Skip to main content
Available on Shopify The Shopify app that audits and fixes what AI reads about your products. Verity Score is on Shopify Free trial

Privacy Policy

Last updated : September 18, 2026

1. Data controller

The data controller is:

  • Company name : Verity Score
  • Legal form : Société par actions simplifiée (French simplified joint-stock company)
  • Share capital : EUR 500
  • Registered office : 138 avenue Victor Hugo, 75016 Paris, France
  • Company registration : Paris Trade and Companies Register (RCS) 108 480 583
  • SIREN number : 108 480 583
  • EU VAT number : FR68108480583
  • European identifier (EUID) : FR7501.108480583
  • President : Kamil Kaderbay
  • Email : [email protected]

For any question regarding personal data: [email protected].

No data protection officer has been appointed: the processing carried out does not fall within any of the mandatory designation cases set out in Article 37 GDPR.

2. Scope

This policy covers all Verity Score services:

  • the verityscore.io marketing website
  • the public GEO audit tool and the reports sent by email
  • the api.verityscore.io/mcp MCP server, distributed via npm, the official MCP registry and Smithery
  • the Verity Score Shopify app installed from the Shopify App Store

For the Shopify app, Verity Score acts as a processor on behalf of the merchant for personal data originating from their store. That role is governed by the data processing agreement, which prevails over this policy for such processing.

3. Data collected

Marketing website. Google Analytics 4 and the interactive help centre are loaded only after explicit consent. Consent is denied by default: no measurement cookie is set until you accept. The contact form and contact pages remain available without the widget. Conditional OpenAI Ads measurement. The shared build state is currently inactive. Only on the ChatGPT Ads campaign landing, once that state is active and after consent, measurement may send the page_viewed page event. The direct oppref click reference is not currently retained or stored, so direct click-reference attribution is unavailable. Any future consented oppref bridge will require a prior update to this policy and technical and legal review before activation. Verity intentionally sends no email address, phone number or shop domain through this page-view event. Our implementation sends {opt_out:true} to opt this event out of future user-level personalization. Automatic Advanced Matching is a function of the OpenAI Pixel: it detects, normalizes and hashes in the browser the customer information found in recognizable forms on a page. OpenAI documentation exposes no advertiser setting to turn it off. Verity neutralizes it through scope: the Pixel loads only on the campaign landing, which contains no form and no field that collects personal data. Optional measurement is denied by default and enabled only after consent; no retargeting or advertising personalization is implemented and data is not sold. The server-side counter classifies requests that declare an AI-agent identifier or carry an AI referrer. For each retained request it sends a path, a minimized source and a cohort, which are then aggregated server-side: no IP address or query string is transmitted to this API. These declarative signals can be spoofed and do not verify the bot's identity. Technical logs (IP address, User-Agent, requested URL, timestamp) are retained separately for security and abuse prevention.

Meta Ads measurement active. Only on the landing pages of our Meta (Facebook and Instagram) campaigns and after consent, the Meta Pixel records the page view and the click to the Shopify listing, with the language, the page family and the ad angle. It receives no email address, shop domain or full URL. Automatic pixel configuration is disabled and no retargeting audience is built.

App listing on the Shopify App Store. On apps.shopify.com, Shopify sends to our Google Analytics 4 property, and to our Meta Pixel when Meta measurement is active, the listing view, the click on the install button and the completed installation, together with the identifier of the installing store. This processing runs on Shopify's website under Shopify's privacy policy; we use it to count installations from our campaigns, without linking them to a person.

Audit request form. URL of the store to audit (public data), email address voluntarily provided to receive the report, first and last name if filled in, timestamp, IP address and User-Agent.

GEO audit execution. Public data only from the audited site: HTML of public pages, robots.txt, sitemap.xml, llms.txt, /.well-known/agent-card.json, JSON-LD structured data, and technical screenshots for diagnostic purposes. No customer data, account, admin area or cart is accessed: Verity Score sees only what an anonymous crawler would see.

MCP server. The parameter passed to the tool (domain name, topic or vertical) and request metadata: IP address, User-Agent truncated to 200 characters, Origin or Referer header, timestamp, tool name and response status. No email, name, authentication token or ChatGPT/Claude account access is requested.

Shopify app. Store data read through the Admin API according to the scopes granted: product catalog, collections, pages and policies, theme, languages and markets, audience reports. Subject to the merchant's explicit and separate authorization, the app may also read orders and customer events in order to measure traffic and revenue attributed to AI engines. Customer identifiers (id, email, phone) are then stored as hashes only, never in clear text.

Support chat. When you open the chat on the site: the messages you send, the email address you voluntarily provide for follow-up, any attachments you share, and the technical page context (URL viewed with sensitive parameters masked, title, timestamp, IP address and User-Agent). A session identifier is written to your browser's local storage only when you open the chat, to keep the conversation continuous. Nothing is stored or transmitted while the chat stays closed.

4. Purposes

  • Deliver the audit results, recommendations and fixes requested
  • Operate the Shopify app subscribed to by the merchant and measure their store's visibility to AI engines
  • Prevent abuse: rate limiting, protection against requests to internal resources, automated script detection
  • Measure aggregate website audience to prioritize product improvements
  • Attribute ChatGPT Ads campaign conversions on its dedicated landing when optional measurement is enabled after consent
  • Measure Meta (Facebook and Instagram) campaigns on their dedicated landing pages when optional measurement is enabled after consent, and count campaign installations through the App Store listing
  • Respond to contact requests and provide support
  • Manage subscription billing
  • Meet legal obligations and retain the necessary security logs

5. Legal bases

  • Performance of a contract or pre-contractual steps (Art. 6(1)(b)): delivering the requested audit report, operating the Shopify app subscription, billing
  • Legitimate interest (Art. 6(1)(f)): running audits on public data, service security, abuse prevention, product improvement
  • Consent (Art. 6(1)(a)): aggregate website audience measurement, loading the interactive help centre, ChatGPT Ads campaign attribution on its dedicated landing, Meta campaign measurement on their dedicated landing pages, and product communications where the corresponding box is ticked
  • Legal obligation (Art. 6(1)(c)): retention of accounting records and security logs

6. Recipients and sub-processors

Data is never sold, rented or shared for third-party marketing. It is processed by the following sub-processors, strictly necessary to operate the service:

Sub-processorPurposeLocationOutside EU
Google Cloud France SARL (Google Cloud Platform)Hosting of the website, the audit engine, the Shopify app, the MCP server, the help center and application databasesEuropean Union (Belgium, europe-west1 region)No
Cloudflare, Inc.Site delivery (CDN), DNS, TLS termination, abuse protection, and object storage (R2) for support-chat attachmentsUnited States and global edge networkYes
MongoDB, Inc. (MongoDB Atlas)Storage of audit results, contact requests and MCP server logsEuropean Union (Frankfurt region)No
Shopify International Ltd.App installation platform, merchant authentication and subscription billingIreland (Shopify Inc. group, Canada)No
OpenAI, L.L.C.Audit findings generation, assisted content drafting and AI purchase simulationsUnited StatesYes
Anthropic PBCAI purchase simulations and generative engine response testingUnited StatesYes
Google LLC (Gemini API)AI purchase simulations and generative engine response testingUnited States and European UnionYes
Perplexity AI, Inc.AI purchase simulations and generative engine response testingUnited StatesYes
Sendinblue SAS (Brevo)Transactional email delivery (audit report, service notifications)FranceNo
Notion Labs, Inc.Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or emailUnited StatesYes
Meta Platforms Ireland Ltd. (Meta Pixel)Meta (Facebook and Instagram) campaign measurement: landing page view and click to the Shopify listing, only on the dedicated landing pages and after consentIreland; transfers to Meta Platforms, Inc. (United States) under Standard Contractual ClausesYes

Conditional OpenAI Ads measurement. This measurement is not activated while the production Pixel configuration is empty, the legal build gate has not been explicitly approved, or every publication safeguard has not been completed. If it is activated after consent, only on the campaign landing, the following conditional provider is involved: OpenAI Ireland Ltd. (Ad Tools) (ChatGPT Ads campaign attribution and conversion measurement, only on the dedicated landing and after consent; Ireland; OpenAI-documented international sub-processors may be involved). Before any activation, this entry must be moved to and published in the active provider list, the required prior notice to users or clients must be completed, and the Pixel scope must be verified to contain no field that collects personal data, since no advertiser setting exists to disable Automatic Advanced Matching. This conditional disclosure is distinct from the OpenAI API entry and does not state that it is currently activated.

Meta Ads measurement active. After consent on the campaign landing pages, the following provider is involved: Meta Platforms Ireland Ltd. (Meta Pixel) (Meta (Facebook and Instagram) campaign measurement: landing page view and click to the Shopify listing, only on the dedicated landing pages and after consent; Ireland; transfers to Meta Platforms, Inc. (United States) under Standard Contractual Clauses). This entry is published in the active provider list.

Language model providers process transmitted data as processors and contractually undertake, under their API terms, not to reuse it to train their models.

The up-to-date list is also reproduced in the data processing agreement. Any change is notified in accordance with Article 28(2) GDPR.

7. Transfers outside the European Union

Some sub-processors are established in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) and, where the provider is certified, by the EU-US Data Privacy Framework. Supplementary technical measures applied are encryption in transit, minimization of transmitted data and pseudonymization of identifiers.

8. Retention periods

DataPeriod
Audit results (full report)24 months from the audit
MCP server logs (IP, User-Agent, tool, domain)Rolling 90 days
Contact or audit request email36 months from last contact
Support chat conversations (messages, email, attachments)36 months from the last message
Cloudflare and Google Cloud security logs30 days
Pseudonymized internal tracking board12 months
Shopify store data (app installed)Duration of the subscription, then 30 days
Customer data requests forwarded by Shopify30 days after handling
Accounting records and invoices10 years (Art. L123-22 French Commercial Code)

On uninstallation of the Shopify app, store data is deleted within 30 days, except where legal retention obligations apply.

The support-chat session identifier is kept in your browser until you clear the site's data.

9. Security

  • All traffic encrypted over HTTPS (TLS 1.3)
  • Security headers: HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
  • MCP server: protection against requests to internal resources, strict input validation, 10 requests per minute per IP address, Ed25519 DNS authentication for the MCP registry
  • Database access restricted by IP allow-list and strong authentication
  • Shopify customer identifiers stored as hashes, never in clear text
  • No payment data is collected or stored: app billing is operated by Shopify

10. Cookies

The website uses services and storage in three categories:

  • Strictly necessary services: site operation and storage of your consent choice. Exempt from consent.
  • Optional measurement and help services (Google Analytics 4 and interactive help centre): loaded only after explicit acceptance. The contact form remains available without the widget.
  • Conditional OpenAI Ads measurement and potential storage: only on the ChatGPT Ads campaign landing, if measurement is active and after explicit acceptance, to send the page_viewed page event. The measurement tooling is loaded only under those conditions, so any storage it triggers is conditional on them as well. The oppref reference is currently removed and is not retained or stored. Any future consented oppref bridge will require a prior update to this policy and technical and legal review before activation.
  • Meta Ads measurement: only on the landing pages of our Meta (Facebook and Instagram) campaigns and after explicit acceptance, to count the page view and the click to the Shopify listing. No retargeting audience is built.

All optional services and storage are denied by default. You can decline from the banner and change your choice at any time by clearing site data in your browser. No retargeting or advertising personalization is used and data is not sold.

11. Your rights

You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent at any time.

To exercise them, write to [email protected]. We respond within one month at most. Proof of identity may be requested in the event of reasonable doubt as to the identity of the requester.

If you are a customer of a store using the Verity Score Shopify app, please address your request directly to the merchant: they are the controller and we assist them in responding.

You may lodge a complaint with the French supervisory authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07 (cnil.fr), or with the supervisory authority of your country of residence.

12. Minors

The Verity Score service is intended for e-commerce professionals. It is not designed to knowingly collect data relating to individuals under 16.

13. Changes

This policy may be updated to reflect changes in the service or in applicable regulation. The date of last modification appears at the top of the page. Material changes are notified through a banner on the website and by email to active users.