AgentProof Privacy Policy
Effective date: July 2026
AgentProof (“AgentProof,” “we,” “us”) is a Shopify app operated by CertPrep Studio LLC. This policy explains what data we access when a merchant installs AgentProof, what we store, and what we never do. If anything here is unclear, contact us at support@tryagentproof.com.
What AgentProof does
AgentProof helps Shopify merchants see whether AI shopping agents (like ChatGPT, Claude, Perplexity, and Gemini) are visiting their store, what those agents read, and how much revenue that traffic drives. It also generates agent-readable files (agents.md, llms.txt) from a merchant's live catalog and scores how ready a store is for AI agents to read.
Data we access
To do this, AgentProof reads the following data from a merchant's Shopify store, using the access scopes granted at install:
- Store catalog — products, collections, and policy pages (shipping, returns, privacy), used to generate agent files and calculate the readiness score.
- Order channel and attribution data — for each order, we read the sales channel, source, and customer journey signals (e.g. which channel or referrer led to the order) so we can identify orders that came from an AI shopping agent and total the revenue they represent. We read order totals and channel information — we do not read or display customer names, emails, addresses, or phone numbers as part of this feature.
Data we store
We store the minimum needed to show merchants their own results inside Shopify admin:
- Scan results — readiness scores and issue checklists from past scans, so merchants can see their history.
- Generated files — the agents.md, llms.txt, and policy content we build from a merchant's catalog.
- AI-agent visit logs — when a known AI agent fetches a store's agent files, we log the bot name, its user-agent string, the resource it requested, and a timestamp. We never log or store any information about human shoppers visiting the store — only requests we identify as coming from a recognized AI agent are recorded.
- Aggregated revenue figures — per-channel order counts and revenue totals (e.g. “$1,240 from 12 orders attributed to ChatGPT”), scoped to each merchant's own store. We do not store individual customers' personal information alongside these figures.
What we never do
- We never sell or rent merchant or shopper data.
- We never store customers' personal information (name, email, address, phone) — the features above work from aggregated order and channel data, not individual shopper identities.
- We never track human shoppers. Our traffic log only records requests we identify as coming from a recognized AI agent, never ordinary store visitors.
- We never share store or order data with third parties except the infrastructure providers (hosting and database) required to run the app, under standard confidentiality terms.
GDPR and data compliance
AgentProof honors Shopify's mandatory GDPR webhooks: customer data requests, customer data redaction, and shop data redaction. If a merchant uninstalls AgentProof, we delete all stored data associated with that store — scan history, generated files, and visit logs — within 48 hours.
Data retention
While a merchant is actively using AgentProof, we retain scan history, generated files, visit logs, and aggregated revenue figures for as long as the app is installed, so merchants can see trends over time. This data is deleted on uninstall as described above.
Changes to this policy
If this policy changes, we'll update the effective date above. Material changes will be communicated to merchants via the app or email where required.
Questions about this policy or how AgentProof handles your data? Contact us at support@tryagentproof.com. AgentProof is operated by CertPrep Studio LLC.