PRIVACY POLICY

How Sold Countly & Reviews handles information used by its features.

This Privacy Policy explains how AI Ecommerce Solutions processes information when merchants install or use Sold Countly & Reviews, when eligible customers interact with review features, and when visitors use this public informational website.

Operator AI Ecommerce Solutions Last updated August 29, 2026
Important

This policy describes the app's data practices and is not a promise that every privacy law applies in the same way to every merchant or customer. Merchants remain responsible for their own store privacy notices and legal obligations. If specific legal advice is needed, consult an appropriate professional.

01

Scope

This policy applies to Sold Countly & Reviews by AI Ecommerce Solutions, including the embedded Shopify merchant app, its storefront and review-request components, merchant support and privacy-request workflows, and this public informational website.

Shopify is a separate platform provider and processes information under its own terms and privacy practices. Shopify merchants also control their own stores and are responsible for the notices and choices they provide to their customers.

02

Information processed by the app

The exact fields available depend on the merchant's Shopify store, enabled features, Shopify permissions, order state, and information entered by the merchant or reviewer. The app can process the following categories.

Merchant and shop information

Shopify shop identifier and domain, authenticated app/session information needed to operate the app, merchant contact information available through the authenticated workflow, app settings, and feature preferences.

Order, product and purchase information

Order identifiers and names, product and variant identifiers/titles, line-item identifiers, quantities, order/payment/fulfillment/delivery/refund state and timestamps, customer identifiers when available, recipient email used for eligible review requests, hashed email identifiers, and country information used by the review-request workflow.

Review information

Rating, optional title and review text, customer display name, review status/source, verified-purchase state, merchant reply, moderation timestamps, and related product/order references. Certain buyer identifiers are stored as hashes in review-related records.

Review media

Photos or a short video submitted with an eligible native verified review, together with technical file metadata such as file name, media type, size, dimensions, duration, storage reference, and thumbnail reference where applicable.

Imported review information

Review fields supplied by a merchant through the supported Excel import workflow, including the review content and product-matching information used for merchant moderation. Imported reviews are handled separately from native purchase-verified reviews.

Storefront activity

For recent cart activity, the current data model stores the shop, hashed cart token, product and variant identifiers, and recent-seen timestamps. The storefront count is designed to use recent observed presence rather than exposing the underlying cart token.

Billing and tax-profile information

When a merchant enters billing or tax-profile details, the app can store business/legal name, billing email, country and address information, and applicable tax/GST profile fields used by the billing administration workflow. Shopify App Pricing manages the subscription plan transaction.

Support information

Support conversation subject and messages, conversation status, merchant contact email when available, unread state, notification records, and private support attachments submitted through the authenticated Help & Support module.

Privacy-request information

Shopify privacy-request identifiers, authenticated shop, customer identifier when supplied, normalized customer email hash when supplied, requested order identifiers, workflow status, timestamps, and audit information used to manage data-access or redaction requests.

Operational records

Webhook delivery records, sold-count adjustments, historical sold-count import records, review email job state, moderation/audit records, and other technical records used to operate, troubleshoot, secure, or make app actions idempotent.

03

Where information comes from

Information can come from:

  • Shopify APIs and webhooks, including shop, product, inventory, order, fulfillment, refund, and privacy-request events available under the app's granted permissions.
  • Merchants, including app settings, imported review files, billing/tax-profile details, moderation actions, support messages, and support attachments.
  • Eligible store customers, including review ratings, review text, display name, and optional review media submitted through the app's review workflow.
  • Storefront feature activity, including the limited recent cart-presence state needed for the optional cart-activity signal.
  • Technical operation of the service, including logs, webhook/audit records, timestamps, and delivery state needed to keep workflows reliable and scoped to the correct shop.

04

How information is used

Information is processed to provide, maintain, secure, and support the app's requested features, including to:

  • Authenticate the Shopify merchant and scope app data to the correct shop.
  • Calculate and maintain sold-count adjustments from eligible order and refund activity.
  • Read tracked inventory state needed for availability and eligible stock-cycle signals.
  • Maintain recent observed cart-presence state used by the optional “X in Cart” storefront signal.
  • Determine product-level review eligibility from eligible paid Shopify purchases.
  • Schedule, send, retry, or suppress review-request emails under the configured review-request rules.
  • Receive, moderate, display, hide, reject, reply to, or remove review content according to app state and merchant actions.
  • Process review media and keep approved media linked to the associated review and product.
  • Validate and moderate imported review records before any supported storefront publication.
  • Operate Shopify-centered subscription, billing, and merchant tax-profile administration.
  • Operate private merchant-to-support conversations and attachments.
  • Process supported Shopify privacy requests and maintain the related delivery/redaction audit state.
  • Detect duplicate processing, troubleshoot failures, protect service integrity, and maintain technical audit records.

The current app features are not designed to use merchant or customer information for unrelated interest-based advertising or unrelated marketing profiling.

05

What can appear publicly on a merchant storefront

Public storefront output is intentionally narrower than the private data processed to operate a feature.

Approved review content

Eligible approved review rating, display name, title/body when provided, approved media, and merchant reply can be presented publicly.

Review aggregates

Approved review counts and rating aggregates can be displayed without publishing private order or recipient-email fields.

Storefront signals

Sold count, tracked availability, recent cart count, and eligible Selling Fast state can be displayed as feature output.

Not intended for public display

Private support threads, support attachments, Shopify session credentials, review-request recipient email, hashed internal identifiers, private billing/tax-profile fields, and privacy-request workflow records are not storefront review content.

06

Service providers, sharing, and international processing

Information can be processed through service providers needed to operate the requested service. These categories include Shopify, application hosting/database infrastructure, private file or media storage, and configured email delivery services used for review-request or support notifications. The public marketing website is hosted through Netlify.

We disclose information to these providers only to the extent reasonably needed to provide or secure the relevant service, or where disclosure is required by applicable law or a valid legal process. Shopify and other service providers operate under their own terms and privacy practices.

Because Shopify and infrastructure/service providers can operate internationally, information can be processed in countries other than the country where a merchant or customer is located. Where applicable, cross-border processing is subject to the safeguards and legal requirements that apply to the relevant party and processing activity.

07

Retention, redaction, and deletion

We retain information only for as long as reasonably needed for the feature or workflow for which it is processed, to maintain service and security integrity, to resolve support or billing matters, to respond to privacy requests, or to satisfy applicable legal, accounting, dispute, fraud-prevention, or audit needs. Different categories can therefore have different retention periods.

Recent cart-presence state is operational and intended to represent recent observed activity rather than a permanent customer profile. Review, billing, support, webhook, and audit records can need longer retention because they support merchant-controlled content, service history, billing, disputes, security, or legal obligations.

When Shopify sends a supported customer or shop redaction request, the app's privacy workflow is designed to remove or redact matching app-held customer-linked or shop-scoped information, subject to information that must be retained for a lawful reason. Redaction can include related review/request records, selected audit identifiers, private review media, and shop-scoped support or application records as applicable to the request type.

A privacy deletion request does not necessarily mean that every record can be deleted in the same way or at the same time. Where retention is legally required, information can instead be minimized, restricted, or retained only for the required purpose.

08

Security safeguards

The app includes controls designed to reduce unnecessary access or exposure, including authenticated merchant routes, shop-scoped queries, authenticated administrative support access, server-side validation, private support-attachment storage, and hashed identifiers for selected review/cart/privacy-request use cases.

Support attachment downloads are designed to require authenticated access and use private response controls. Review media publication follows the associated review's eligible public moderation state. Webhook handlers use Shopify's authenticated webhook processing path before acting on webhook payloads.

No internet-connected service can promise absolute security. Security controls, access permissions, dependency updates, backups, logging, and incident procedures should be reviewed as the service and threat environment change.

09

Public marketing website

The current standalone public website is informational. Its website source does not include Google Analytics, advertising pixels, Hotjar, or similar third-party marketing trackers. The website uses local page assets and does not itself provide the authenticated Shopify merchant app.

The website is hosted through Netlify, which can process standard technical request information as part of hosting and service operation under Netlify's own terms and privacy practices. If analytics, consent tooling, forms, or other third-party website services are added in the future, this policy and any required notice or consent behavior will be updated as appropriate.

10

Privacy and data requests

Depending on applicable law and the relationship between a shopper, merchant, Shopify, and AI Ecommerce Solutions, an individual may have rights relating to access, correction, deletion/redaction, restriction, or other handling of personal information.

Store customers should normally begin with the Shopify merchant from whom they purchased. The merchant controls the underlying store relationship and can initiate the applicable Shopify privacy-request process when appropriate.

Sold Countly & Reviews includes handling for Shopify's mandatory privacy-request topic types: customers/data_request, customers/redact, and shop/redact. When a supported request is received through Shopify, the app's privacy workflow is designed to scope processing to the authenticated shop and the identifiers Shopify supplies. Data-access delivery to a merchant remains separate from the merchant's own response to its customer.

Installed merchants can use the authenticated in-app Privacy Requests and Help & Support areas for app-related privacy questions and workflows. Additional guidance is available on the Data / Privacy Request page.

11

Children

Sold Countly & Reviews is a business tool for Shopify merchants and is not designed as a service directed to children. Merchant storefront customers interact with the merchant's Shopify store and any eligible review workflow connected to their purchase.

12

Changes to this policy

We can update this policy when app features, infrastructure, service providers, privacy-request processes, or applicable requirements change. The current public version will show its last-updated date. Materially different data handling should be reflected in this policy before or when the change becomes applicable.

13

Contact

Sold Countly & Reviews is operated by AI Ecommerce Solutions.

Installed merchants can contact us through the authenticated Help & Support area inside the app. For pre-install or App Store listing questions, use the support channel displayed on the Sold Countly & Reviews listing in the Shopify App Store. For privacy-request guidance, see our Data / Privacy Request page.

Store customers should normally contact the Shopify merchant from whom they purchased first so the merchant can identify the relevant store relationship and initiate any applicable Shopify privacy workflow.

PRIVACY & SUPPORT

Need help with app data or a privacy request?

Use the route that matches your relationship to the store so the request can be scoped correctly.