GEO Studio Privacy Policy
Last updated: August 25, 2026 · Operator: Nexcess Technologies · App: GEO Studio
This Privacy Policy describes how GEO Studio (“we”, “the app”) handles information when merchants install and use the app on their Shopify store. GEO Studio helps merchants add product schema, FAQs, and SEO copy so AI shopping assistants can understand catalog pages.
1. Information we collect
- Shop authentication data — Shopify shop domain, offline access token, and session metadata required to run the app.
- Product and storefront content — product titles, descriptions, variants, SKUs/GTINs, tags, and merchant-edited FAQ and attribute data stored as Shopify metafields and in our database.
- Optional AI keys — if a merchant pastes an OpenAI or OpenRouter API key in Settings, we store it so we can generate copy on their behalf. We do not use that key for other shops.
- Referral analytics — anonymized visit events from the theme embed (path, inferred AI referrer, timestamp) used only in the merchant admin.
- Technical logs — ordinary server logs (IP, user agent, timestamps) for security and debugging.
GEO Studio does not intentionally collect Shopify customer personal information (names, emails, addresses, or order histories) for marketing or profiling.
2. How we use information
- Authenticate the merchant and run the embedded admin app
- Generate and save schema, FAQs, attributes, and SEO copy
- Show GEO scores and AI-referral analytics
- Call the merchant’s chosen AI provider when they request generation
- Maintain security, prevent abuse, and improve reliability
3. AI providers
When a merchant uses Generate, product text they choose to send is forwarded to OpenAI and/or OpenRouter under that merchant’s own API key (or a server key the merchant has configured). Those providers process the request under their own policies (OpenAI, OpenRouter).
4. Storefront / app proxy
Product and FAQ JSON-LD is output on the merchant’s storefront via a Shopify theme app embed. A small analytics beacon may post referrer data through Shopify’s app proxy. Merchants control whether the embed is enabled.
5. Sharing
We do not sell personal data. Data may be processed by infrastructure providers that host the app (cloud VPS / database) and by Shopify as part of the platform. AI providers receive only the product context needed for a generation request the merchant initiates.
6. Retention & deletion
- When a merchant uninstalls the app, Shopify sends webhooks. We delete shop sessions and GEO Studio data for that shop (including on
shop/redact). - Metafields on Shopify products remain until the merchant deletes them in Shopify Admin.
- Merchants may request deletion by uninstalling the app or contacting support.
7. GDPR / CCPA requests
We respond to Shopify mandatory compliance webhooks (customers/data_request, customers/redact, shop/redact). Because we do not store customer PII, customer data requests typically result in confirmation that no customer records exist.
8. Security
Access tokens, optional AI keys, and app data are stored on secured servers with HTTPS in production. No method of transmission or storage is 100% secure.
9. Children’s privacy
The app is intended for Shopify merchants (businesses), not for children under 13.
10. Changes
We may update this policy. The “Last updated” date above will change when we do. Continued use of the app after changes constitutes acceptance of the updated policy.
11. Contact
Questions about privacy: suresh@nexcesstech.com
Website: nexcesstech.com
App host: geo.nexcesstech.com