K1 ChatGPT and Claude MCP — Privacy Policy

Effective date: August 26, 2026

Controller: K1 Apps LLC, 30 N Gould St, STE R, Sheridan, WY 82801, USA
Contact: support@k1apps.com · privacy@k1apps.com

1) Scope & Roles

This policy covers K1 ChatGPT and Claude MCP (the "App"), a Shopify application that gives a merchant a single Model Context Protocol ("MCP") endpoint through which an AI assistant the merchant connects — such as Anthropic's Claude or OpenAI's ChatGPT — can read and act on that merchant's Shopify data.

Two roles apply, and the distinction matters:

  • Merchant data. For your shop configuration, organization membership, access keys, subscription state and audit journal, K1 acts as an independent controller.
  • Store data, including your customers' personal data. When the App reads or writes data in your Shopify store on your instruction, K1 acts as a processor and you remain the controller. You decide which stores are linked, which operations each access key permits, and whether an access key may see unmasked personal data.

A third role sits outside this policy. The AI assistant is connected under your account with the AI provider. When the App returns store data in response to a request from that assistant, the data is transmitted to a destination you chose, and the provider processes it under your agreement with them — not under ours. K1 does not hold your AI provider account, does not select the model, and does not control the provider's retention or training practices. See §5.

2) What we collect

From Shopify, at install and during use

  • Shop domain, shop ID, shop name, primary email, country and currency
  • The Shopify access tokens the App needs to act on your behalf (stored encrypted — see §8)
  • The identity of the staff member who installs or administers the App (account_owner and collaborator flags), used solely to decide who may change organization settings

Created by the App

  • Organization records: name, linked shops, plan, subscription and grace state
  • One-time link codes used to join a second store to an organization
  • Access keys: label, permitted operations per store, and whether personal data is returned masked or in full
  • An audit journal of operations performed through the endpoint: which key, which store, which operation, when, and the values changed
  • Webhook delivery identifiers, kept only to make Shopify's retries idempotent

Read on request, never stored as a copy

Store data requested by your AI assistant — products, orders, customers, discounts, inventory, themes, and the other resources your access key permits. This data is read from Shopify, returned to the assistant, and not retained by K1, except where an entry in the audit journal necessarily records the values an operation changed.

We do not collect payment card numbers, Shopify account passwords, or your AI provider credentials.

3) Why we collect it (Purposes & Legal Bases)

PurposeDataLegal basis (GDPR/UK GDPR)
Provide the App: authenticate, authorise, relay store dataShop identifiers, tokens, access keys, store dataContract (Art. 6(1)(b)); for store data, processing on the controller's instruction (Art. 28)
Enforce per-key permissions and plan limitsOrganization, keys, planContract
Audit journal — accountability for what an assistant didOperation recordsLegitimate interests (Art. 6(1)(f)); also your own accountability obligation
Billing and tax recordsSubscription state, shop identifiersContract; legal obligation
Security, abuse prevention, error diagnosisLogs, error reportsLegitimate interests
Service email about the AppShop primary emailContract; legitimate interests

We do not sell personal data, and we do not use store data or customer personal data to train any model, ours or anyone else's.

4) Cookies & similar technologies

The App's admin interface runs inside the Shopify admin and sets only what is needed for the session and for the App Bridge integration. It sets no advertising cookies. Where product analytics or session insight tools are used, they cover the merchant-facing admin interface only and never the store data relayed through the endpoint. See §12.

5) Disclosures to third parties

5.1 Your AI provider — the disclosure that defines this App

The purpose of the App is to make your store data available to an AI assistant that you connect. In doing so, store data — which may include your customers' names, email addresses, phone numbers, shipping addresses and order histories — leaves Shopify and leaves K1's systems, and is transmitted to the AI provider you chose.

You should understand, before granting an access key:

  • The provider processes that data under your agreement with them. Their retention, human-review and model-training terms are theirs, not ours, and you should read them.
  • K1 gives you two controls and expects you to use them: each access key permits only the operations you select, and each key carries a masked or full setting for personal data. masked is the default and partially redacts email, phone and address.
  • K1 cannot recall data once it has reached the provider.

5.2 Sub-processors

K1 engages the vendors in the Appendix to operate the App. Each is bound by written terms no less protective than this policy, and each is listed with the purpose it serves.

5.3 Other disclosures

We may disclose data where required by law, to establish or defend legal claims, or in connection with a merger or acquisition — in which case the acquirer is bound by terms at least as protective as these, and you will be notified.

6) International transfers

K1 is established in the United States and hosts the App in the European Union. Where personal data is transferred out of the EEA, UK or Switzerland, we rely on the EU Standard Contractual Clauses (2021), Module 2 (controller to processor) and Module 3 (processor to sub-processor), together with the UK Addendum / IDTA for UK-subject data. Transfers to the AI provider you connect are governed by your arrangement with that provider (§5.1).

7) Data retention

DataRetention
Store data read on requestNot retained. Held in memory for the duration of the request only
Audit journal entries12 months from the operation, then deleted
Shopify access tokensDeleted when the store is unlinked or the App is uninstalled
Shop record after uninstallRetained for the audit journal, then removed by the retention job
Organization after its last store leavesDeleted 30 days after the last store is unlinked
Link codes24 hours, or immediately on use
Webhook delivery identifiers7 days
Error and access logs90 days
Billing and tax records7 years (legal obligation)

8) Security

  • Credentials are encrypted at rest with AES-256-GCM. Encryption happens at a single boundary in the code, and the set of encrypted columns is declared in a type-checked table, so a new credential field cannot be added without being classified.
  • All traffic is served over TLS. The application processes bind to loopback and are reachable only through the reverse proxy that terminates TLS.
  • Test and production data are held in separate databases.
  • Access to production is limited to named personnel, over key-based SSH, with no shared accounts.
  • Access to personal data through the endpoint is logged in the audit journal.
  • We maintain a security incident response procedure and notify affected merchants without undue delay.

No system is perfectly secure. We do not claim certification we do not hold; see §12.

9) Your rights & how we help you

Depending on where you are, you may have rights to access, correct, delete, port, restrict or object to the processing of your personal data, and to withdraw consent where consent is the basis.

  • For merchant data (where K1 is controller): write to privacy@k1apps.com. We respond within one month (GDPR/UK GDPR) or 45 days (US state privacy laws), and may extend once where permitted, telling you why.
  • For your customers' data (where K1 is processor): the request belongs to you as controller. We assist you, and we honour the Shopify privacy webhooks in §11.

You may also lodge a complaint with your supervisory authority.

10) Your choices

  • Choose which stores are linked to an organization, and unlink any of them at any time.
  • Choose, per access key, which operations are permitted and in which store.
  • Choose, per access key, whether personal data is returned masked (default) or in full.
  • Revoke any access key immediately; revocation takes effect on the next request.
  • Uninstall the App, which deletes its tokens and unlinks the store.

11) Shopify privacy webhooks we honor

  • customers/data_request — we identify what the App holds about the named customer and provide it to you for your response.
  • customers/redact — we delete audit journal entries identifying that customer.
  • shop/redact — we delete the shop's stored data, including all sessions and tokens.

Because store data is not retained (§7), the App's exposure to these requests is limited to journal entries.

12) Details on our tools

We name our tools rather than describe them generically, so you can assess them yourself. See the Appendix. Two things we state plainly:

  • We hold no third-party security certification. We have not completed a SOC 2 or ISO 27001 audit. Where a form asks, we answer that we have not.
  • Analytics and support tools cover the merchant-facing admin interface only. They receive no store data and no customer personal data.

13) Children

The App is a business tool and is not directed at children. We do not knowingly process the personal data of children through it. Data about your customers, including any minors, is processed on your instruction as controller.

14) Changes to this policy

We will post any change here and update the effective date. For a change that materially reduces your rights or expands our processing, we will give notice through the App or by email at least 30 days before it takes effect.

15) Contact

K1 Apps LLC
30 N Gould St, STE R
Sheridan, WY 82801, USA
support@k1apps.com · privacy@k1apps.com

Related documents: Terms & Conditions · Data Processing Addendum

16) Appendix — Sub-processor List

VendorService
Shopify Inc. and affiliatesPlatform APIs, managed installation, billing and privacy webhooks
Hetzner Online GmbHCloud hosting — application, database and queue (European Union)
Sentry (Functional Software, Inc.)Error and performance diagnostics
Mixpanel, Inc.Product analytics, merchant admin interface only

Recipients that are not our sub-processors. The AI provider you connect — for example Anthropic PBC (Claude) or OpenAI, L.L.C. (ChatGPT) — receives store data at your direction, under your own agreement with that provider. They are recipients you have chosen, not sub-processors we have engaged, and we have no contract with them covering your data. This is the most important sentence in this policy.

We will update this Appendix before engaging a new sub-processor and give you the opportunity to object as set out in the Data Processing Addendum.