Legal
Privacy Policy
Effective date: May 11, 2026
This Privacy Policy explains how Mashup(“Mashup”, “we”, “us”) collects, uses, shares, and protects personal information when you install or use the Mashup application (the “App”) on Shopify, when you visit our website at www.mashupai.io, or when you otherwise interact with us.
By installing the App or using our services, you agree to the practices described below.
1. Who we are
The data controller for personal information processed under this Policy is Mashup, [Company address]. For privacy questions or to exercise your rights, contact us at support@mashupai.io.
2. Information we collect
From the Shopify merchant (you)
- Shop domain, store name, owner email, country, currency
- Shopify API access tokens granted to the App during installation
- Product, collection, theme, and page data accessed through the Shopify Admin API in order to generate AI content
- Billing status, plan, and subscription identifiers received from Shopify Billing
- Account preferences, generated content history, and app usage within Mashup
From your customers (storefront visitors)
The App does not directly collect identifiable information from your storefront visitors. The Liquid sections and templates we install run inside your Shopify theme and use Shopify’s native mechanisms (e.g. cart, checkout). Any visitor analytics you choose to enable (e.g. Shopify Analytics, Google Analytics) are governed by your own privacy policy, not this one.
From visitors to our website
- Standard request metadata (IP address, user-agent, referrer, timestamp) collected by our hosting providers for security and abuse prevention
- Cookies set by analytics or marketing tools, if enabled
- Information you submit through contact forms or email
3. How we use information
- To provide, operate, and improve the App and our website
- To generate AI-powered themes, page content, copy, SEO metadata, and product descriptions based on prompts and product data you provide
- To process subscription billing through Shopify and enforce plan entitlements
- To send transactional and service-related emails (e.g. billing receipts, subscription updates, support replies)
- To detect, prevent, and respond to fraud and security issues
- To comply with legal obligations and enforce our Terms
4. Legal bases (EEA / UK)
If you are in the EEA, UK, or Switzerland, we rely on:
- Contract: processing necessary to provide the App you installed
- Legitimate interests: securing our services, preventing fraud, improving the product, marketing our own services to existing customers
- Consent: where required (e.g. certain cookies)
- Legal obligation: tax, accounting, and regulatory requirements
5. Subprocessors and third parties
We use trusted third-party providers to operate the App. They process personal information only on our instructions and under written data-protection terms. Current subprocessors:
| Provider | Purpose | Location |
|---|---|---|
| Shopify Inc. | Platform, billing, merchant data source | Canada / Global |
| Anthropic, PBC | AI content generation (Claude) | United States |
| Google LLC | AI content generation (Gemini) | United States |
| Fly.io, Inc. | Application hosting | Global |
| Vercel Inc. | Website hosting | United States |
| Resend | Transactional email delivery | United States |
| Functional Software, Inc. (Sentry) | Error monitoring and diagnostics | United States |
Where data is transferred outside the EEA / UK, we rely on Standard Contractual Clauses or equivalent safeguards.
6. AI processing notice
When you use AI features (theme generation, copy, SEO), the prompt text and product context you provide are sent to AI providers listed above for the sole purpose of returning a generated result. We do not allow these providers to use your data to train their models, to the extent their terms of service permit such an opt-out. Do not submit sensitive personal data (e.g. national IDs, payment card numbers, health data) through AI features.
7. How long we keep information
- Active merchant data is kept while the App is installed.
- After uninstall: Shopify access tokens are invalidated immediately. Merchant data is retained for up to 30 days to support reinstall, then deleted, except where retention is required by law (e.g. invoicing records).
- Backups may retain copies for up to 90 days before being overwritten.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- access the personal information we hold about you
- correct inaccurate information
- delete your information (right to erasure)
- export your information in a portable format
- object to or restrict certain processing
- withdraw consent where processing is based on consent
- lodge a complaint with a supervisory authority
To exercise any of these rights, email support@mashupai.io. We respond within 30 days.
9. Customer data requests via Shopify
Shopify forwards three GDPR-related webhooks to Mashup:
customers/data_request— a merchant’s customer has requested their data. We forward this request to the merchant; Mashup does not store storefront-customer personal data.customers/redact— a merchant’s customer has requested deletion. Same forwarding behavior.shop/redact— sent 48 hours after a shop uninstalls the App. We delete all shop data on receipt.
10. Security
We use industry-standard safeguards including TLS in transit, encryption at rest for sensitive fields, access controls, principle-of-least-privilege internal access, and audit logging. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
11. Children
The App is intended for businesses. It is not directed to children under 16 and we do not knowingly collect personal information from children.
12. International users
Personal information may be processed and stored in countries other than your own, including the United States and Canada. By using the App you understand this.
13. Changes to this Policy
We may update this Policy from time to time. Material changes will be announced via email to merchant account owners and posted at this URL at least 30 days before taking effect. The “Effective date” at the top reflects the most recent revision.
14. Contact
For any privacy question or to exercise your rights, contact:
Mashup
[Company address]
support@mashupai.io