Privacy Policy
Last updated:
This Privacy Policy explains how Blast Commerce LLC, doing business as PinkyBrain ("PinkyBrain," "we," "us," or "our"), collects, uses, stores, and discloses information when merchants install or use the PinkyBrain app for Shopify and when shoppers interact with storefront features operated by PinkyBrain.
PinkyBrain is an evidence-driven store and product optimization application. It synchronizes authorized Shopify data, can connect to Google Analytics 4, collects first-party storefront analytics through a Shopify Web Pixel, generates AI-assisted reports and content, captures storefront evidence for audits, and supports experiments and merchant support requests.
1. Business Information
Blast Commerce LLC1308 E Colorado Blvd
#3296
Pasadena, CA 91106
United States
Contact: support@pinkybrain.app
2. Scope and Privacy Roles
This policy applies to information processed through the PinkyBrain embedded Shopify app, its Shopify theme and Web Pixel extensions, its app-proxy endpoints, and its support and privacy-request features. It does not govern Shopify, Google, or other third parties when they process information for their own purposes under their own policies.
For Shopify customer and shopper information that PinkyBrain processes to provide services to a merchant, the merchant generally determines why and how that information is used, and PinkyBrain generally acts as the merchant's service provider or processor. PinkyBrain may act as an independent business or controller for merchant account administration, billing and entitlement records, security, product analytics, legal compliance, and direct support communications. The precise legal roles can vary by jurisdiction and context.
3. Sources of Information
We receive information from:
- the merchant and authorized users when they install, configure, or use PinkyBrain;
- Shopify Admin APIs, webhooks, App Bridge, billing, theme extensions, app proxy, and Web Pixel customer events;
- Google Analytics 4 when the merchant affirmatively connects a property;
- the merchant's public or password-protected storefront during requested or scheduled audits and observations;
- shoppers' browsers when PinkyBrain analytics or experiment delivery operates on a participating storefront; and
- our infrastructure, security, analytics, AI, storage, and email service providers.
4. Information We Collect
Store, account, authorization, and configuration information
- Shop domain, store identifiers, primary domain, store name, timezone, currency, installation state, and Shopify account or session identifiers.
- Shopify access and refresh tokens, granted scopes, webhook identifiers, app-host parameters, and related authorization metadata.
- Store maturity, industry, positioning, business-model, benchmark, saved context, feature settings, model-routing selections, and guided-setup state.
Catalog, storefront, theme, and policy information
- Products, titles, descriptions, handles, variants, images, media identifiers, tags, SKUs, prices, compare-at prices, publication and lifecycle status, inventory-related information, and subscription or selling-plan indicators.
- Theme and template identifiers, app-block placement and configuration, storefront URLs, rendered visible text and structure, store identity assets such as a favicon, and change history.
- Shipping, refund, privacy, and other Shopify policy text used to provide merchant-requested context.
Orders, customers, returns, refunds, and commercial information
- Order and line-item identifiers, order names and dates, purchased products and variants, quantity, price, revenue, discounts, currency, subscription indicators, and fulfillment-related status.
- Customer identifiers and, where available through authorized Shopify data, customer or order names, email address, company, tags, merchant notes, order history, purchase totals, and B2B-related signals.
- Return and refund identifiers, amounts, dates, quantities, status, reasons, customer-provided return notes, and related product, variant, order, and customer references.
- Aggregated product, variant, store, promotion, subscription, customer-outcome, retention, and performance measures derived from this information.
PinkyBrain does not receive or store full payment-card numbers for app subscription or extra-usage purchases. Shopify processes those charges and provides PinkyBrain with charge, subscription, plan, amount, status, and billing-period information.
Storefront behavioral and experiment information
- Page views, product views, add-to-cart events, checkout starts and completions, product engagement, experiment exposures, and experiment delivery failures.
- Pseudonymous client, session, visitor, assignment, experiment, run, product, variant, version, and order identifiers.
- Event time, page and referrer URLs without query strings or fragments, landing path, UTM source/medium/campaign/term/content, device or browser user agent, and traffic-quality classification.
- Quantity, amount, currency, and whether common advertising click identifiers were present. PinkyBrain intentionally does not transmit or store the raw click identifiers.
Google Analytics 4 information
- Google OAuth access and refresh tokens, token expiry, authorized scopes, selected account/property and data-stream identifiers, property name, and measurement ID.
- Read-only GA4 reporting data such as dates, page paths, product or item dimensions, sessions, engaged sessions, views, add-to-cart events, purchases, items purchased, revenue, acquisition source/medium/campaign, device category, and legacy experiment dimensions where available.
AI, generated-content, analysis, and workflow information
- Merchant prompts, instructions, settings, selected date windows, product and store evidence, and other context submitted to an AI-assisted workflow.
- Generated titles, descriptions, notifications, analyses, recommendations, audits, experiment analyses, drafts, saved versions, report history, and publishing or workflow events.
- AI route, provider and model, prompt or policy version, token usage, cached-token usage, response status, calculated provider cost, usage reservation or debit, and related diagnostic metadata.
Audit, screenshot, and protected-store information
- Desktop and mobile storefront screenshots, visible page content, rendered component manifests, page URLs, capture checkpoints, audit findings, PDF reports, and historical media needed to explain changes over time.
- A storefront password supplied for a protected storefront. The password is encrypted while a background audit or observation may need it and is cleared after successful completion or terminal failure; it is not included in merchant-facing reports.
Support information
- Support category, reply email, message, current app page, app version, ticket and request identifiers, user agent, delivery status, and related correspondence.
- An optional PNG, JPEG, or WebP screenshot. PinkyBrain transmits the compressed screenshot as an email attachment to its support delivery provider and support inbox; the application does not store the screenshot itself in its database or object storage as part of the support-request record.
Technical, security, and product-analytics information
- Request and correlation identifiers, route, method, status, timestamps, query and path parameters, user agent, error details, job state, integration spans, performance timings, rate-limit and concurrency state, and abuse or traffic-quality signals.
- For the PinkyBrain merchant application, production product analytics may include a hashed store identifier, normalized app route, app open and page-view events, selected operation type, completion or failure, duration, date-range category, audit scope, report type, status code, web-vital data, heatmaps, and masked session recordings.
- Product analytics do not intentionally include raw shop domains, email addresses, product or order identifiers, search queries, request or response bodies, captured network headers, typed input, or readable page text. Product analytics are disabled outside configured production deployments and respect browser Do Not Track.
5. How We Use Information
We use information to:
- authenticate the merchant, maintain tenant isolation, and operate the embedded Shopify app;
- synchronize and reconcile catalog, commerce, customer, return, refund, theme, policy, and analytics data;
- provide store, product, variant, image, copy, storefront, and product-page analysis;
- generate and manage titles, descriptions, notifications, recommendations, reports, and reusable workflow history;
- capture and compare storefront evidence, track meaningful changes, and produce Change Impact reports;
- create, deliver, measure, analyze, and settle A/B experiments;
- calculate performance metrics, source coverage, data health, benchmark context, prioritization opportunities, and product suggestions;
- administer plans, monthly AI usage, extra usage, billing reconciliation, and included setup actions;
- provide guided setup, privacy exports, customer support, and merchant communications;
- secure the service, prevent abuse, enforce limits, investigate errors, recover background work, and maintain reliability;
- understand and improve the merchant application using privacy-reduced product analytics; and
- comply with law, Shopify requirements, and our agreements, and protect rights and platform integrity.
Where applicable law requires a legal basis and PinkyBrain acts as a controller, processing may be based on performance of a contract, legitimate interests in operating and securing the service, consent, or compliance with legal obligations, depending on the context.
6. AI and Automated Processing
PinkyBrain uses automated rules and third-party AI models to generate store and product insights, content, recommendations, visual analyses, audits, and experiment interpretations. Depending on the requested workflow, PinkyBrain may send an AI provider the store, catalog, policy, commerce or analytics summaries, merchant instructions, prior workflow context, product images, or storefront screenshots needed to return that store-specific result.
Current code supports AI processing through OpenAI and Anthropic, with the provider and model selected by configured routing and capability rules. These providers process the submitted information to return the requested output and may maintain service logs under the applicable service-provider terms and PinkyBrain's configuration.
PinkyBrain does not use merchant or Google API data to train its own generalized foundation models. AI output may be incomplete or inaccurate and is intended to assist the merchant. Merchants are responsible for reviewing content, publishing decisions, experiments, and business actions before relying on them. PinkyBrain does not use AI to make legal, credit, employment, or similarly significant decisions about individual shoppers.
7. Storefront Analytics, Cookies, and Browser Storage
PinkyBrain uses a Shopify Web Pixel for analytics and experiment measurement. The pixel is configured for analytics, not marketing or sale of data, and runs within Shopify's strict pixel sandbox. Where Shopify requires shopper consent, the pixel receives events only in accordance with Shopify Customer Privacy signals.
- A pseudonymous Web Pixel session identifier is stored in browser local storage and rotates after approximately 30 minutes of inactivity.
- Verified experiment context used to attribute later cart or checkout activity is treated as valid for up to seven days. A stale browser copy may remain until it is overwritten or cleared, but PinkyBrain does not use it for attribution after that period.
- Experiment delivery may use a pseudonymous, HttpOnly, SameSite=Lax visitor cookie with a maximum age of one year, as well as local or session storage used to keep a shopper's assigned Slice A or Slice B experience stable.
- Server-side experiment assignments associate a pseudonymous visitor identifier with an experiment and slice. They do not require a shopper name or email address.
- Merchants and shoppers can use browser controls to clear cookies or local storage. Doing so may reset a pseudonymous session or experiment assignment.
Storefront event and session records are retained for a configured period that is currently 400 days by default, unless they are deleted earlier through shop redaction or operational cleanup. Merchant storefronts remain responsible for presenting any notices and consent controls required for their use of analytics and experiment features.
8. Google Analytics and Google API Data
Connecting GA4 is optional. If a merchant connects a property, PinkyBrain uses Google's OAuth
consent flow and currently requests only the
https://www.googleapis.com/auth/analytics.readonly scope. PinkyBrain uses this
access to list properties and data streams available to the authorized Google account and to
read reporting data for historical product, store, acquisition, and legacy experiment
measurement. PinkyBrain does not use GA4 edit access and does not create or modify GA4 custom
dimensions or unrelated Google Analytics settings.
GA4 data is used only for the connected merchant's user-facing PinkyBrain features. Aggregated GA4 metrics may be included in a PinkyBrain analysis request processed by an AI service provider solely to generate the merchant-requested, store-specific output. Merchants can disconnect GA4 in PinkyBrain; the app then attempts to revoke the Google access token and clears locally stored GA4 tokens and property identifiers. Previously derived reports or aggregates remain subject to the retention and deletion rules below.
PinkyBrain's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular, PinkyBrain does not sell Google API data, use it for advertising or lending, transfer it to data brokers, or use it to create, train, or improve generalized AI or machine-learning models beyond the merchant-requested, store-specific feature. Human access is limited to circumstances permitted by the Google API Services User Data Policy, such as explicit user consent for support, security, legal compliance, or appropriately aggregated and de-identified internal operations.
10. Sale, Advertising, and Data Brokerage
PinkyBrain does not sell merchant or shopper personal information, does not provide it to data brokers, and does not use it for cross-context behavioral advertising. PinkyBrain's Shopify Web Pixel is configured with marketing disabled and sale-of-data disabled. PinkyBrain does not use raw advertising click identifiers; it records only whether certain identifiers were present to classify acquisition without retaining the identifier itself.
11. Retention and Deletion
PinkyBrain retains information for as long as reasonably necessary to provide the service, preserve merchant-requested history, maintain security and operational records, comply with law and platform requirements, resolve disputes, and enforce agreements. Retention varies by data type and configuration.
- Storefront analytics: Web Pixel events and session rows are retained for 400 days by default and cleaned on a rolling basis.
- Protected-store passwords: encrypted only while a background capture may need to complete or retry, then cleared after success or terminal failure.
- Customer data exports: generated exports are marked unavailable after seven days by default. Download URLs are short-lived, normally about 15 minutes. Expiration of download access does not itself guarantee immediate deletion of the stored artifact; current application code removes the export record and object-storage artifact during tenant purge.
- Support screenshots: not stored by the PinkyBrain application as part of the support record, but transmitted to the email provider and support inbox, where provider and support-mailbox retention applies.
- Merchant workflows and records: store, catalog, commerce, generated content, reports, screenshots, experiment history, support tickets, model usage, logs, and related records generally remain while the account is active or until deletion is required or requested.
On uninstall, PinkyBrain immediately disables normal tenant processing and clears the Shopify
access token. Shopify subsequently sends its mandatory shop/redact request.
PinkyBrain's shop-redaction process deletes tenant data from application tables, caches, and
linked object-storage artifacts. Minimal shop lifecycle and paid-entitlement metadata may be
retained until the end of an already-paid billing period, after which the remaining retained
entitlement rows are deleted.
A Shopify customers/redact request deletes identifiable customer-linked rows from
PinkyBrain's customer, line-item, and return records for that shop. Aggregated or de-identified
measures that no longer identify the customer may remain where permitted. PinkyBrain also
responds to customers/data_request by preparing a tenant-scoped export for the
merchant. Shopify's compliance-webhook process is described in its
privacy law compliance documentation.
12. Data Security
PinkyBrain uses administrative, technical, and organizational safeguards designed to protect information. The implementation includes authenticated Shopify session tokens, webhook signature verification, tenant-scoped database access, request correlation, rate and concurrency controls, abuse detection, encrypted storage of temporary storefront passwords, protected credentials, short-lived signed download URLs, recoverable background jobs, and controlled access to infrastructure and service-provider credentials.
No transmission or storage system is completely secure. Merchants should protect their Shopify, Google, and PinkyBrain access and should avoid including unnecessary personal or confidential information in prompts, support messages, screenshots, or storefront content.
13. Rights and Choices
Merchants and authorized users
- Disconnect GA4 from PinkyBrain to attempt token revocation and clear the app's stored GA4 connection credentials.
- Use Shopify's privacy controls for Web Pixel consent and browser controls for cookies, local storage, session storage, or Do Not Track.
- Request access, correction, deletion, or restriction of information by contacting PinkyBrain, subject to applicable law and records PinkyBrain must retain.
Shopify customers and storefront visitors
A Shopify customer or storefront visitor should ordinarily submit a privacy request to the merchant whose store they visited. The merchant can route the request through Shopify, which sends PinkyBrain the applicable mandatory privacy webhook. PinkyBrain will assist the merchant and respond to valid Shopify customer-data and redaction requests as required.
Depending on applicable law, individuals may have rights to know, access, correct, delete, restrict, or object to certain processing, and to appeal or complain to a supervisory authority. PinkyBrain will not discriminate against an individual for exercising a privacy right. To make a direct request, contact support@pinkybrain.app and identify the relevant Shopify store. We may need to verify the request or coordinate with the merchant.
14. International Processing
PinkyBrain and its service providers may process information in the United States and other jurisdictions. Those jurisdictions may have data-protection laws different from the laws where the merchant or shopper is located. Where required, PinkyBrain uses appropriate contractual or other safeguards for international transfers.
15. Children's Privacy
PinkyBrain is a business application for Shopify merchants and is not directed to children. We do not knowingly collect personal information directly from children through the merchant application. Shopify merchants are responsible for their storefront audience and customer data.
16. Changes to This Privacy Policy
We may update this Privacy Policy as PinkyBrain, applicable requirements, or our service providers change. We will update the "Last updated" date and provide any additional notice or consent required by applicable law or Google API policy before using previously collected data for a materially different purpose.
17. Contact Us
Questions or privacy requests can be sent to:
PinkyBrain / Blast Commerce LLC1308 E Colorado Blvd
#3296
Pasadena, CA 91106
United States
support@pinkybrain.app