Privacy Policy
Last updated: 3 August 2026
This policy explains how Custodian AI (“Custodian”, “we”, “us”) processes data when a Shopify merchant installs or uses the Custodian AI Page Builder. Custodian is operated by Adrien Belhomme, 67 avenue Gambetta, 92400 Courbevoie, France. The merchant remains the controller of data from its store; Custodian acts as its processor for the services described below.
1. Merchant and store data
We process only the data needed to provide features selected by the merchant:
- shop domain, currency, locale and store configuration;
- products, collections, public reviews and legal policies;
- Online Store pages, generated page versions and theme files;
- optional connected-service data when the merchant explicitly connects a Meta Ads, Google Ads or reviews account; and
- app usage, billing and operational diagnostics.
2. Connected Google Ads data
Google Ads is optional and is connected only after an authorised user starts Google’s OAuth flow. We receive an access token, a refresh token for offline synchronisation, the selected advertiser or manager account identifiers, and the granted scope. We never receive the user’s Google password.
Custodian’s Google Ads integration is read-only. It can retrieve accessible accounts; campaign, ad-group and ad identifiers, names, types and statuses; ad headlines, descriptions, images and destination URLs; and limited delivery or performance metrics needed for the merchant-facing Daily Brief. Custodian does not create, edit, pause or delete campaigns, ads, keywords, bids or budgets, and does not access Google Ads billing or user-management data.
When the merchant selects an ad, its chosen copy and creative may be sent to our configured AI generation providers solely to generate that merchant’s requested page. Custodian does not use Google Ads data to train a shared model, build profiles across merchants, sell data or target unrelated advertising. A page can retain a bounded campaign/ad snapshot and an opaque tracking key so its first-party sessions can be reported against the source selected by the merchant.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
3. Storefront analytics and consent
On a Custodian-generated page, our Shopify app embed can measure page views, exposures, CTA clicks, confirmed add-to-cart actions, checkout starts and related page interactions. It uses random session and page-view identifiers that are not tied to a Shopify customer account. The embed loads Shopify’s Customer Privacy API and starts analytics only when Shopify reports that analytics processing is allowed for that visitor. If the API is unavailable, consent loading fails, or analytics permission is denied or revoked, Custodian does not create an analytics session, assign an A/B variant or emit storefront telemetry.
4. Paid-order attribution for A/B tests
When a merchant runs an A/B test, Shopify can send Custodian an authenticated orders/paid webhook. The subscription is restricted to the order identifier, currency and the line-item price, quantity, discount and properties needed to read Custodian’s signed attribution marker. We use this data to calculate attributed orders, conversion rate and revenue per session, and to verify that attribution remains reliable before any automatic rollback.
Custodian stores a cryptographic order reference, the experiment, variant and anonymous assignment identifiers, attributed line revenue, currency, timestamps and integrity counters. We do not intentionally store customer names, email addresses, telephone numbers, postal addresses, payment-card data or the raw Shopify order payload.
5. How data is used
We use the data exclusively to:
- generate, edit, publish and restore merchant landing pages;
- provide the Daily Brief and explain A/B test verdicts;
- attribute funnel events and paid orders to the correct test arm;
- protect the service against abuse and unreliable attribution; and
- operate, secure, troubleshoot and bill the service.
We do not sell merchant or customer data, use it for cross-context behavioural advertising, or make automated decisions about individuals that produce legal or similarly significant effects.
6. Service providers and international processing
We use Shopify to receive authorised store data, Vercel to operate the web application, Railway to operate the PostgreSQL database, and configured AI or media providers to perform merchant-requested page generation. These providers process data only to deliver the requested service under their applicable data-protection and security commitments. Data may be processed in the regions used by those providers, subject to applicable contractual transfer safeguards.
7. Security
Custodian applies shop-level access controls, signed attribution tokens, replay and traffic safeguards, restricted operational access and encrypted transport. Google and Meta OAuth credentials are encrypted at rest using AES-256-GCM and isolated by Shopify store. Production database connections require TLS and the database provider encrypts data at rest. Secrets and buyer identity are not written to A/B event logs.
8. Retention and deletion
Detailed storefront telemetry, anonymous assignments, A/B event data, decision snapshots and paid-order attribution signals are retained for no more than 24 months. An automated scheduled process removes expired records. A Shopify customer-data request creates an AES-GCM encrypted report in the authenticated merchant Settings. The merchant can view or download it and include it in the merchant’s response to the customer; the webhook response and operational logs never contain the report. The encrypted copy is deleted when delivery is confirmed or, at the latest, 30 days after the request. Only a non-customer-identifying delivery audit may remain for up to 24 months. Shopify privacy webhooks are also used to delete order-linked A/B records for a data-subject request. After uninstall, Shopify sends a shop-redact request and Custodian deletes the data keyed to that shop, except where a mandatory legal obligation requires a limited record to be retained.
Disconnecting Google Ads revokes the available Google OAuth credential and deletes the stored tokens. Bounded campaign/page provenance and reporting records may remain with the merchant’s page for up to 24 months so historical reports remain explainable; they are deleted when the page or shop data is deleted. A merchant can also revoke access at any time from the Google Account third-party access settings.
9. Rights and requests
Customers should normally contact the Shopify merchant with whom they placed an order. Merchants and customers may also contact us regarding access, correction, deletion, restriction or objection requests at adrien@custodiancommerce.com. We cooperate with the merchant and Shopify’s mandatory privacy-webhook process; requested data is provided directly to the merchant for delivery within the applicable 30-day period, not in a webhook response.
10. Changes and contact
We may update this policy when the Service changes. The date above shows the current version. Questions about this policy or our processing can be sent to adrien@custodiancommerce.com.