Effective date: August 26, 2026
Controller: K1 Apps LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA
Contact: support@k1apps.com · privacy@k1apps.com
This policy covers K1 ChatGPT and Claude MCP (the "App"), a Shopify application that gives a merchant a single Model Context Protocol ("MCP") endpoint through which an AI assistant the merchant connects — such as Anthropic's Claude or OpenAI's ChatGPT — can read and act on that merchant's Shopify data.
Two roles apply, and the distinction matters:
A third role sits outside this policy. The AI assistant is connected under your account with the AI provider. When the App returns store data in response to a request from that assistant, the data is transmitted to a destination you chose, and the provider processes it under your agreement with them — not under ours. K1 does not hold your AI provider account, does not select the model, and does not control the provider's retention or training practices. See §5.
account_owner and collaborator flags), used solely to decide who may change organization settingsStore data requested by your AI assistant — products, orders, customers, discounts, inventory, themes, and the other resources your access key permits. This data is read from Shopify, returned to the assistant, and not retained by K1, except where an entry in the audit journal necessarily records the values an operation changed.
We do not collect payment card numbers, Shopify account passwords, or your AI provider credentials.
| Purpose | Data | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Provide the App: authenticate, authorise, relay store data | Shop identifiers, tokens, access keys, store data | Contract (Art. 6(1)(b)); for store data, processing on the controller's instruction (Art. 28) |
| Enforce per-key permissions and plan limits | Organization, keys, plan | Contract |
| Audit journal — accountability for what an assistant did | Operation records | Legitimate interests (Art. 6(1)(f)); also your own accountability obligation |
| Billing and tax records | Subscription state, shop identifiers | Contract; legal obligation |
| Security, abuse prevention, error diagnosis | Logs, error reports | Legitimate interests |
| Service email about the App | Shop primary email | Contract; legitimate interests |
We do not sell personal data, and we do not use store data or customer personal data to train any model, ours or anyone else's.
The App's admin interface runs inside the Shopify admin and sets only what is needed for the session and for the App Bridge integration. It sets no advertising cookies. Where product analytics or session insight tools are used, they cover the merchant-facing admin interface only and never the store data relayed through the endpoint. See §12.
The purpose of the App is to make your store data available to an AI assistant that you connect. In doing so, store data — which may include your customers' names, email addresses, phone numbers, shipping addresses and order histories — leaves Shopify and leaves K1's systems, and is transmitted to the AI provider you chose.
You should understand, before granting an access key:
masked or full setting for personal data. masked is the default and partially redacts email, phone and address.K1 engages the vendors in the Appendix to operate the App. Each is bound by written terms no less protective than this policy, and each is listed with the purpose it serves.
We may disclose data where required by law, to establish or defend legal claims, or in connection with a merger or acquisition — in which case the acquirer is bound by terms at least as protective as these, and you will be notified.
K1 is established in the United States and hosts the App in the European Union. Where personal data is transferred out of the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses (2021), Module 2 (controller to processor) and Module 3 (processor to sub-processor), together with the UK Addendum / IDTA for UK-subject data. Transfers to the AI provider you connect are governed by your arrangement with that provider (§5.1).
| Data | Retention |
|---|---|
| Store data read on request | Not retained. Held in memory for the duration of the request only |
| Audit journal entries | 12 months from the operation, then deleted |
| Shopify access tokens | Deleted when the store is unlinked or the App is uninstalled |
| Shop record after uninstall | Retained for the audit journal, then removed by the retention job |
| Organization after its last store leaves | Deleted 30 days after the last store is unlinked |
| Link codes | 24 hours, or immediately on use |
| Webhook delivery identifiers | 7 days |
| Error and access logs | 90 days |
| Billing and tax records | 7 years (legal obligation) |
No system is perfectly secure. We do not claim certification we do not hold; see §12.
Depending on where you are, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent where consent is the basis.
You may also lodge a complaint with your supervisory authority.
customers/data_request — we identify what the App holds about the named customer and provide it to you for your response.customers/redact — we delete audit journal entries identifying that customer.shop/redact — we delete the shop's stored data, including all sessions and tokens.Because store data is not retained (§7), the App's exposure to these requests is limited to journal entries.
We name our tools rather than describe them generically, so you can assess them yourself. See the Appendix. Two things we state plainly:
The App is a business tool and is not directed at children. We do not knowingly process the personal data of children through it. Data about your customers, including any minors, is processed on your instruction as controller.
We will post any change here and update the effective date. For a change that materially reduces your rights or expands our processing, we will give notice through the App or by email at least 30 days before it takes effect.
K1 Apps LLC
30 N Gould St, STE R
Sheridan, WY 82801, USA
support@k1apps.com · privacy@k1apps.com
Related documents: Terms & Conditions · Data Processing Addendum
| Vendor | Service |
|---|---|
| Shopify Inc. and affiliates | Platform APIs, managed installation, billing and privacy webhooks |
| Hetzner Online GmbH | Cloud hosting — application, database and queue (European Union) |
| Sentry (Functional Software, Inc.) | Error and performance diagnostics |
| Mixpanel, Inc. | Product analytics, merchant admin interface only |
Recipients that are not our sub-processors. The AI provider you connect — for example Anthropic PBC (Claude) or OpenAI, L.L.C. (ChatGPT) — receives store data at your direction, under your own agreement with that provider. They are recipients you have chosen, not sub-processors we have engaged, and we have no contract with them covering your data. This is the most important sentence in this policy.
We will update this Appendix before engaging a new sub-processor and give you the opportunity to object as set out in the Data Processing Addendum.