[ Legal / Privacy Policy ]

Last updated: August 4, 2026

Privacy Policy

This policy describes how Klyrox collects, uses, and protects personal information in connection with klyrox.ai, our Shopify apps, and our business communications.

1. Introduction

This Privacy Policy explains how Klyrox (“Klyrox,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you visit klyrox.ai (the “Site”), install or use our Shopify apps (the “Apps”), contact us, or otherwise interact with our online presence.

Klyrox is an AI product studio. We design and build AI agents, automation systems, Shopify applications, SaaS platforms, mobile apps, and related digital products for clients. This Policy covers information processed in connection with our marketing website, our Shopify apps, and general business inquiries. Client engagements may also be governed by a separate agreement, statement of work, or data processing addendum.

By using the Site or our Apps, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Site or Apps.

2. Who We Are

Klyrox operates the Site at https://klyrox.ai. For privacy-related questions or requests, contact us at hello@klyrox.ai.

If you engage us for a project, the contracting entity named in your agreement is the controller (or processor, as applicable) for project-related personal data, unless that agreement says otherwise.

3. Scope of This Policy

This Policy applies to:

  • Visitors to our Site and related pages (including blog, case studies, and legal pages)
  • Merchants who install, authorize, or use our Shopify apps, and their store staff users
  • Shoppers and other individuals whose data may be processed through a merchant’s Shopify store when an App is installed (as described in Section 9)
  • People who contact us by email or through inquiry flows on the Site
  • Prospective clients, partners, vendors, and applicants who communicate with us

This Policy does not cover Shopify’s own platform practices, or third-party websites, apps, or services that we do not control, even if they are linked from the Site or used alongside our Apps. Their privacy practices are governed by their own policies (including Shopify’s Privacy Policy and the merchant’s store privacy policy).

4. Information We Collect

We collect information in the following categories.

4.1 Information you provide to us

When you reach out about a project, partnership, career opportunity, or support request, you may provide:

  • Name, company name, and role
  • Email address and other contact details
  • Project descriptions, requirements, files, or other content you choose to share
  • Any other information you include in your message

Our primary contact channel is email. If you start an inquiry on the Site, your message may be opened in your email client and sent to us; in that case, the content of the message is provided by you when you send the email.

4.2 Information collected automatically

When you visit the Site, our hosting provider and standard web infrastructure may automatically collect technical information such as:

  • IP address and approximate location derived from IP
  • Browser type and version, device type, and operating system
  • Referring URL, pages viewed, and timestamps
  • Diagnostic logs needed to operate, secure, and troubleshoot the Site

This information is typically collected as part of normal server and content-delivery operation. We use it to keep the Site available, perform security monitoring, and understand aggregate traffic patterns.

4.3 Information stored on your device

The Site may store limited data in your browser to remember preferences and improve experience, for example:

  • Sound preference (whether site audio is enabled)
  • Session flags used for UI state (such as whether an intro sequence has already played)

These values are stored locally on your device (for example in localStorage or sessionStorage). They are not used to identify you across unrelated websites, and you can clear them at any time through your browser settings.

4.4 Client and project information

If you become a client, we may process additional personal data needed to deliver services—such as stakeholder contacts, account credentials you provide, workspace content, analytics configuration, or end-user data inside systems we build or operate for you. That processing is defined by your contract and any applicable data processing terms. Where we act as a processor on your behalf, you remain responsible for having a lawful basis to collect and share that data with us.

5. How We Use Information

We use personal information to:

  • Operate, maintain, secure, and improve the Site
  • Respond to inquiries and communicate about potential or ongoing work
  • Prepare proposals, statements of work, and project delivery plans
  • Provide, support, and improve our products and professional services
  • Send administrative messages related to projects, billing, or security
  • Comply with legal obligations and enforce our agreements
  • Protect against fraud, abuse, and security threats
  • Analyze aggregated, de-identified usage trends where feasible

We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

7. How We Share Information

We may share personal information with:

  • Service providers who help us host the Site, send email, store files, manage projects, process payments, or provide security and analytics tooling—under contractual confidentiality and data-protection obligations
  • Professional advisors such as lawyers, accountants, and insurers when needed
  • Authorities or other parties when required by law, legal process, or to protect rights, safety, and security
  • A buyer or successor in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections

We do not sell personal information to data brokers or third parties for their independent marketing use.

For client projects, we may share information with subprocessors needed to deliver the engagement (for example cloud infrastructure, model providers, or messaging platforms you ask us to integrate). Those parties are selected based on project requirements and contractual terms.

8. Artificial Intelligence and Automation

As an AI product studio, we may use AI systems—including third-party model providers—to assist with research, drafting, coding, support, and product features. When we do:

  • We aim to share only the information reasonably needed for the task
  • We instruct providers according to our contracts and applicable privacy requirements where feasible
  • Client confidential information is handled under the confidentiality and data terms of the relevant engagement

If a product we build for you uses AI to process end-user or customer data, the privacy notices and settings for that product are defined with you as part of the engagement and should be communicated to those end users by the appropriate controller. For Shopify apps specifically, see Section 9.

9. Shopify App Privacy

This section applies to Shopify apps developed, published, or operated by Klyrox (including apps listed on the Shopify App Store and custom/private apps we provide to merchants). It is intended to meet Shopify’s app privacy requirements and to explain how store and customer data is handled when a merchant installs and uses an App.

9.1 Roles and responsibilities

When a merchant installs an App on their Shopify store:

  • The merchant (store owner) is generally the controller of store, customer, and order data
  • Klyrox acts as a service provider / processor for data accessed through the App to provide the App’s features
  • Shopify provides the underlying commerce platform and API access under Shopify’s terms and policies

Merchants are responsible for providing appropriate privacy notices to their customers and for ensuring they have a lawful basis to collect and process customer data, including authorizing Apps to access that data.

9.2 Information our Shopify apps may access or collect

Depending on the App’s features and the permissions (scopes) a merchant approves during installation, an App may access or process:

  • Shop information — store name, domain, Shopify shop ID, plan details, timezone, currency, and locale
  • Merchant / staff account information — name, email, and role of users who install or administer the App
  • Customer information — such as name, email, phone, shipping/billing addresses, and other customer profile fields available via Shopify APIs when required for App functionality
  • Order and checkout data — order IDs, line items, fulfillment status, shipping details, refunds, and related commerce events
  • Product and inventory data — products, variants, collections, inventory levels, and catalog metadata
  • Themes, storefront, or checkout configuration data needed to enable App features (where scoped)
  • Usage and diagnostics — App installation status, feature usage events, error logs, and performance metrics needed to operate and support the App
  • Authentication tokens — OAuth access tokens or session credentials required to call Shopify APIs on the merchant’s behalf

We only request Shopify API scopes that are reasonably necessary for the App’s stated functionality. We do not intentionally collect payment card numbers through our Apps; payment processing is handled by Shopify and the merchant’s payment providers.

Exact data access for each App is also disclosed in the App’s Shopify App Store listing (where applicable) and during the install authorization screen.

9.3 How we use Shopify app data

We use App-related information solely to:

  • Provide, operate, maintain, and improve the App’s features (for example order routing, inventory sync, recommendations, automation, analytics, or AI-assisted commerce tools)
  • Authenticate the merchant store and maintain a secure connection to Shopify
  • Sync and process store data according to merchant configuration
  • Provide customer support, troubleshoot issues, and communicate service notices to merchants
  • Monitor reliability, prevent abuse, and secure the App
  • Comply with Shopify platform requirements, legal obligations, and valid data requests

We do not sell Shopify merchant or customer personal data. We do not use customer personal data from a merchant’s store for independent advertising, data brokering, or to contact those customers for our own marketing.

Where an App uses AI or machine-learning features, store or customer data may be processed to generate recommendations, classifications, or automations for that merchant’s store. We do not use merchant customer personal data to train public foundation models for unrelated third parties unless the merchant has expressly agreed otherwise in writing.

9.4 Sharing of Shopify app data

App data may be shared only as needed to provide the service:

  • With Shopify, as required to authenticate, read, or write store data through Shopify’s APIs and webhooks
  • With infrastructure and subprocessors (for example cloud hosting, databases, logging, email, or AI model providers) bound by confidentiality and data-protection obligations
  • With the merchant’s authorized staff and systems the merchant connects to the App
  • With professional advisors or authorities when required by law or to protect rights and security

We do not disclose Shopify store customer personal data to unaffiliated third parties for their own marketing purposes.

9.5 Storage, security, and retention

Shopify app data is stored on secured systems with access limited to personnel who need it to build, operate, or support the App. We apply measures such as encryption in transit (HTTPS/TLS), credential protection for API tokens, access controls, and monitoring appropriate to the sensitivity of the data.

We retain App data only for as long as needed to provide the App, comply with Shopify requirements, resolve disputes, and meet legal obligations. After a merchant uninstalls an App, or when Shopify sends a mandatory deletion webhook, we delete or anonymize related personal data in accordance with Section 9.6, except where retention is required by law or for legitimate security/audit records that no longer identify individuals where feasible.

9.6 Uninstall, deletion, and Shopify mandatory webhooks

Merchants can uninstall an App at any time from their Shopify admin. After uninstall, the App loses ongoing API access to the store (subject to Shopify platform behavior).

We comply with Shopify’s mandatory privacy webhooks for apps that process customer personal data, including:

  • customers/data_request — when a merchant or customer requests a copy of customer personal data held by the App
  • customers/redact — when customer personal data must be erased from the App
  • shop/redact — when store data must be erased after App uninstall (typically after Shopify’s required waiting period)

Merchants or customers may also contact us at hello@klyrox.ai with the subject line “Shopify Privacy Request,” including the shop domain and details of the request. Shoppers should generally contact the merchant first, because the merchant is the store’s primary controller; we will assist merchants in fulfilling requests that relate to data held in our Apps.

9.7 Merchant responsibilities

By installing or using an App, the merchant agrees that they:

  • Have the right to authorize the App to access their Shopify store data
  • Will configure the App in a manner consistent with applicable privacy and consumer laws
  • Are responsible for their storefront privacy policy and customer disclosures
  • Will not use the App to process data in ways that violate Shopify’s terms, applicable law, or this Policy

9.8 Custom Shopify apps and client projects

For custom or private Shopify apps built under a client agreement, additional privacy, security, and data-processing terms in that agreement control if there is a conflict with this Policy. Unless otherwise agreed, we still apply the same core principles: purpose limitation, no sale of personal data, secure handling, and deletion upon request or project end as specified in the contract.

10. Cookies and Similar Technologies

The Site may use cookies, local storage, session storage, or similar technologies to:

  • Remember interface preferences
  • Maintain basic session or visit state
  • Support security and performance of hosted content

You can control cookies and site data through your browser settings. Blocking some storage may affect certain Site features (for example remembered audio preferences).

If we introduce additional analytics or advertising cookies in the future, we will update this Policy and, where required, provide notice or obtain consent.

Shopify apps may also set cookies or similar technologies in the merchant admin or on storefronts where the App injects functionality. Those technologies are limited to operating the App’s features and remembering merchant configuration where needed.

11. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, including to:

  • Respond to and follow up on inquiries
  • Deliver and support client engagements and Shopify apps
  • Meet legal, accounting, tax, and dispute-resolution requirements
  • Maintain security logs for a reasonable period
  • Comply with Shopify uninstall and redaction timelines

Retention periods vary by data type and context. Inquiry emails are typically kept for as long as useful for business follow-up and recordkeeping, then deleted or archived according to our internal practices. Client project data is retained per the governing agreement and applicable law. Shopify app data is retained as described in Section 9. Browser-stored preferences remain until you clear them or they expire.

12. Security

We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, or alteration. These may include encryption in transit (HTTPS), access controls, least-privilege practices, secure handling of Shopify API credentials, and vendor due diligence.

No method of transmission or storage is completely secure. If you believe your interaction with us has been compromised, contact us immediately at hello@klyrox.ai.

13. International Transfers

We may process and store information in countries other than where you live, including places that may have different data-protection laws. When we transfer personal data internationally, we take steps designed to provide an appropriate level of protection, such as contractual safeguards with vendors, where required.

14. Your Rights and Choices

Depending on your location, you may have rights to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information
  • Object to or restrict certain processing
  • Request portability of information you provided to us
  • Withdraw consent where processing is based on consent
  • Lodge a complaint with a supervisory authority

To exercise these rights, email hello@klyrox.ai with the subject line “Privacy Request” and enough detail for us to verify and fulfill your request. We may need to confirm your identity before acting. For Shopify store customer requests related to an App, include the shop domain and use “Shopify Privacy Request” where possible.

California residents: We do not sell or share personal information as those terms are commonly defined under the CCPA/CPRA. You may still contact us to request access or deletion of personal information we hold about you in connection with the Site, our Apps, or your communications with us.

You can also unsubscribe from optional marketing emails by using the unsubscribe link in those messages or by contacting us. Transactional, project-related, or App service messages may still be sent when necessary.

15. Children’s Privacy

The Site, Apps, and our services are directed to businesses and professionals. We do not knowingly collect personal information from children under 16 (or the age required by local law). If you believe a child has provided us personal information, contact us and we will take appropriate steps to delete it.

16. Third-Party Links and Integrations

The Site may link to third-party sites, social platforms, documentation, or demos. Our Apps also depend on Shopify and may integrate with other services a merchant connects. If you follow those links or use third-party services, their privacy policies apply. We are not responsible for the content or practices of third parties we do not control.

17. Changes to This Policy

We may update this Privacy Policy from time to time. The “Last updated” date at the top of this page reflects the latest revision. Material changes will be posted on this page. Continued use of the Site or Apps after an update means you acknowledge the revised Policy.

18. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy, our Site, or our Shopify apps, contact:

  • Klyrox
  • Email: hello@klyrox.ai

We aim to respond to privacy requests within a reasonable period, and within any timeframe required by applicable law or Shopify platform rules.