🇮🇹 Italiano · 🇬🇧 English

Privacy Policy — AdPilot

Last updated: 03/07/2026
Privacy contact: jasoncurro31399@gmail.com


1. Who we are and what AdPilot does

AdPilot is an embedded Shopify application that helps merchants simulate, generate and optimize Meta (Facebook/Instagram) advertising campaigns using an artificial intelligence model. The app installs on the merchant's Shopify store and runs inside the Shopify admin.

This policy describes what data we process, why, who we share it with, and your rights. It concerns the merchants who install the app; we do not collect personal data about the store's end customers (see §3).

2. Data we process

CategoryExamplesSource
Store identifiers*.myshopify.com domain, installation ID, session/access tokenShopify (during installation/OAuth)
Catalog data (read-only)product title, description, price, images, tags, vendorShopify API (read_products scope)
Data generated in the appsimulations, campaign plans, parameters (sector, niche, country, budget, duration, objective), merchant targets (CPA/CPL/ROAS)entered by the merchant / produced by the app
Advertising performance dataCSV reports exported from Meta Ads Manager, aggregated by ad set/interest (spend, impressions, CTR, ROAS…)uploaded by the merchant
Subscription dataactive plan, payment statusShopify Billing (via webhook)

Access tokens: stored only to let the app operate on behalf of the store; never shared with third parties except as needed for technical operation (hosting).

3. End-customer data

AdPilot does not collect or process personal data about the store's end customers (names, emails, orders, addresses). The performance CSVs uploaded contain aggregated metrics (per ad set/interest), not identifiable personal data. We nonetheless respond to Shopify's mandatory GDPR compliance webhooks (see §7).

4. Why we process data (purposes and legal basis)

We do not use the data for our own advertising profiling, and we do not sell it.

5. Artificial Intelligence (Anthropic / Claude)

To generate campaign plans and analyses, the app sends prompts to an AI model provided by Anthropic (Claude), which acts as a processor/sub-processor.

Refer to Anthropic's terms for how the API processes data.

6. Third parties (sub-processors)

ProviderRoleLocation
Shopifye-commerce platform, authentication, billingper Shopify policies
AnthropicAI model (generation/analysis)per Anthropic policies
Railwayapplication and database hostingEuropean Union (Amsterdam, NL)

The production database is hosted on Railway infrastructure in the European Union (Amsterdam, NL).

7. Data retention and deletion

8. Your rights (GDPR)

You have the right to access, rectify, erase, restrict, port, and object to the processing of your data. To exercise them, write to jasoncurro31399@gmail.com. You also have the right to lodge a complaint with the competent supervisory authority (in Italy, the Garante per la protezione dei dati personali).

9. Security

We apply reasonable technical and organizational measures: encrypted connections (HTTPS), HMAC signature verification on Shopify webhooks, input validation and sanitization, per-store data isolation, and error handling that does not expose technical details to users. No system is 100% secure.

10. Minors

The app is intended for businesses (merchants) and is not directed at children under 16.

11. Changes to this policy

We may update this policy; we will publish the updated version at this address with a new "Last updated" date. Material changes will be communicated through appropriate channels.

12. Contact

For any questions about data processing: jasoncurro31399@gmail.com.