Privacy policy
Last updated 13 August 2026
LnqAI ("the App") is operated by Web Cube, LLC ("we", "us"). This policy explains what the App collects when you install it on your Shopify store, why, and what we do with it.
1. What the App accesses from your store
When you install LnqAI, you grant it read-only access to:
- Products — titles, descriptions, variants, prices, images, product types, vendors, and metafields
- Inventory — stock levels and availability
- Legal policies — your published store policies, used to populate the return-policy field OpenAI's feed format requires
The App requests read-only scopes (read_products,read_inventory, read_legal_policies). It cannot create, modify, or delete anything in your store.
The App does not access customer records, orders, checkout data, payment information, or any other personal information about your customers.
2. What the App stores
We store only what is needed to generate and deliver your feed:
| What | Why |
|---|---|
Your store's .myshopify.com domain | Identifies your installation |
| Shopify session and offline access tokens | Lets the App read your catalog on a schedule without you being logged in |
| Feed configuration — default brand name, brand metafield namespace and key, return-policy URL, target countries, product eligibility flags | Your setup choices |
| Last-run status and timestamps | So you can see whether the last feed run succeeded |
| Your OpenAI SFTP credentials — host, port, username, and password | Needed to deliver the feed to OpenAI on your behalf |
Product data is not retained. Your catalog is read, transformed into the feed file, and delivered. The feed is generated in memory and pushed; we do not keep a copy of your product data on our servers.
We store no personal information about your customers. Not their names, addresses, emails, orders, or any other identifier.
3. How your credentials are protected
Your OpenAI SFTP password is encrypted at rest in our database using field-level encryption. It is decrypted only at the moment a feed is delivered, and is never displayed back to you in the App interface after you save it.
Access tokens issued by Shopify are stored in our database and used solely to read your catalog for feed generation.
4. Who we share data with
We do not sell your data, and we do not share it for advertising purposes.
We share data only with the service providers required to run the App:
- OpenAI — receives the product feed file you configure and choose to send. What it contains is determined by your setup and by OpenAI's feed specification.
- Heroku — hosts the App and its database, and therefore stores the configuration described above.
We may disclose information if required by law.
5. Where data is processed
The App and its database are hosted in the United States. If you are outside the United States, your configuration data is transferred to and processed there.
6. How long we keep data
Configuration and credentials are kept for as long as the App is installed.
When you uninstall LnqAI, Shopify sends us an app/uninstalled webhook and we delete your stored configuration, credentials, and access tokens. We also honour Shopify's mandatory shop/redact request, which arrives 48 hours after uninstall, by removing any remaining record of your shop.
Because we hold no customer personal information, customers/data_request andcustomers/redact requests return no data — we respond to confirm there is nothing to provide or erase.
7. Your rights
Depending on where you are located, you may have the right to access, correct, export, or delete the information we hold about your store, and to object to or restrict its processing.
To exercise any of these, email support@lnqai.io. You can also delete everything immediately by uninstalling the App.
If you are in the EEA or UK, our legal basis for processing this data is performance of our contract with you — we cannot generate your feed without it.
If you are in California, note that we do not sell or share personal information as those terms are defined by the CCPA.
8. Children
The App is a business tool for merchants. It is not directed at anyone under 16 and we do not knowingly collect information from them.
9. Security
We use encryption in transit (HTTPS, and SFTP for feed delivery) and field-level encryption at rest for stored credentials. No system is perfectly secure, but we take reasonable measures appropriate to the sensitivity of what we hold.
10. Changes
If we change this policy materially, we will update the effective date above and, where the change affects how your data is handled, notify you in the App.
11. Contact
Web Cube, LLC
P.O. Box 712733
Santee, CA 92072
support@lnqai.io