Privacy Policy

Last updated:

This Privacy Policy explains how Blast Commerce LLC, doing business as PinkyBrain ("PinkyBrain," "we," "us," or "our"), collects, uses, stores, and discloses information when merchants install or use the PinkyBrain app for Shopify and when shoppers interact with storefront features operated by PinkyBrain.

PinkyBrain is an evidence-driven store and product optimization application. It synchronizes authorized Shopify data, can connect to Google Analytics 4, collects first-party storefront analytics through a Shopify Web Pixel, generates AI-assisted reports and content, captures storefront evidence for audits, and supports experiments and merchant support requests.

1. Business Information

Blast Commerce LLC
1308 E Colorado Blvd
#3296
Pasadena, CA 91106
United States

Contact: support@pinkybrain.app

2. Scope and Privacy Roles

This policy applies to information processed through the PinkyBrain embedded Shopify app, its Shopify theme and Web Pixel extensions, its app-proxy endpoints, and its support and privacy-request features. It does not govern Shopify, Google, or other third parties when they process information for their own purposes under their own policies.

For Shopify customer and shopper information that PinkyBrain processes to provide services to a merchant, the merchant generally determines why and how that information is used, and PinkyBrain generally acts as the merchant's service provider or processor. PinkyBrain may act as an independent business or controller for merchant account administration, billing and entitlement records, security, product analytics, legal compliance, and direct support communications. The precise legal roles can vary by jurisdiction and context.

3. Sources of Information

We receive information from:

4. Information We Collect

Store, account, authorization, and configuration information

Catalog, storefront, theme, and policy information

Orders, customers, returns, refunds, and commercial information

PinkyBrain does not receive or store full payment-card numbers for app subscription or extra-usage purchases. Shopify processes those charges and provides PinkyBrain with charge, subscription, plan, amount, status, and billing-period information.

Storefront behavioral and experiment information

Google Analytics 4 information

AI, generated-content, analysis, and workflow information

Audit, screenshot, and protected-store information

Support information

Technical, security, and product-analytics information

5. How We Use Information

We use information to:

Where applicable law requires a legal basis and PinkyBrain acts as a controller, processing may be based on performance of a contract, legitimate interests in operating and securing the service, consent, or compliance with legal obligations, depending on the context.

6. AI and Automated Processing

PinkyBrain uses automated rules and third-party AI models to generate store and product insights, content, recommendations, visual analyses, audits, and experiment interpretations. Depending on the requested workflow, PinkyBrain may send an AI provider the store, catalog, policy, commerce or analytics summaries, merchant instructions, prior workflow context, product images, or storefront screenshots needed to return that store-specific result.

Current code supports AI processing through OpenAI and Anthropic, with the provider and model selected by configured routing and capability rules. These providers process the submitted information to return the requested output and may maintain service logs under the applicable service-provider terms and PinkyBrain's configuration.

PinkyBrain does not use merchant or Google API data to train its own generalized foundation models. AI output may be incomplete or inaccurate and is intended to assist the merchant. Merchants are responsible for reviewing content, publishing decisions, experiments, and business actions before relying on them. PinkyBrain does not use AI to make legal, credit, employment, or similarly significant decisions about individual shoppers.

7. Storefront Analytics, Cookies, and Browser Storage

PinkyBrain uses a Shopify Web Pixel for analytics and experiment measurement. The pixel is configured for analytics, not marketing or sale of data, and runs within Shopify's strict pixel sandbox. Where Shopify requires shopper consent, the pixel receives events only in accordance with Shopify Customer Privacy signals.

Storefront event and session records are retained for a configured period that is currently 400 days by default, unless they are deleted earlier through shop redaction or operational cleanup. Merchant storefronts remain responsible for presenting any notices and consent controls required for their use of analytics and experiment features.

8. Google Analytics and Google API Data

Connecting GA4 is optional. If a merchant connects a property, PinkyBrain uses Google's OAuth consent flow and currently requests only the https://www.googleapis.com/auth/analytics.readonly scope. PinkyBrain uses this access to list properties and data streams available to the authorized Google account and to read reporting data for historical product, store, acquisition, and legacy experiment measurement. PinkyBrain does not use GA4 edit access and does not create or modify GA4 custom dimensions or unrelated Google Analytics settings.

GA4 data is used only for the connected merchant's user-facing PinkyBrain features. Aggregated GA4 metrics may be included in a PinkyBrain analysis request processed by an AI service provider solely to generate the merchant-requested, store-specific output. Merchants can disconnect GA4 in PinkyBrain; the app then attempts to revoke the Google access token and clears locally stored GA4 tokens and property identifiers. Previously derived reports or aggregates remain subject to the retention and deletion rules below.

PinkyBrain's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, PinkyBrain does not sell Google API data, use it for advertising or lending, transfer it to data brokers, or use it to create, train, or improve generalized AI or machine-learning models beyond the merchant-requested, store-specific feature. Human access is limited to circumstances permitted by the Google API Services User Data Policy, such as explicit user consent for support, security, legal compliance, or appropriately aggregated and de-identified internal operations.

9. How We Disclose Information

We disclose information only as needed for the purposes described in this policy, including to:

Service providers are permitted to process information only for the contracted service or as otherwise allowed by applicable law and their governing terms. Authorized PinkyBrain personnel may access information when necessary to provide requested support, operate and secure the service, investigate incidents, or comply with law.

10. Sale, Advertising, and Data Brokerage

PinkyBrain does not sell merchant or shopper personal information, does not provide it to data brokers, and does not use it for cross-context behavioral advertising. PinkyBrain's Shopify Web Pixel is configured with marketing disabled and sale-of-data disabled. PinkyBrain does not use raw advertising click identifiers; it records only whether certain identifiers were present to classify acquisition without retaining the identifier itself.

11. Retention and Deletion

PinkyBrain retains information for as long as reasonably necessary to provide the service, preserve merchant-requested history, maintain security and operational records, comply with law and platform requirements, resolve disputes, and enforce agreements. Retention varies by data type and configuration.

On uninstall, PinkyBrain immediately disables normal tenant processing and clears the Shopify access token. Shopify subsequently sends its mandatory shop/redact request. PinkyBrain's shop-redaction process deletes tenant data from application tables, caches, and linked object-storage artifacts. Minimal shop lifecycle and paid-entitlement metadata may be retained until the end of an already-paid billing period, after which the remaining retained entitlement rows are deleted.

A Shopify customers/redact request deletes identifiable customer-linked rows from PinkyBrain's customer, line-item, and return records for that shop. Aggregated or de-identified measures that no longer identify the customer may remain where permitted. PinkyBrain also responds to customers/data_request by preparing a tenant-scoped export for the merchant. Shopify's compliance-webhook process is described in its privacy law compliance documentation.

12. Data Security

PinkyBrain uses administrative, technical, and organizational safeguards designed to protect information. The implementation includes authenticated Shopify session tokens, webhook signature verification, tenant-scoped database access, request correlation, rate and concurrency controls, abuse detection, encrypted storage of temporary storefront passwords, protected credentials, short-lived signed download URLs, recoverable background jobs, and controlled access to infrastructure and service-provider credentials.

No transmission or storage system is completely secure. Merchants should protect their Shopify, Google, and PinkyBrain access and should avoid including unnecessary personal or confidential information in prompts, support messages, screenshots, or storefront content.

13. Rights and Choices

Merchants and authorized users

Shopify customers and storefront visitors

A Shopify customer or storefront visitor should ordinarily submit a privacy request to the merchant whose store they visited. The merchant can route the request through Shopify, which sends PinkyBrain the applicable mandatory privacy webhook. PinkyBrain will assist the merchant and respond to valid Shopify customer-data and redaction requests as required.

Depending on applicable law, individuals may have rights to know, access, correct, delete, restrict, or object to certain processing, and to appeal or complain to a supervisory authority. PinkyBrain will not discriminate against an individual for exercising a privacy right. To make a direct request, contact support@pinkybrain.app and identify the relevant Shopify store. We may need to verify the request or coordinate with the merchant.

14. International Processing

PinkyBrain and its service providers may process information in the United States and other jurisdictions. Those jurisdictions may have data-protection laws different from the laws where the merchant or shopper is located. Where required, PinkyBrain uses appropriate contractual or other safeguards for international transfers.

15. Children's Privacy

PinkyBrain is a business application for Shopify merchants and is not directed to children. We do not knowingly collect personal information directly from children through the merchant application. Shopify merchants are responsible for their storefront audience and customer data.

16. Changes to This Privacy Policy

We may update this Privacy Policy as PinkyBrain, applicable requirements, or our service providers change. We will update the "Last updated" date and provide any additional notice or consent required by applicable law or Google API policy before using previously collected data for a materially different purpose.

17. Contact Us

Questions or privacy requests can be sent to:

PinkyBrain / Blast Commerce LLC
1308 E Colorado Blvd
#3296
Pasadena, CA 91106
United States
support@pinkybrain.app