Skip to main content
Private betaThe Shopify app that makes your products readable and verifiable by AI.Shopify app: be readable by AII want in

Privacy Policy

Last updated : August 8, 2026

1. Data controller

The data controller is:

  • Company name : Verity Score
  • Legal form : Société par actions simplifiée (French simplified joint-stock company)
  • Share capital : EUR 500
  • Registered office : 138 avenue Victor Hugo, 75016 Paris, France
  • Company registration : Paris Trade and Companies Register (RCS) 108 480 583
  • SIREN number : 108 480 583
  • EU VAT number : FR68108480583
  • European identifier (EUID) : FR7501.108480583
  • President : Kamil Kaderbay
  • Email : [email protected]

For any question regarding personal data: [email protected].

No data protection officer has been appointed: the processing carried out does not fall within any of the mandatory designation cases set out in Article 37 GDPR.

2. Scope

This policy covers all Verity Score services:

  • the verityscore.io marketing website
  • the public GEO audit tool and the reports sent by email
  • the api.verityscore.io/mcp MCP server, distributed via npm, the official MCP registry and Smithery
  • the Verity Score Shopify app installed from the Shopify App Store

For the Shopify app, Verity Score acts as a processor on behalf of the merchant for personal data originating from their store. That role is governed by the data processing agreement, which prevails over this policy for such processing.

3. Data collected

Marketing website. Audience measurement via Google Analytics 4 (Google Tag Manager), set only after consent. Consent is denied by default (Consent Mode v2): no measurement cookie is set until you accept. No advertising pixels, no retargeting, no data resale. Technical logs (IP address, User-Agent, requested URL, timestamp) are retained for security and abuse prevention.

Audit request form. URL of the store to audit (public data), email address voluntarily provided to receive the report, first and last name if filled in, timestamp, IP address and User-Agent.

GEO audit execution. Public data only from the audited site: HTML of public pages, robots.txt, sitemap.xml, llms.txt, /.well-known/agent-card.json, JSON-LD structured data, and technical screenshots for diagnostic purposes. No customer data, account, admin area or cart is accessed: Verity Score sees only what an anonymous crawler would see.

MCP server. The parameter passed to the tool (domain name, topic or vertical) and request metadata: IP address, User-Agent truncated to 200 characters, Origin or Referer header, timestamp, tool name and response status. No email, name, authentication token or ChatGPT/Claude account access is requested.

Shopify app. Store data read through the Admin API according to the scopes granted: product catalog, collections, pages and policies, theme, languages and markets, audience reports. Subject to the merchant's explicit and separate authorization, the app may also read orders and customer events in order to measure traffic and revenue attributed to AI engines. Customer identifiers (id, email, phone) are then stored as hashes only, never in clear text.

4. Purposes

  • Deliver the audit results, recommendations and fixes requested
  • Operate the Shopify app subscribed to by the merchant and measure their store's visibility to AI engines
  • Prevent abuse: rate limiting, protection against requests to internal resources, automated script detection
  • Measure aggregate usage to prioritize product improvements
  • Respond to contact requests and provide support
  • Manage subscription billing
  • Meet legal obligations and retain the necessary security logs

5. Legal bases

  • Performance of a contract or pre-contractual steps (Art. 6(1)(b)): delivering the requested audit report, operating the Shopify app subscription, billing
  • Legitimate interest (Art. 6(1)(f)): running audits on public data, service security, abuse prevention, product improvement
  • Consent (Art. 6(1)(a)): website audience measurement, product communications where the corresponding box is ticked
  • Legal obligation (Art. 6(1)(c)): retention of accounting records and security logs

6. Recipients and sub-processors

Data is never sold, rented or shared for third-party marketing. It is processed by the following sub-processors, strictly necessary to operate the service:

Sub-processorPurposeLocationOutside EU
Railway Corp.Hosting of the audit engine, the Shopify app, the MCP server and application databasesUnited StatesYes
Cloudflare, Inc.Site delivery (CDN), DNS, TLS termination and abuse protectionUnited States and global edge networkYes
MongoDB, Inc. (MongoDB Atlas)Storage of audit results, contact requests and MCP server logsEuropean Union (Frankfurt region)No
Shopify International Ltd.App installation platform, merchant authentication and subscription billingIreland (Shopify Inc. group, Canada)No
OpenAI, L.L.C.Audit findings generation, assisted content drafting and AI purchase simulationsUnited StatesYes
Anthropic PBCAI purchase simulations and generative engine response testingUnited StatesYes
Google LLC (Gemini API)AI purchase simulations and generative engine response testingUnited States and European UnionYes
Perplexity AI, Inc.AI purchase simulations and generative engine response testingUnited StatesYes
Sendinblue SAS (Brevo)Transactional email delivery (audit report, service notifications)FranceNo
Notion Labs, Inc.Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or emailUnited StatesYes

Language model providers process transmitted data as processors and contractually undertake, under their API terms, not to reuse it to train their models.

The up-to-date list is also reproduced in the data processing agreement. Any change is notified in accordance with Article 28(2) GDPR.

7. Transfers outside the European Union

Some sub-processors are established in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) and, where the provider is certified, by the EU-US Data Privacy Framework. Supplementary technical measures applied are encryption in transit, minimization of transmitted data and pseudonymization of identifiers.

8. Retention periods

DataPeriod
Audit results (full report)24 months from the audit
MCP server logs (IP, User-Agent, tool, domain)Rolling 90 days
Contact or audit request email36 months from last contact
Cloudflare and Railway security logs30 days
Pseudonymized internal tracking board12 months
Shopify store data (app installed)Duration of the subscription, then 30 days
Customer data requests forwarded by Shopify30 days after handling
Accounting records and invoices10 years (Art. L123-22 French Commercial Code)

On uninstallation of the Shopify app, store data is deleted within 30 days, except where legal retention obligations apply.

9. Security

  • All traffic encrypted over HTTPS (TLS 1.3)
  • Security headers: HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • MCP server: protection against requests to internal resources, strict input validation, 10 requests per minute per IP address, Ed25519 DNS authentication for the MCP registry
  • Database access restricted by IP allow-list and strong authentication
  • Shopify customer identifiers stored as hashes, never in clear text
  • No payment data is collected or stored: app billing is operated by Shopify

10. Cookies

The website sets two categories of cookies:

  • Strictly necessary cookies: site operation and storage of your consent choice. Exempt from consent.
  • Audience measurement cookies (Google Analytics 4): set only after explicit acceptance. Denied by default.

You can decline from the banner and change your choice at any time by clearing site data in your browser. No advertising or retargeting cookies are used.

11. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent at any time.

To exercise them, write to [email protected]. We respond within one month at most. Proof of identity may be requested in the event of reasonable doubt as to the identity of the requester.

If you are a customer of a store using the Verity Score Shopify app, please address your request directly to the merchant: they are the controller and we assist them in responding.

You may lodge a complaint with the French supervisory authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07 (cnil.fr), or with the supervisory authority of your country of residence.

12. Minors

The Verity Score service is intended for e-commerce professionals. It is not designed to knowingly collect data relating to individuals under 16.

13. Changes

This policy may be updated to reflect changes in the service or in applicable regulation. The date of last modification appears at the top of the page. Material changes are notified through a banner on the website and by email to active users.