Privacy Policy

Last updated: February 20, 2026

1. Introduction

Maevn AI ("Maevn," "we," "us," or "our") operates the Maevn Shopify application (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when merchants install and use our App, and when their customers ("End Users") interact with stores that have the App installed.

By installing or using the App, you agree to the terms of this Privacy Policy. If you do not agree, please uninstall the App.

2. Information We Collect

2.1 Merchant Information

When you install the App, we collect:

  • Store information: Shop domain, store name, and Shopify plan details provided through the Shopify API during the OAuth installation flow.
  • API access token: A scoped access token granted by Shopify to allow the App to read product data and manage discounts on your behalf.
  • Configuration preferences: Settings you configure within the App, such as discount percentages, campaign settings, and branding preferences.

2.2 End User (Customer) Information

When customers visit a store with Maevn installed, we collect behavioral data to power AI-driven recommendations. This data is collected only after the customer has provided consent through the Shopify Customer Privacy API:

  • Browsing behavior: Pages viewed, products viewed, time spent on pages, scroll depth, and navigation patterns.
  • Cart activity: Products added to cart (used to generate relevant recommendations).
  • Interaction with Maevn popups: Whether a customer engaged with, dismissed, or clicked through a recommendation.
  • Anonymous identifiers: We generate random session and visitor IDs stored in the browser's localStorage. These are not linked to personally identifiable information.
  • Email address (optional): Only if the customer voluntarily provides their email through a Maevn popup. This is used for discount delivery and, if the merchant has enabled Klaviyo integration, synced to their Klaviyo account.

2.3 Information We Do NOT Collect

  • We do not collect payment or credit card information.
  • We do not collect personal addresses, phone numbers, or government IDs.
  • We do not use cookies. All client-side storage uses localStorage.
  • We do not track customers across different stores or websites.

3. How We Use Information

  • To provide AI-powered recommendations: Behavioral data is processed in real-time to determine the most relevant product bundles, comparisons, and offers for each visitor.
  • To generate and manage discounts: We create time-limited discount codes via the Shopify Admin API on behalf of the merchant.
  • To display analytics: Aggregated, anonymized data is shown in the merchant dashboard to help merchants understand performance.
  • To improve the App: We may use aggregated, non-identifying data to improve our AI models and App functionality.

4. AI Processing

Maevn uses Claude AI (by Anthropic) to generate personalized product recommendations. When a recommendation is triggered:

  • Product information (titles, prices, descriptions, tags) from the merchant's store is sent to the Claude API.
  • Anonymous behavioral signals (e.g., "viewed 3 products in the same category") are included for context.
  • No personally identifiable customer information is sent to the AI.
  • AI responses are not stored by Anthropic for training purposes per our API agreement.

5. Data Storage and Security

  • Database: Merchant settings and anonymized analytics are stored in a PostgreSQL database hosted on Railway (encrypted at rest).
  • Session data: Real-time visitor sessions are stored temporarily in Redis (Upstash) and automatically expire after 30 minutes of inactivity.
  • Client-side: Visitor IDs are stored in the browser's localStorage and can be cleared by the customer at any time.
  • All data transmission between the storefront, our servers, and third-party APIs uses HTTPS/TLS encryption.

6. Data Sharing

We do not sell, rent, or trade any data. We share data only with:

  • Shopify: Through the Shopify API as required to provide App functionality (creating discounts, reading products).
  • Anthropic (Claude AI): Product data (not customer PII) is sent for AI recommendation generation.
  • Klaviyo: Only if the merchant has explicitly enabled Klaviyo integration and a customer voluntarily provides their email.
  • Infrastructure providers: Railway (hosting), Upstash (Redis) — these providers process data on our behalf under their own privacy policies.

7. Data Retention

  • Session data: Automatically deleted after 30 minutes of inactivity.
  • Visitor profiles: Retained for the duration configured by the merchant (default 30 days), then automatically purged.
  • Offer history: Bundle and comparison offer records are retained for merchant analytics purposes.
  • On app uninstall: When a merchant uninstalls the App, we receive a webhook from Shopify and queue all associated data for deletion within 30 days.

8. GDPR and Customer Rights

Maevn supports Shopify's mandatory GDPR webhooks:

  • Customer Data Request: When a customer requests their data, we provide all information associated with their identifier.
  • Customer Redaction: When a customer requests deletion, we remove all associated data.
  • Shop Redaction: When a merchant's store is deleted, we remove all associated data within 48 hours.

End users who wish to clear their local Maevn data can clear their browser's localStorage at any time.

9. Consent

Maevn respects the Shopify Customer Privacy API. Behavioral tracking only begins after a visitor has provided consent for analytics tracking through the store's cookie/consent banner. If consent is not granted, no behavioral data is collected and no popups are shown.

10. Children's Privacy

The App is not directed at children under 13 (or 16 in the EU). We do not knowingly collect information from children. If we become aware that we have collected data from a child, we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify merchants of material changes through the App dashboard or via email. The "Last updated" date at the top of this page indicates when the policy was last revised.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

Email: privacy@maevn.ai