Legal
Privacy Policy
Effective 8 September 2026.
Siddesh Patil ("Citelift", "we") builds software that connects to Shopify and, for invited beta stores, WooCommerce and WordPress. It writes and publishes SEO articles to a merchant's own site and measures whether AI assistants cite that store. This policy explains what the service holds, why, for how long, and how to make us delete it.
We do not sell personal data, and we do not share it for advertising. No third-party advertising or analytics pixels run on this site or inside the embedded app.
Who the controller is
For the marketing site, the AI-visibility check and our own email, Siddesh Patil is the controller. For everything the app does inside a merchant's store, the merchant is the controller and Siddesh Patil is the processor acting on their instructions — the terms of that arrangement are in our Data Processing Addendum.
What we collect
From a merchant's Shopify store, once the app is installed
- The shop domain, plan, locale, primary market and timezone.
- The product catalog: titles, handles, descriptions, tags, prices, images and collection membership. Used to plan topics and to link articles to products.
- Blog content the app creates: articles, summaries, artwork, schema markup and the internal links between them.
- Order journey fields only, for orders placed after install: the order id, total, currency, landing page, referrer and UTM parameters. This is what lets the app say which article produced which sale. We do not read or store customer names, email addresses, phone numbers or shipping addresses. These rows are deleted 90 days after the order.
- Search Console metrics — clicks, impressions and average position for the pages the app published — where a merchant chooses to connect their property. The connection is read-only and can be revoked from Settings at any time.
From an invited WooCommerce and WordPress beta store, once its administrator approves the connector
- The canonical site and API addresses, WordPress installation identity, connector and protocol versions, connection health, and encrypted scoped service credential. We do not ask for or store the administrator's password.
- WooCommerce product and variant facts, prices, availability and media used to prepare articles, plus Citelift-managed WordPress posts and media.
- Order id, total, currency, article id and consent-aware attribution fields when tracking is enabled. We do not need customer names, email addresses, phone numbers or postal addresses for this reporting.
- Subscription state and provider identifiers needed to verify hosted checkout, renewal, payment failure and cancellation. Card details are collected by the payment provider and are not sent to Citelift.
From visitors to this site
- When you create a Citelift web account, Clerk, Inc. runs sign-in for us: it holds your email address, the credentials or social sign-in you chose, and the session token your browser keeps signed in with. Citelift stores your account reference and verified email; a password never reaches us. Clerk is listed on the Subprocessors page.
- For historical reports, the email address you give to unlock a full AI-visibility report, together with the domain you checked, the campaign parameters on the link that brought you, and the timestamps of your consent, confirmation and any unsubscribe.
- Historical checks retain the domain and questions previously asked. The authenticated free AI check stores your account reference, store domain, brand, product type, market, questions, answers, source links and provider usage receipts so you can reopen the same report. Generic product questions and the market are sent through OpenRouter to GPT-5 nano with native web search; your email is not included in the model request. A keyed email fingerprint and the lifetime-use record prevent repeat free runs across accounts using the same verified email. We retain this minimal anti-abuse record when report content is erased. The public AI visibility check, which needs no account, stores the store domain, the brand name and category used, the questions, the answers, their source links and provider cost receipts, under a link anyone holding it can open; the domain and the questions are sent to DataForSEO, and TypeSafe may be sent the domain, brand, homepage title and description and an answer excerpt. To enforce the daily limit it keeps a salted hash of your IP address with each check; the address itself is not stored. The separate manual citation checker analyzes pasted answers locally in your browser and does not upload those answers. The writing tools also run locally when JavaScript is enabled; their no-JavaScript fallback processes drafts on the server without storing them or sending them to a model. When the public check is on, the homepage form sends the domain to the public check, which stores it with the check as described above; when it is off, the form opens the checker page with the domain in its URL.
- Email me this result. If you ask for a public check result to be emailed, we store the address you typed and the domain checked. Each request sends that address one transactional email with the result's link, through Resend, our email provider; nothing else is sent to it. The address is deleted after 30 days; if you unsubscribe, it is kept only to honour that unsubscribe, for the period in the table below.
- Public page-load counts are sent by the page to citelift.app once it has loaded, and contain a known page path and a broad referral category, such as Google, an AI service, another site or unavailable. When the link that brought you carries campaign tags (
utm_source,utm_medium,utm_campaign), those tags are kept too, with whether the click came from a Google or a Meta ad — never the ad click identifier itself. The same campaign tags are kept when you press an install button, and any campaign tags or ad click identifier on that install link are passed on to our Shopify App Store listing so Shopify can attribute an install. We do not send your IP address, browser identifier, full referring URL, any other page query parameter or tool inputs with these counts. Each count does carry a daily visitor number computed on our server: your IP address and user-agent string are hashed together with a secret that is replaced every 24 hours, and only that hash is sent. The hash cannot be reversed to your IP address, and it cannot be matched to the number you were given on any other day, so it supports a count of how many people read a page on one day and cannot support return-visit, session, journey or cross-day profiling. No cookie or other identifier is stored on your device for these counts. Requests expressing Do Not Track or Global Privacy Control are excluded, and are never given a visitor number. - Website analytics on public pages. A small script served from citelift.app runs on our public pages only — never in the signed-in workspace, the embedded Shopify app or a private report link. It reports the page address without its query string, the site that linked you here (its domain only, never the full address), your browser, operating system, device type and screen size, when you leave the page, and page-loading speed measurements (Core Web Vitals), and — if the advertising prompt is shown — that it was shown and which answer you gave. These go through citelift.app to PostHog. The script sets no cookie and stores nothing in your browser. PostHog tells one visit from another with a number it works out on its own servers from your IP address and browser user-agent string and a salt it replaces daily; the number cannot be turned back into your IP address and cannot connect one day's visits to another's. No location is looked up. The script does not record your screen, your clicks or keystrokes, or anything you type into our tools, and it does not load at all if your browser sends Do Not Track or Global Privacy Control. Anonymous tool-completion requests send only the tool name and outcome (or a successful file-copy count), without tool inputs or a browser identifier. When you follow a signup journey, a validated Citelift page path may accompany account creation; this is not cross-visit tracking and does not retain arbitrary referrer URLs or query values. These measurements also respect Do Not Track and Global Privacy Control. Existing product events, such as an install or a publication, use a store or domain identifier. See our Cookie notice.
Why we use it, and on what basis
| Purpose | Basis (UK/EU GDPR) |
|---|---|
| Running the app a merchant installed: planning, writing and publishing articles | Contract (Art. 6(1)(b)), on the merchant's instructions as processor |
| Attributing orders to articles, so the merchant can see the return | Contract, and the merchant's own legitimate interest as controller |
| Serving free tool pages and requested AI-visibility reports | Legitimate interest (Art. 6(1)(f)): answering a request you made |
| Sending your report and product updates by email | Consent (Art. 6(1)(a)), given by ticking the box and confirming the address |
| Billing, invoicing and fraud prevention | Contract, and legal obligation |
| Keeping the service secure and diagnosing faults | Legitimate interest |
Who else processes it
We use a small number of vendors, each under a written data processing agreement. The current list, with purpose and region, is on the Subprocessors page, which is the page we update — and give notice from — when it changes.
Where an invited WordPress store uses Dodo Payments checkout, Dodo processes the payment method and billing details under the notices shown in its hosted checkout. Citelift receives subscription and payment status, not card details.
How long we keep it
| Data | Retained |
|---|---|
| Order journey fields (order id, total, currency, landing page, referrer, UTM) | 90 days |
| AI-visibility runs and reports | 180 days |
| Model-call cost ledger (no content, no personal data) | 365 days |
| Email addresses that never confirmed | 30 days |
| Email addresses after an unsubscribe | 24 months, then deleted |
| Everything belonging to a disconnected or uninstalled store | Erased 30 days after uninstall or verified deletion request, sooner where the in-product deletion flow confirms it |
| Articles the app published to a merchant's blog | The merchant's own content, on their store, indefinitely |
A nightly job enforces these periods and records what it deleted. Uninstalling schedules the erasure of everything belonging to the store for 30 days later; reinstalling inside that window cancels it, so a merchant who reauthorises after a scope change does not lose their articles and plan. Erasure requested through Shopify's shop/redact webhook, or asked for in the app's settings, is carried out immediately.
Your rights
If you are in the UK, EU, or a jurisdiction with comparable law, you may ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or hand it to another provider. You may withdraw consent to email at any time — every message carries a one-click unsubscribe link, and using it does not affect anything you were sent before.
Write to siddesh@citelift.app and we will answer within 30 days. If a merchant's customer contacts us directly about data in a merchant's store, we will refer them to the merchant, who is the controller of it.
You also have the right to complain to your data protection authority.
International transfers
Our infrastructure runs in the United States. Where data moves out of the UK or EEA we rely on the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum, referenced in our DPA.
Security
Access tokens are encrypted with AES-256-GCM before they are written, on top of the AES-256 encryption our database provider applies at rest. All traffic runs over TLS. Administrative access requires two-factor authentication, and secret values are masked before anything is logged. More detail is in the security annex of the DPA.
Children
The app is sold to businesses. It is not directed at anyone under 16, and we do not knowingly collect their data.
Changes
We will post any change here and update the effective date. A material change is announced to merchants in the app and by email at least 30 days before it applies.
8 September 2026. The data of an uninstalled store is now erased 30 days after uninstall rather than 48 hours, and reinstalling inside that window keeps it. A merchant reauthorising after a scope change was losing their catalog, plan and article history to a window too short to come back through. Thirty days is the outer limit Shopify allows, it is stated here and in the DPA, and erasure on request — in the app's settings, or through Shopify — is still immediate.
Contact
- Siddesh Patil
- siddesh@citelift.app