Effective October 7, 2026 · Questions or requests? florian@sqrly.ai — a human answers.
1. What we collect, and why
If you run the free snapshot
Your email address and the store URL you asked about. We use the email once to confirm it's really you (double opt-in) and once to send your report link. Your email is stored alongside the request for our own records — it never appears in the report itself, which contains only facts about the store's public website.
If you subscribe to sqrly Pulse
Your email (for the dashboard link, alerts, and digests — you can point alerts at a different address from the dashboard), your store URL, your scan history, and your billing relationship. Payment details go directly to our payment processor; we never see or store card numbers.
What's in a report
Reports are about a business's public website: what our scanner read on its public pages, what its product catalog exposes, and what AI assistants said about it when we asked. Public pages sometimes mention people (a founder's name on an about page); that content is already public, and it appears in a report only served at a private link.
Usage signals
We count report opens (a count and a device type like "iPhone" — never your IP or identity), collect anonymous interaction events on dashboards (which panels get opened, so we know what's useful), and store any feedback votes or notes you choose to leave. Dashboard-link recovery is rate-limited by IP address; those rate-limit records expire within a day.
If your store uses the sqrly Shopify app
The app reads your products, variants, prices and stock (that's all it asks for at install) so the guide can answer from your real catalog. It stores what you teach it: your notes, your answers to shopper questions, your offers, and, if you allow the import, short notes taken from your store policies and published pages. Two features are optional and ask for more access only when you turn them on: offer checks read your discount codes, and confirmed revenue looks at your last 30 days of orders (only each order's number, total and cart tags, no customer details) to find the ones that came from a sqrly chat, and keeps only those orders' number, total and currency. The app never writes to your store, never handles payment, and never reads your customer list.
When you install the app (and whenever you ask), it also searches the public web for things your guide doesn't know yet: what customers, reviewers and the press say about your shop and products, your shop's story, and your team's public professional background. It never looks into anyone's private life. Findings are shown to you as suggestions, each with its source; the guide uses only the ones you accept. We keep the ones you dismiss only so we don't suggest them again. You can turn automatic searches off in the app.
If you chat with a store's sqrly guide
When you use the chat on a store that runs sqrly, we receive what you type, the page you're on, and what's in your cart (product names, quantities, prices), so the guide can give a useful answer. We keep the conversation, the products shown, and whether you added something to your cart or started checkout, so the store can see which advice helped. We don't ask for your name or email, and we don't use your chat for anything else. Please don't type payment details or passwords into the chat. Your IP address is used only for a few minutes, in memory, to stop abuse; it is never stored. The store is in charge of these conversations; we handle them on its behalf.
2. Cookies: none for you
sqrly.ai and your reports set no cookies and load no third-party trackers, ad pixels, or analytics scripts. That's why there's no cookie banner. The only cookie in the whole system belongs to our own internal admin login. Reports remember tiny preferences (like "you've seen the tour") in your browser's local storage, which never leaves your device. The free-snapshot form uses a privacy-friendly bot check to keep bots out — it's designed to work without tracking you. The sqrly chat on a store sets no cookies either: it keeps the current conversation in your browser tab's session storage (cleared when you close the tab), and remembers the chat panel's size in local storage. When you add a product from the chat, the cart gets a small sqrly conversation tag so the store can tell which sales the chat helped with.
3. Who touches the data
We work with a small number of service providers, each getting only what it needs to do its job, under contracts that limit them to that job:
- Hosting and infrastructure providers — run our website, our apps and their databases, and keep encrypted backups (kept 30 days).
- Shopify — the platform the sqrly Shopify app runs on; it passes us the store data listed above and relays privacy requests from the store's customers.
- Our payment processor — billing for sqrly Pulse; it holds your payment details. You'll see its name when you pay.
- Our email delivery provider — delivers our emails (confirmation, report links, alerts).
- AI model providers — to answer a shopper, the sqrly Shopify app sends the shopper's message, the page and cart context, and the store's catalog and knowledge to the AI models that power the guide; for web research, it sends the shop's name, website and product names. They process it only to return an answer, and their terms don't allow them to train their models on it.
- The AI assistants a Pulse scan checks (Claude, ChatGPT, Gemini, Perplexity) — during a scan we ask them about your store, sending its name, category and public website facts. That's the point of the scan: seeing how they answer. We never send them your email address or billing information.
A current list of these providers is available on request. We don't sell data, rent lists, or share anything with advertisers. There are no advertisers.
4. How long we keep things
- Free snapshot reports: expire automatically after 90 days.
- Subscriber reports and dashboards: kept while your subscription is active, up to a year per report.
- Subscription records: kept while you're subscribed, then as long as billing and tax rules require.
- Recovery rate-limit records: gone within 24 hours.
- Shopify app data (catalog, knowledge, conversations, offers): kept while the app is installed. If you uninstall, it stays for 48 hours so a reinstall picks up where you left off, then Shopify tells us to erase the store's data and we delete all of it. Backups age out within 30 days.
5. Reports about stores we haven't met
We sometimes generate a snapshot of a store's public AI-readiness and share it privately with that store's owner — that's often how merchants first hear of us. These reports are built entirely from the store's public website and public AI-assistant answers, are never posted publicly, and are sent as a private link. If one is about your store and you'd like it gone, one email to florian@sqrly.ai deletes it.
6. Your rights
Wherever you are — and including under GDPR and CCPA — you can ask us to show you everything we hold about you, correct it, export it, or delete it. Email florian@sqrly.ai; because the founder answers the inbox, this usually happens the same day, not in 30 business days. Deleting a subscription deletes its dashboards, reports, and scan history.
If you chatted with a store's sqrly guide, the store is your first contact: when it receives a data request or deletion request from you through Shopify, Shopify forwards it to us and we act on it. You can also email us directly.
7. Changes
If this policy changes in a way that matters, subscribers get an email before it takes effect, and this page's date updates. We won't quietly get worse.
8. Contact
sqrly · operated by Florian Mandel (the data controller) · San Francisco, CA · florian@sqrly.ai · sqrly.ai/contact