Skip to the content.

Privacy Policy

IFG GEO Optimizer — a Shopify app for Generative Engine Optimization Last updated: July 2026

1. Data Controller

The data controller for personal data processed through IFG GEO Optimizer is:

IFG eCommerce — based in Rome, Italy Email: info@ifgecommerce.com

2. What We Collect

The app never requests or receives personal end-customer data — no names, emails, addresses, or orders. The Shopify permissions requested are read_products, write_products (catalog and structured data), read_themes (checking the theme embed is active), and write_pixels (activating the anonymous traffic pixel above).

We process this data to provide the service you installed the app for — under Art. 6(1)(b) GDPR, performance of a contract: analyzing and improving your catalog’s visibility on generative search engines, including AI-assisted FAQ drafting and content rewriting, the in-app support chat, weekly AI-visibility tracking on prompts you choose, and anonymous AI-referral traffic measurement — all either merchant-initiated or, for the traffic pixel, consent-gated on your storefront.

4. How We Collect It

Account data is collected once, through Shopify’s OAuth flow, at install. Catalog data is read through Shopify’s Admin API only when you trigger an action from the dashboard. The traffic pixel runs on your storefront and reports events only after consent; nothing else runs in the background without you asking for it.

5. Who We Share It With

We don’t sell data, and we don’t use it for marketing or behavioral profiling.

6. How Long We Keep It

7. Your Rights

Under Articles 15–22 GDPR, you can request access to your data, correction of inaccurate data, or deletion — the simplest way is to uninstall the app — or object to processing. You can also lodge a complaint with your local data protection authority. Since the app never processes personal end-customer data, the customers/data_request and customers/redact compliance webhooks respond confirming there’s nothing to export or delete.

8. Security

All traffic runs over HTTPS/TLS 1.2+. Shopify authentication tokens are never exposed to the browser. Every webhook is verified with a constant-time HMAC SHA-256 check before it’s processed. The database is reachable only from the backend, authenticated via the hosting platform’s own service identity — there are no static credentials in the code, and direct client access is denied by the database’s own security rules. Data is encrypted at rest and in transit.

9. Changes

We may update this policy from time to time. Material changes will be reflected here, with the date at the top kept current.


Questions about your data? info@ifgecommerce.com

← Back to Help Center