[ Legal / Privacy Policy ]
Last updated: August 4, 2026
Privacy Policy
This policy describes how Klyrox collects, uses, and protects personal information in connection with klyrox.ai, our Shopify apps, and our business communications.
1. Introduction
This Privacy Policy explains how Klyrox (“Klyrox,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit klyrox.ai (the “Site”), install or use our Shopify apps (the “Apps”), contact us, or otherwise interact with our online presence.
Klyrox is an AI product studio. We design and build AI agents, automation systems, Shopify applications, SaaS platforms, mobile apps, and related digital products for clients. This Policy covers information processed in connection with our marketing website, our Shopify apps, and general business inquiries. Client engagements may also be governed by a separate agreement, statement of work, or data processing addendum.
By using the Site or our Apps, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Site or Apps.
2. Who We Are
Klyrox operates the Site at https://klyrox.ai. For privacy-related questions or requests, contact us at hello@klyrox.ai.
If you engage us for a project, the contracting entity named in your agreement is the controller (or processor, as applicable) for project-related personal data, unless that agreement says otherwise.
3. Scope of This Policy
This Policy applies to:
- Visitors to our Site and related pages (including blog, case studies, and legal pages)
- Merchants who install, authorize, or use our Shopify apps, and their store staff users
- Shoppers and other individuals whose data may be processed through a merchant’s Shopify store when an App is installed (as described in Section 9)
- People who contact us by email or through inquiry flows on the Site
- Prospective clients, partners, vendors, and applicants who communicate with us
This Policy does not cover Shopify’s own platform practices, or third-party websites, apps, or services that we do not control, even if they are linked from the Site or used alongside our Apps. Their privacy practices are governed by their own policies (including Shopify’s Privacy Policy and the merchant’s store privacy policy).
4. Information We Collect
We collect information in the following categories.
4.1 Information you provide to us
When you reach out about a project, partnership, career opportunity, or support request, you may provide:
- Name, company name, and role
- Email address and other contact details
- Project descriptions, requirements, files, or other content you choose to share
- Any other information you include in your message
Our primary contact channel is email. If you start an inquiry on the Site, your message may be opened in your email client and sent to us; in that case, the content of the message is provided by you when you send the email.
4.2 Information collected automatically
When you visit the Site, our hosting provider and standard web infrastructure may automatically collect technical information such as:
- IP address and approximate location derived from IP
- Browser type and version, device type, and operating system
- Referring URL, pages viewed, and timestamps
- Diagnostic logs needed to operate, secure, and troubleshoot the Site
This information is typically collected as part of normal server and content-delivery operation. We use it to keep the Site available, perform security monitoring, and understand aggregate traffic patterns.
4.3 Information stored on your device
The Site may store limited data in your browser to remember preferences and improve experience, for example:
- Sound preference (whether site audio is enabled)
- Session flags used for UI state (such as whether an intro sequence has already played)
These values are stored locally on your device (for example in localStorage or sessionStorage). They are not used to identify you across unrelated websites, and you can clear them at any time through your browser settings.
4.4 Client and project information
If you become a client, we may process additional personal data needed to deliver services—such as stakeholder contacts, account credentials you provide, workspace content, analytics configuration, or end-user data inside systems we build or operate for you. That processing is defined by your contract and any applicable data processing terms. Where we act as a processor on your behalf, you remain responsible for having a lawful basis to collect and share that data with us.
5. How We Use Information
We use personal information to:
- Operate, maintain, secure, and improve the Site
- Respond to inquiries and communicate about potential or ongoing work
- Prepare proposals, statements of work, and project delivery plans
- Provide, support, and improve our products and professional services
- Send administrative messages related to projects, billing, or security
- Comply with legal obligations and enforce our agreements
- Protect against fraud, abuse, and security threats
- Analyze aggregated, de-identified usage trends where feasible
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
6. Legal Bases for Processing (EEA/UK)
If you are in the European Economic Area or the United Kingdom, we process personal data under one or more of these legal bases:
- Contract — to take steps at your request before entering a contract, or to perform a contract with you
- Legitimate interests — to operate our business and Site, respond to inquiries, secure systems, and improve services, where those interests are not overridden by your rights
- Consent — where you have given clear consent (for example, for optional communications), which you may withdraw at any time
- Legal obligation — where processing is required to comply with applicable law
8. Artificial Intelligence and Automation
As an AI product studio, we may use AI systems—including third-party model providers—to assist with research, drafting, coding, support, and product features. When we do:
- We aim to share only the information reasonably needed for the task
- We instruct providers according to our contracts and applicable privacy requirements where feasible
- Client confidential information is handled under the confidentiality and data terms of the relevant engagement
If a product we build for you uses AI to process end-user or customer data, the privacy notices and settings for that product are defined with you as part of the engagement and should be communicated to those end users by the appropriate controller. For Shopify apps specifically, see Section 9.
9. Shopify App Privacy
This section applies to Shopify apps developed, published, or operated by Klyrox (including apps listed on the Shopify App Store and custom/private apps we provide to merchants). It is intended to meet Shopify’s app privacy requirements and to explain how store and customer data is handled when a merchant installs and uses an App.
9.1 Roles and responsibilities
When a merchant installs an App on their Shopify store:
- The merchant (store owner) is generally the controller of store, customer, and order data
- Klyrox acts as a service provider / processor for data accessed through the App to provide the App’s features
- Shopify provides the underlying commerce platform and API access under Shopify’s terms and policies
Merchants are responsible for providing appropriate privacy notices to their customers and for ensuring they have a lawful basis to collect and process customer data, including authorizing Apps to access that data.
9.2 Information our Shopify apps may access or collect
Depending on the App’s features and the permissions (scopes) a merchant approves during installation, an App may access or process:
- Shop information — store name, domain, Shopify shop ID, plan details, timezone, currency, and locale
- Merchant / staff account information — name, email, and role of users who install or administer the App
- Customer information — such as name, email, phone, shipping/billing addresses, and other customer profile fields available via Shopify APIs when required for App functionality
- Order and checkout data — order IDs, line items, fulfillment status, shipping details, refunds, and related commerce events
- Product and inventory data — products, variants, collections, inventory levels, and catalog metadata
- Themes, storefront, or checkout configuration data needed to enable App features (where scoped)
- Usage and diagnostics — App installation status, feature usage events, error logs, and performance metrics needed to operate and support the App
- Authentication tokens — OAuth access tokens or session credentials required to call Shopify APIs on the merchant’s behalf
We only request Shopify API scopes that are reasonably necessary for the App’s stated functionality. We do not intentionally collect payment card numbers through our Apps; payment processing is handled by Shopify and the merchant’s payment providers.
Exact data access for each App is also disclosed in the App’s Shopify App Store listing (where applicable) and during the install authorization screen.
9.3 How we use Shopify app data
We use App-related information solely to:
- Provide, operate, maintain, and improve the App’s features (for example order routing, inventory sync, recommendations, automation, analytics, or AI-assisted commerce tools)
- Authenticate the merchant store and maintain a secure connection to Shopify
- Sync and process store data according to merchant configuration
- Provide customer support, troubleshoot issues, and communicate service notices to merchants
- Monitor reliability, prevent abuse, and secure the App
- Comply with Shopify platform requirements, legal obligations, and valid data requests
We do not sell Shopify merchant or customer personal data. We do not use customer personal data from a merchant’s store for independent advertising, data brokering, or to contact those customers for our own marketing.
Where an App uses AI or machine-learning features, store or customer data may be processed to generate recommendations, classifications, or automations for that merchant’s store. We do not use merchant customer personal data to train public foundation models for unrelated third parties unless the merchant has expressly agreed otherwise in writing.
9.4 Sharing of Shopify app data
App data may be shared only as needed to provide the service:
- With Shopify, as required to authenticate, read, or write store data through Shopify’s APIs and webhooks
- With infrastructure and subprocessors (for example cloud hosting, databases, logging, email, or AI model providers) bound by confidentiality and data-protection obligations
- With the merchant’s authorized staff and systems the merchant connects to the App
- With professional advisors or authorities when required by law or to protect rights and security
We do not disclose Shopify store customer personal data to unaffiliated third parties for their own marketing purposes.
9.5 Storage, security, and retention
Shopify app data is stored on secured systems with access limited to personnel who need it to build, operate, or support the App. We apply measures such as encryption in transit (HTTPS/TLS), credential protection for API tokens, access controls, and monitoring appropriate to the sensitivity of the data.
We retain App data only for as long as needed to provide the App, comply with Shopify requirements, resolve disputes, and meet legal obligations. After a merchant uninstalls an App, or when Shopify sends a mandatory deletion webhook, we delete or anonymize related personal data in accordance with Section 9.6, except where retention is required by law or for legitimate security/audit records that no longer identify individuals where feasible.
9.6 Uninstall, deletion, and Shopify mandatory webhooks
Merchants can uninstall an App at any time from their Shopify admin. After uninstall, the App loses ongoing API access to the store (subject to Shopify platform behavior).
We comply with Shopify’s mandatory privacy webhooks for apps that process customer personal data, including:
- customers/data_request — when a merchant or customer requests a copy of customer personal data held by the App
- customers/redact — when customer personal data must be erased from the App
- shop/redact — when store data must be erased after App uninstall (typically after Shopify’s required waiting period)
Merchants or customers may also contact us at hello@klyrox.ai with the subject line “Shopify Privacy Request,” including the shop domain and details of the request. Shoppers should generally contact the merchant first, because the merchant is the store’s primary controller; we will assist merchants in fulfilling requests that relate to data held in our Apps.
9.7 Merchant responsibilities
By installing or using an App, the merchant agrees that they:
- Have the right to authorize the App to access their Shopify store data
- Will configure the App in a manner consistent with applicable privacy and consumer laws
- Are responsible for their storefront privacy policy and customer disclosures
- Will not use the App to process data in ways that violate Shopify’s terms, applicable law, or this Policy
9.8 Custom Shopify apps and client projects
For custom or private Shopify apps built under a client agreement, additional privacy, security, and data-processing terms in that agreement control if there is a conflict with this Policy. Unless otherwise agreed, we still apply the same core principles: purpose limitation, no sale of personal data, secure handling, and deletion upon request or project end as specified in the contract.
11. Data Retention
We retain personal information only as long as needed for the purposes described in this Policy, including to:
- Respond to and follow up on inquiries
- Deliver and support client engagements and Shopify apps
- Meet legal, accounting, tax, and dispute-resolution requirements
- Maintain security logs for a reasonable period
- Comply with Shopify uninstall and redaction timelines
Retention periods vary by data type and context. Inquiry emails are typically kept for as long as useful for business follow-up and recordkeeping, then deleted or archived according to our internal practices. Client project data is retained per the governing agreement and applicable law. Shopify app data is retained as described in Section 9. Browser-stored preferences remain until you clear them or they expire.
12. Security
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. These may include encryption in transit (HTTPS), access controls, least-privilege practices, secure handling of Shopify API credentials, and vendor due diligence.
No method of transmission or storage is completely secure. If you believe your interaction with us has been compromised, contact us immediately at hello@klyrox.ai.
13. International Transfers
We may process and store information in countries other than where you live, including places that may have different data-protection laws. When we transfer personal data internationally, we take steps designed to provide an appropriate level of protection, such as contractual safeguards with vendors, where required.
14. Your Rights and Choices
Depending on your location, you may have rights to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Object to or restrict certain processing
- Request portability of information you provided to us
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
To exercise these rights, email hello@klyrox.ai with the subject line “Privacy Request” and enough detail for us to verify and fulfill your request. We may need to confirm your identity before acting. For Shopify store customer requests related to an App, include the shop domain and use “Shopify Privacy Request” where possible.
California residents: We do not sell or share personal information as those terms are commonly defined under the CCPA/CPRA. You may still contact us to request access or deletion of personal information we hold about you in connection with the Site, our Apps, or your communications with us.
You can also unsubscribe from optional marketing emails by using the unsubscribe link in those messages or by contacting us. Transactional, project-related, or App service messages may still be sent when necessary.
15. Children’s Privacy
The Site, Apps, and our services are directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or the age required by local law). If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.
16. Third-Party Links and Integrations
The Site may link to third-party sites, social platforms, documentation, or demos. Our Apps also depend on Shopify and may integrate with other services a merchant connects. If you follow those links or use third-party services, their privacy policies apply. We are not responsible for the content or practices of third parties we do not control.
17. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be posted on this page. Continued use of the Site or Apps after an update means you acknowledge the revised Policy.
18. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, our Site, or our Shopify apps, contact:
- Klyrox
- Email: hello@klyrox.ai
We aim to respond to privacy requests within a reasonable period, and within any timeframe required by applicable law or Shopify platform rules.