Back to Home

Privacy Policy

Last updated: April 5, 2026

Xi Yu Li Chen ("we", "us", "our") operates Buildora (the "Service"), a Shopify application and web platform for AI-powered product page generation. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

1. Information We Collect

1.1 Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Profile picture (optional, if uploaded or provided via Google OAuth)
  • Organization name and details
  • Password (stored as a secure hash — we never store plaintext passwords)

1.2 Shopify Store Data

When you connect your Shopify store, we access and store:

  • Store domain and name
  • OAuth access token (encrypted at rest using AES-256 encryption)
  • OAuth scope permissions you granted
  • Product data (titles, descriptions, images, pricing) — only for products you choose to manage with Buildora
  • Active theme information (for theme injection)

1.3 Product & Content Data

When you use Buildora to create product pages, we collect and store:

  • Source product URLs you provide
  • Scraped product data (product name, description, images, pricing from public product pages)
  • AI-generated content (HTML pages, section data, design configurations)
  • Your edits and customizations to generated pages
  • Uploaded images (product images, avatars)

1.4 Usage & Billing Data

We track the following for billing and service operation:

  • AI generation records (token counts, model used, credits consumed, timestamps)
  • Credit balance and transaction history
  • Subscription plan and billing period
  • Stripe or Shopify billing identifiers (we do not store full credit card numbers)

1.5 Customer Data

Buildora does not access, collect, or store any of your Shopify store's customer data (such as customer names, emails, addresses, or order information). Our Shopify API scopes are limited to product and theme management only.

2. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Buildora service
  • Generate AI-powered product pages based on your product data
  • Publish and sync content to your connected Shopify store
  • Process billing, manage subscriptions, and track credit usage
  • Send important service notifications (not marketing — we do not send promotional emails without consent)
  • Respond to your support requests
  • Detect and prevent fraud, abuse, and security incidents

3. AI Data Processing

Buildora uses third-party AI services (Anthropic Claude, Google Gemini) to generate product page content. When you trigger a generation:

  • Your product data (name, description, images, pricing) is sent to the AI provider to generate page content
  • AI providers process your data according to their own privacy policies and data processing agreements
  • We do not use your data to train AI models — Anthropic and Google do not use API inputs for model training
  • Generated content is stored in our database and associated with your account

4. Data Sharing & Third Parties

We do not sell, rent, or trade your personal information. We share data only with:

  • Shopify — to publish products and inject theme templates into your store (via Shopify Admin API)
  • Anthropic (Claude AI) — to generate product page content
  • Google (Gemini AI) — to generate product images
  • Firecrawl — to scrape public product pages for data extraction
  • Supabase — our database and authentication provider (data stored in Supabase-hosted infrastructure)
  • Stripe — for payment processing (Stripe handles all credit card data directly)
  • Law enforcement — if required by law, subpoena, or court order

5. Data Security

We implement industry-standard security measures to protect your data:

  • All data is transmitted over TLS/SSL (HTTPS)
  • Shopify access tokens are encrypted at rest using AES-256 encryption
  • Passwords are hashed using bcrypt via Supabase Auth
  • Database access is secured with Row Level Security (RLS) policies
  • We follow the principle of least privilege for API scope requests

6. Data Retention

We retain your data for as long as your account is active. Specifically:

  • Account data — retained until you delete your account
  • Product and generated content — retained until you delete the product or your account
  • Shopify store data — deleted within 30 days after you uninstall Buildora from your store
  • Billing records — retained as required by applicable tax and accounting laws
  • AI generation logs — retained for service operation and credit reconciliation

7. Your Rights (GDPR, CCPA & Global Privacy)

Regardless of your location, you have the right to:

  • Access — request a copy of the personal data we hold about you
  • Correction — request correction of inaccurate or incomplete data
  • Deletion — request deletion of your personal data
  • Portability — request your data in a structured, machine-readable format
  • Restriction — request we limit how we process your data
  • Objection — object to data processing based on legitimate interests
  • Withdraw consent — withdraw consent where processing is based on consent

To exercise any of these rights, contact us at hello@buildoraai.com. We will respond within 30 days.

8. Shopify Compliance

As a Shopify app, Buildora complies with Shopify's mandatory data protection requirements:

  • Customer Data Request — when a store customer requests their data, we provide any data we hold within 30 days
  • Customer Data Erasure — when a store customer requests data deletion, we erase their data within 30 days
  • Shop Data Erasure — within 30 days after you uninstall Buildora, we erase all data associated with your store

9. Cookies

Buildora uses only essential cookies required for authentication and session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies. No cookie consent banner is required because we only use strictly necessary cookies.

10. Children's Privacy

Buildora is not directed to children under the age of 16. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last updated" date. Continued use of the Service after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions about this Privacy Policy or our data practices, contact us at:

Xi Yu Li Chen

Operating as Buildora

hello@buildoraai.com