AgentCheck Privacy Policy
AgentCheck (“we”, “us”), operated by Wolfram Hedrich, is a Shopify app that runs a simulated AI shopping agent against a merchant’s store on a schedule and reports, in plain English, where an AI shopper struggled and what to fix. This policy explains what data the app accesses, how we use it, and how you can have it deleted. Your use of AgentCheck is also governed by our Terms of Service.
Information we access and store
- Store & account data. When you install AgentCheck, Shopify issues us an offline access token scoped to
read_products. We store your.myshopify.comdomain and that token so the app can read your catalog on your behalf. The token is read-only: it lets the app read your products and basic store settings, and nothing else. - Product catalog and store settings. To run its audits, the app reads your product catalog, the countries your store ships to and your store’s country through Shopify’s Admin API, and uses your storefront’s public AI shopping endpoint (the Universal Commerce Protocol) the way an AI shopper would. AgentCheck never creates, edits, or deletes your products. To test the buying flow it creates temporary carts on your storefront, which contain no customer details and are never turned into orders or payments. We store the results of each audit (the issues found and the product titles/IDs they reference), not a full copy of your catalog.
- Settings you provide. Your chosen monitoring cadence and, if you enable email alerts, the alert email address you enter.
- Waitlist sign-ups (our website). If you join the waitlist on our website, we store your email address, when you gave consent and which consent wording you agreed to, and whether you confirmed through the link we email you. You may also tell us your store’s web address — that field is optional, and we use it only to prepare your audit before opening day, from the same public store data an AI shopper can already see. We use all of this only to tell you when AgentCheck opens and to send occasional launch updates. Unconfirmed sign-ups are deleted after 7 days.
- Technical logs. Our servers keep short-lived technical logs (for example, which store an audit ran for and whether it succeeded) to operate and secure the service. They do not include your alert email address.
- Visitor counts on this website. We count how many people visit our public page each day, and how many join the waiting list, so we can tell whether the product is wanted. These are counts only: no cookies, no tracking scripts, no advertising networks, and no record of who visited — your address and browser are not stored.
- What we do NOT collect. AgentCheck does not access or store your customers’ (your buyers’) personal data, order data, or payment information. It only reads your product catalog and basic store settings.
How we use this information
- To run the discovery, evaluation, and transaction checks in each audit you request or schedule.
- To generate reports, show your audit history, and compare audits over time.
- To email you when a new or worsened issue appears, if you enable alerts.
- To tell waitlist members when AgentCheck opens, if they joined and confirmed.
We do not sell your data, and we do not use it for advertising or for any purpose other than providing the service.
Legal bases (EU/UK GDPR)
- Audits, reports and alerts for an installed store: to perform our contract with you (our Terms of Service).
- Waitlist emails: your consent, which you can withdraw at any time.
- Technical logs and abuse prevention: our legitimate interest in keeping the service secure and within its limits.
Service providers
We share the minimum data necessary with providers that help us run the service:
- Email delivery. When you enable alerts, your alert email address and the alert’s contents are sent to our email provider (Resend) solely to deliver that email. If you join our waitlist, your email address is also sent to Resend to deliver the confirmation email and, on Opening Day, our launch email.
- Hosting and database. The app runs on Fly.io, and your data is stored in a Supabase database, on our behalf.
These providers are located in the United States (our servers and database are in Virginia), so your data is transferred to and processed in the United States. Where the law requires it, we rely on our providers’ data processing agreements, including the European Commission’s Standard Contractual Clauses, to protect it.
Data retention and deletion
We keep your data only while AgentCheck is installed. When you uninstall the app, we delete your access token right away. About 48 hours later Shopify sends us a data-erasure request, and we then permanently erase everything else we hold for your store: your audits, the issues they found, and your schedule and alert email. You may also request deletion at any time by contacting us. Technical logs are deleted automatically after a short period.
Waitlist email addresses are kept in our database only until Opening Day. They are then imported into our email provider (Resend) to send the launch announcement and deleted from our database. You can leave the waitlist at any time using the link in our emails, which deletes your address from our database, and every marketing email includes an unsubscribe link.
AI and automated analysis
AgentCheck simulates how an AI shopping agent uses your store: it calls the same AI shopping endpoint that AI assistants can use, and applies fixed rules to what comes back. It does not currently use a large language model or any third-party AI provider, so your data is not sent to one, and it is never used to train, fine-tune, or improve any AI model. If we add an AI provider in the future, we will update this policy before we do and clearly label any AI-written text.
Your rights
Depending on where you live (for example under the EU/UK GDPR, Singapore’s Personal Data Protection Act (PDPA), or the CCPA), you may have the right to access or delete the personal data we hold. We honor Shopify’s mandatory data-request and redaction webhooks, and you can reach us — or our data protection contact — using the details below. Because AgentCheck stores no buyer/customer data, a customer data request typically returns nothing from us. You can withdraw consent (for example, by leaving the waitlist) at any time, and you have the right to complain to a data protection authority, such as the one in your EU country or Singapore’s Personal Data Protection Commission.
Security
We take reasonable measures to protect your data, restrict access to it, and transmit it over encrypted connections. No method of storage or transmission is completely secure, but we work to safeguard your information.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected by the “Last updated” date above.
Contact
Questions about this policy or your data — or to reach our data protection contact (our Data Protection Officer for PDPA purposes) — email us at support@getagentcheck.com.