Privacy Policy
Last updated: August 5, 2026
This Privacy Policy explains how MidasLift AI CRO Audit (“we”, “us”, “the App”) collects, uses, and shares information when a Shopify merchant installs or uses the App.
1. Who we are
The App is operated to deliver a free CRO (conversion rate optimization) audit: we review your storefront and email you 5 improvement recommendations.
Contact: midasliftia@gmail.com
2. Data we collect
Depending on how you use the App, we may process:
- Shop identifiers — shop domain, store name, primary storefront URL.
- Contact details — claim email you enter, store email and phone available via Shopify Admin (when accessible).
- Storefront password — only if your online store is password-protected and you provide it so we can open the storefront for review.
- Homepage screenshot — a capture of your public (or password-unlocked) homepage for the audit.
- Analytics metrics — sales, orders, average order value, conversion rate, and sessions for recent periods, read from Shopify analytics / reports APIs you authorize.
- Sector signals — product/collection titles and types, and (when configured) analysis of the screenshot or domain via an AI provider to estimate your industry for benchmarking.
- Technical data — standard logs needed to run and secure the App (e.g. request metadata, authentication session for Shopify).
3. How we use data
- To capture your storefront and prepare your CRO 5 audit.
- To compare your conversion rate with an industry benchmark and show insights in the App.
- To notify our review team (via Slack webhook) when you claim CRO 5 FREE, so a specialist can follow up by email.
- To email you the 5 improvements and related follow-up.
- To operate, secure, and improve the App.
4. Sharing
We share data only as needed to provide the service:
- Shopify — authentication and Admin API access under your install scopes.
- Hosting (Render) — where the App runs and temporary screenshot files may be stored.
- Slack — claim details for our internal review team.
- OpenAI — optional sector classification from domain / screenshot signals when enabled.
- Email — to send your audit results to the contact address you provide.
We do not sell your personal data. We do not use customer personal data from your store for advertising.
5. Retention
We keep claim and audit materials only as long as needed to deliver the CRO 5 report and handle support, then delete or anonymize them when no longer required, unless a longer period is needed for legal or security reasons. Screenshots and passwords are not intended for long-term storage beyond the audit workflow.
6. Security
We use industry-standard safeguards appropriate to a Shopify embedded app (HTTPS, authenticated Admin API sessions, restricted environment secrets). No method of transmission or storage is 100% secure.
7. Your choices
- You can uninstall the App from Shopify Admin at any time.
- You can request access, correction, or deletion of claim-related data by emailing us.
- Do not submit a storefront password unless you want us to access a password-protected storefront for the audit.
8. Children
The App is for Shopify merchants and is not directed at children under 16.
9. Changes
We may update this policy. The “Last updated” date at the top will change when we do. Continued use of the App after updates means you accept the revised policy.
10. Contact
Questions about privacy: midasliftia@gmail.com
© 2026 MidasLift AI CRO Audit