through the Shopify API; the only checkout information we receive is the anonymous order summary described above, sent by our web pixel. Billing for the app itself is handled entirely by Shopify.
Cookies on our marketing website
The public pages of positionbird.io use Google Ads conversion measurement (the Google tag) to understand whether our advertising works, for example whether a visitor who clicked one of our ads continued to the Shopify App Store. This may set Google advertising cookies in your browser. For visitors in the European Economic Area, the United Kingdom, and Switzerland, these cookies default to denied. No advertising or analytics tags load inside the PositionBird app itself, and no merchant or customer data from the app is ever shared with advertising services. See the Google Privacy Policy for how Google processes this data.
Sharing with third-party AI engines
To measure your visibility, PositionBird sends your tracked prompts (for example, "best soy candles for sleep") to the AI engines you enable (Perplexity, OpenAI, Google Gemini, and Anthropic) and records their answers. Prompts describe shopping questions; they never contain customer data. Each engine processes these requests under its own terms and privacy policy.
Data retention and deletion
- When you uninstall PositionBird, your login sessions are deleted immediately.
- 48 hours after uninstall, Shopify sends us a deletion request and we erase all remaining data for your store: profile, prompts, competitors, scan history, and recommendations.
- We honor Shopify's mandatory privacy webhooks (customer data requests, customer redaction, and shop redaction). Because we hold no customer-level data, customer requests have nothing to return or redact.
- Web accounts have no uninstall step, so deletion is in your hands: open Account in the app and choose “Delete my account”. That cancels any Stripe subscription, ends your session, and immediately erases your account, site profile, prompts, competitors, scan history, evidence, and recommendations. Until you do, we keep the data so your trend lines stay intact.
Free scan and waitlist data. We keep free scan entries and waitlist emails for up to 24 months from your most recent scan or interaction with us, after which they are deleted automatically. If you unsubscribe or ask us to delete your data, we remove your email, scan results, and consent record within 30 days. You can withdraw consent at any time using the unsubscribe link in any email we send, or by contacting us at support@positionbird.io.
Service providers
We host the app and its database on Render (render.com), a cloud infrastructure provider; your data is stored in Render-managed PostgreSQL and processed only to operate the service. Card payments for web accounts are processed by Stripe (stripe.com) under its own privacy policy. We do not sell your data, use it to train AI models, or share it with anyone beyond the AI engines described above, our hosting provider, and our payment processor.
Security
All traffic between your browser, Shopify, and PositionBird is encrypted with TLS. Access to your store's data is authorized through Shopify's OAuth and session tokens; we never see or store your Shopify password.
Changes to this policy
If we make material changes, we will update this page and the "last updated" date below. Continued use of the app after changes take effect constitutes acceptance.
Contact
Questions or data requests: support@positionbird.io.
This policy was last updated on August 10, 2026.