Privacy Policy
Last updated : August 8, 2026
1. Data controller
The data controller is:
- Company name : Verity Score
- Legal form : Société par actions simplifiée (French simplified joint-stock company)
- Share capital : EUR 500
- Registered office : 138 avenue Victor Hugo, 75016 Paris, France
- Company registration : Paris Trade and Companies Register (RCS) 108 480 583
- SIREN number : 108 480 583
- EU VAT number : FR68108480583
- European identifier (EUID) : FR7501.108480583
- President : Kamil Kaderbay
- Email : [email protected]
For any question regarding personal data: [email protected].
No data protection officer has been appointed: the processing carried out does not fall within any of the mandatory designation cases set out in Article 37 GDPR.
2. Scope
This policy covers all Verity Score services:
- the verityscore.io marketing website
- the public GEO audit tool and the reports sent by email
- the
api.verityscore.io/mcpMCP server, distributed via npm, the official MCP registry and Smithery - the Verity Score Shopify app installed from the Shopify App Store
For the Shopify app, Verity Score acts as a processor on behalf of the merchant for personal data originating from their store. That role is governed by the data processing agreement, which prevails over this policy for such processing.
3. Data collected
Marketing website. Audience measurement via Google Analytics 4 (Google Tag Manager), set only after consent. Consent is denied by default (Consent Mode v2): no measurement cookie is set until you accept. No advertising pixels, no retargeting, no data resale. Technical logs (IP address, User-Agent, requested URL, timestamp) are retained for security and abuse prevention.
Audit request form. URL of the store to audit (public data), email address voluntarily provided to receive the report, first and last name if filled in, timestamp, IP address and User-Agent.
GEO audit execution. Public data only from the audited site: HTML of public pages, robots.txt, sitemap.xml, llms.txt, /.well-known/agent-card.json, JSON-LD structured data, and technical screenshots for diagnostic purposes. No customer data, account, admin area or cart is accessed: Verity Score sees only what an anonymous crawler would see.
MCP server. The parameter passed to the tool (domain name, topic or vertical) and request metadata: IP address, User-Agent truncated to 200 characters, Origin or Referer header, timestamp, tool name and response status. No email, name, authentication token or ChatGPT/Claude account access is requested.
Shopify app. Store data read through the Admin API according to the scopes granted: product catalog, collections, pages and policies, theme, languages and markets, audience reports. Subject to the merchant's explicit and separate authorization, the app may also read orders and customer events in order to measure traffic and revenue attributed to AI engines. Customer identifiers (id, email, phone) are then stored as hashes only, never in clear text.
4. Purposes
- Deliver the audit results, recommendations and fixes requested
- Operate the Shopify app subscribed to by the merchant and measure their store's visibility to AI engines
- Prevent abuse: rate limiting, protection against requests to internal resources, automated script detection
- Measure aggregate usage to prioritize product improvements
- Respond to contact requests and provide support
- Manage subscription billing
- Meet legal obligations and retain the necessary security logs
5. Legal bases
- Performance of a contract or pre-contractual steps (Art. 6(1)(b)): delivering the requested audit report, operating the Shopify app subscription, billing
- Legitimate interest (Art. 6(1)(f)): running audits on public data, service security, abuse prevention, product improvement
- Consent (Art. 6(1)(a)): website audience measurement, product communications where the corresponding box is ticked
- Legal obligation (Art. 6(1)(c)): retention of accounting records and security logs
6. Recipients and sub-processors
Data is never sold, rented or shared for third-party marketing. It is processed by the following sub-processors, strictly necessary to operate the service:
| Sub-processor | Purpose | Location | Outside EU |
|---|---|---|---|
| Railway Corp. | Hosting of the audit engine, the Shopify app, the MCP server and application databases | United States | Yes |
| Cloudflare, Inc. | Site delivery (CDN), DNS, TLS termination and abuse protection | United States and global edge network | Yes |
| MongoDB, Inc. (MongoDB Atlas) | Storage of audit results, contact requests and MCP server logs | European Union (Frankfurt region) | No |
| Shopify International Ltd. | App installation platform, merchant authentication and subscription billing | Ireland (Shopify Inc. group, Canada) | No |
| OpenAI, L.L.C. | Audit findings generation, assisted content drafting and AI purchase simulations | United States | Yes |
| Anthropic PBC | AI purchase simulations and generative engine response testing | United States | Yes |
| Google LLC (Gemini API) | AI purchase simulations and generative engine response testing | United States and European Union | Yes |
| Perplexity AI, Inc. | AI purchase simulations and generative engine response testing | United States | Yes |
| Sendinblue SAS (Brevo) | Transactional email delivery (audit report, service notifications) | France | No |
| Notion Labs, Inc. | Pseudonymized internal tracking board (audited domain, tool called, status). No IP address or email | United States | Yes |
Language model providers process transmitted data as processors and contractually undertake, under their API terms, not to reuse it to train their models.
The up-to-date list is also reproduced in the data processing agreement. Any change is notified in accordance with Article 28(2) GDPR.
7. Transfers outside the European Union
Some sub-processors are established in the United States. These transfers are governed by the European Commission's Standard Contractual Clauses (Implementing Decision 2021/914) and, where the provider is certified, by the EU-US Data Privacy Framework. Supplementary technical measures applied are encryption in transit, minimization of transmitted data and pseudonymization of identifiers.
8. Retention periods
| Data | Period |
|---|---|
| Audit results (full report) | 24 months from the audit |
| MCP server logs (IP, User-Agent, tool, domain) | Rolling 90 days |
| Contact or audit request email | 36 months from last contact |
| Cloudflare and Railway security logs | 30 days |
| Pseudonymized internal tracking board | 12 months |
| Shopify store data (app installed) | Duration of the subscription, then 30 days |
| Customer data requests forwarded by Shopify | 30 days after handling |
| Accounting records and invoices | 10 years (Art. L123-22 French Commercial Code) |
On uninstallation of the Shopify app, store data is deleted within 30 days, except where legal retention obligations apply.
9. Security
- All traffic encrypted over HTTPS (TLS 1.3)
- Security headers: HSTS, CSP, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
- MCP server: protection against requests to internal resources, strict input validation, 10 requests per minute per IP address, Ed25519 DNS authentication for the MCP registry
- Database access restricted by IP allow-list and strong authentication
- Shopify customer identifiers stored as hashes, never in clear text
- No payment data is collected or stored: app billing is operated by Shopify
10. Cookies
The website sets two categories of cookies:
- Strictly necessary cookies: site operation and storage of your consent choice. Exempt from consent.
- Audience measurement cookies (Google Analytics 4): set only after explicit acceptance. Denied by default.
You can decline from the banner and change your choice at any time by clearing site data in your browser. No advertising or retargeting cookies are used.
11. Your rights
You have the rights of access, rectification, erasure, restriction, portability and objection, as well as the right to withdraw consent at any time.
To exercise them, write to [email protected]. We respond within one month at most. Proof of identity may be requested in the event of reasonable doubt as to the identity of the requester.
If you are a customer of a store using the Verity Score Shopify app, please address your request directly to the merchant: they are the controller and we assist them in responding.
You may lodge a complaint with the French supervisory authority, CNIL, 3 place de Fontenoy, TSA 80715, 75334 Paris CEDEX 07 (cnil.fr), or with the supervisory authority of your country of residence.
12. Minors
The Verity Score service is intended for e-commerce professionals. It is not designed to knowingly collect data relating to individuals under 16.
13. Changes
This policy may be updated to reflect changes in the service or in applicable regulation. The date of last modification appears at the top of the page. Material changes are notified through a banner on the website and by email to active users.