Abbot Kinney Agency

Privacy Policy for the GiftAI Application

 

Effective Date: [Date of Launch/Acceptance]

“GiftAI” (the “App”) is a Shopify Mini application provided by Abbot Kinney Agency (“we,” “us,” or “our”). This App is designed to provide personalized gift recommendations by using AI to analyze user data provided exclusively through the Shopify Minis SDK (Shopify’s official software development kit and APIs for Shop Minis).

This policy describes how we collect, use, and handle information when you use the GiftAI App within the Shopify Shop mobile application.

1. Our Commitment to Data Minimization

As a Shopify Mini, we are committed to the principle of data minimization and strictly adhere to the Shopify Minis Guidelines.

  • We do not collect or store any Personal Identifying Information (PII) that can directly identify you (such as your name, email address, physical address, or payment details).
  • We do not track your activity outside of the GiftAI App.
  • We do not sell or monetize your data for advertising or any purpose other than providing the core recommendation service.

2. Information We Collect and How We Use It

The only information we access and process (but do not permanently store) is the data made available to us by the Shopify Minis SDK when you interact with the App.

Category of Data

What We Access/Receive

How We Use It (Purpose)

Personalized Data

Anonymized Purchase History: A list of past product purchases, accessed securely as anonymized data for analytical purposes.

Used to generate high-level, anonymized insights (e.g., “top categories: gardening, fiction books”) to personalize search queries and improve the final gift recommendation relevance.

User Input

Text Prompts: The text you type into the chat interface (e.g., “gift for my mom, loves gardening”).

Used to deconstruct your request into structured data (recipient, budget, interests) and guide the LLM’s final product curation.

Operational Data

Session ID/User Token: A non-PII token provided by Shopify to authenticate your session and link your actions to your anonymized data within the Mini.

Used solely for secure communication between the App’s front-end, the backend server, and the Shopify Minis API bridge.

3. Sharing and Disclosure of Information

We will not share your information with any third parties except in the following limited circumstances:

3.1 Third-Party AI/LLM Providers

  • We use a third-party Large Language Model (LLM) provider (e.g., Gemini, OpenAI, or similar) to perform the advanced analytical tasks described in Section 2 (Deconstruct the Prompt, Analyze History, Generate Search Queries, Final Curate).
  • Your data (anonymized purchase history and text prompts) is sent to the LLM solely for real-time processing to generate the recommendation.
  • We utilize the provider’s API offerings and contractual terms designed to prevent the use of submitted data for training public or commercial models, subject to the provider’s policies.

3.2 Legal Compliance

We may disclose your information if required to do so by law or in the good faith belief that such action is necessary to comply with legal obligations, protect our rights or property, or ensure the safety of our users.

4. Data Security

We implement reasonable technical and organizational measures to protect the information transmitted to and from our backend server (e.g., encryption during transit) and adhere to the security requirements mandated by the Shopify Minis environment. Since we do not collect or store PII, the risk of a breach involving sensitive personal data is minimized.

5. Data Retention

Because we do not permanently store PII or purchase history, there is no ongoing data retention period for this sensitive information. Your text prompts and the associated LLM analyses are deleted from our active logs shortly after the recommendation is successfully generated and returned to you, and are subject to the temporary retention policies of our LLM API provider.

6. Your Choices and Rights

Since the App is a Shopify Mini, your rights regarding the purchase history data are primarily managed by Shopify through the Shop mobile application settings.

  • If you wish to control or restrict the data made available to Shopify Minis, you must manage those settings directly within the Shopify Shop mobile application.
  • If you wish to stop using the App, simply close it within the Shop app. No further data will be accessed by the App.

7. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will notify you of any changes by posting the new policy within the App and updating the “Effective Date” at the top of this policy.

8. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:

Abbot Kinney Agency

Email: [email protected]