Skip to content
Maaya
How it works AI search Growth Pricing Questions
Add to Shopify
Legal

Privacy Policy

Effective 19 September 2026. Last updated 19 September 2026.

The short version

  • Maaya reads your product, collection, page and blog content so it can find and fix SEO problems. That is the whole job.
  • Maaya does not read, store or process your customers' personal data. No names, no emails, no addresses, no orders tied to a person.
  • Your product text is sent to an AI provider to write titles and descriptions. Nothing else is sent, and it is not used to train their models.
  • Uninstalling drops your access tokens immediately. Everything is erased within 48 hours, automatically, when Shopify tells us the app was removed.
  • You can ask for your data at any time by emailing support@maayaseo.com.

Contents

  1. Who we are
  2. What Maaya accesses
  3. What we store
  4. Your customers' data
  5. Your own account details
  6. AI processing
  7. Google Search Console
  8. The storefront pixel
  9. Subprocessors
  10. Security
  11. Retention and deletion
  12. Your rights
  13. International transfers
  14. Cookies
  15. Changes
  16. Contact

1. Who we are

Maaya is a search engine optimisation app for Shopify stores, operated by Jay Patel, a sole proprietor based in Anand, Gujarat, India ("Maaya", "we", "us"). Our full postal address is available on request.

This policy explains what we do with information from your Shopify store when you install and use the app. For the purposes of the UK GDPR and EU GDPR, you are the data controller for your store's data and we act as a data processor on your instructions. Where we hold your own account details in order to run the service, we are a controller for that limited purpose.

2. What Maaya accesses

When you install the app, Shopify asks you to approve a set of permissions. We request only what the features need, and each one is used for the purpose below and nothing else.

PermissionWhy Maaya needs it
read_products / write_productsRead product and collection titles, descriptions, SEO fields, URL handles and image alt text, and write back the fixes you approve.
read_content / write_contentThe same, for pages and blog posts.
write_filesReplace an oversized product image with a smaller version of itself, when you ask for it.
read_themes / write_themesCheck whether the Maaya theme extension is switched on, so structured data can be added to your storefront.
write_online_store_navigationCreate 301 redirects for broken links you choose to fix.
read_reportsRead aggregate traffic and sales totals per product per day, so the Growth page can show whether a change helped. This returns totals only, never individual orders or customers.

Maaya does not request access to customer records, checkout data, payment details, or order line items.

3. What we store

We keep a working copy of your catalogue and a record of what the app did, so the app can load quickly and so every change can be undone. In detail:

WhatWhyKept for
Your store's .myshopify.com domain and Shopify access tokenTo identify your store and make API calls on your behalfUntil uninstall
A cached snapshot of product, collection, page and blog contentSo pages load without re-reading your whole catalogue each visitRefreshed every 10 minutes; deleted at uninstall
SEO findings and AI draftsThe fix queue you review and approveUntil erasure
A log of every change the app made, with the previous valueSo any change can be undoneUntil erasure
Your settings: brand voice, tone, title and meta templates, auto-pilot preferencesTo write copy that sounds like youUntil erasure
Score history and scan countsThe trend chart on your dashboardUntil erasure
Search Console metrics per page per day, and your top search queriesThe Growth page, and measuring whether a change workedUntil erasure
Aggregate counts of AI assistant referrals and AI crawler visitsThe AI search pageCrawler counts are deleted after 180 days
Buying questions and whether your store was named in the answerTracking AI assistant visibilityUntil erasure
Monthly counts of AI runs and fixes appliedEnforcing plan limitsUntil erasure
Install, uninstall and plan change events for your shop domainOperating the business: knowing how many stores use the appAnonymised at erasure, see section 11

4. Your customers' data

Maaya does not collect, store or process personal data about the people who shop in your store. We hold no customer names, email addresses, postal addresses, phone numbers, IP addresses, payment details or individual order records.

Two features touch commerce data, and both are aggregate by design:

  • Sales performance. We read daily totals per product (net sales, order counts) to judge whether an SEO change helped. A total is not attributable to a person.
  • AI assistant referrals. We record that a visit arrived from an AI assistant and which page it landed on, as a daily count. See section 8.

Because we hold no customer data, a customers/data_request or customers/redact request from Shopify is acknowledged with nothing to return and nothing to erase.

5. Your own account details

Shopify provides the name, email address, locale and account-owner status of the staff account that installs the app. We store this so support can match an email to a store, and so we can contact you about the service. It is not used for marketing without your consent and is never sold or shared.

6. AI processing

When you press Write with AI, or when auto-pilot drafts copy for you, Maaya sends the following to our AI provider:

  • The product, collection, page or blog item's title, description, product type and vendor.
  • Your shop name, brand voice and tone settings.
  • Where available, the top search queries that already bring people to that page, taken from Search Console.

Nothing else is sent. No customer data, no order data, no access tokens, and no information about other stores. The provider returns suggested copy, which is saved as a draft for you to review. Nothing is written to your store until you approve it, unless you have switched auto-pilot on yourself.

For AI search visibility, Maaya also asks an AI model buying questions relevant to your catalogue (for example "which shops sell merino running shoes") and records whether your store was named in the answer. These requests contain the question and your shop name. They contain no customer or order data.

We use our providers' business APIs, under terms which do not permit your content to be used to train their models. We do not grant any provider the right to use your content for training.

7. Google Search Console

Connecting Search Console is optional. If you connect it, you authorise Maaya through Google's own consent screen, and we receive a token that lets us read your search performance data: clicks, impressions, average position and search queries, per page per day. We use it to show your Growth page and to measure whether changes worked.

We ask only for read access to Search Console. We never post, modify or delete anything in your Google account. You can disconnect at any time in Maaya's Growth page, or revoke access from your Google account permissions. Disconnecting deletes the stored token.

Maaya's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

8. The storefront pixel

Maaya includes an optional web pixel that measures traffic from AI assistants. Shopify attributes most assistant traffic as "direct" because the referring page is stripped before it reaches the server, so the pixel reads it in the browser instead.

The pixel reports exactly two things, and only when a visit came from a recognised AI assistant:

  • The assistant's hostname, for example chatgpt.com.
  • The path of the page the visitor landed on, for example /products/merino-runner.

It reports once per visit. It sets no cookies of its own, reads no cart or checkout data, and sends no identifier of any kind for the visitor. Visits from anywhere other than a recognised assistant are ignored in the browser and never leave it. The result is stored as a daily count, not as individual events.

9. Subprocessors

We use these providers to run the service. Each processes only what the feature requires.

ProviderPurposeWhat it receives
ShopifyThe platform the app runs on, and billingYour store data, as the source of it
OpenAIWriting SEO copy, and AI visibility checksProduct and page text, brand voice, search queries
GoogleSearch Console metrics, and PageSpeed page speed testingYour Search Console data, and public storefront URLs
Fly.ioApplication hosting and database, in the United StatesEverything listed in section 3

We will update this list before adding a new subprocessor. If you need a signed data processing agreement, email support@maayaseo.com.

10. Security

  • All traffic is encrypted in transit with HTTPS.
  • Google refresh tokens are encrypted at rest with AES-256-GCM before being written to the database.
  • Shopify access tokens are stored in our database and are never sent to the browser or to any third party.
  • Your data is scoped to your store. The app has no feature that exposes one store's data to another.
  • Database access is restricted to the application and to a small number of operator accounts.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you without undue delay and within the timeframes required by applicable law.

11. Retention and deletion

When you uninstall, immediately and automatically:

  • Your Shopify access token is deleted, so we can no longer reach your store.
  • Any stored Google token is deleted.
  • The cached copy of your catalogue is deleted.
  • Auto-pilot is switched off.

Settings, history and the change log are kept briefly, so that reinstalling within the window picks up where you left off rather than starting from nothing.

Within 48 hours of uninstalling, Shopify sends a shop/redact request and we erase everything listed in section 3 for your store. The one exception is the operator event log, which records that a store installed, upgraded or uninstalled on a given date. Those rows are kept, but your shop domain is replaced with a one-way hash, so the record of "a store left in September" survives without naming you. It cannot be reversed to identify your store.

You do not need to request any of this. It happens automatically. You can also ask us directly at any time.

12. Your rights

Depending on where you are, you may have the right to access, correct, export, restrict, or erase your personal data, to object to processing, and to complain to a supervisory authority. Under the California Consumer Privacy Act, you have the right to know what is collected and to request deletion. We do not sell or share personal information, and we never have.

To exercise any of these, email support@maayaseo.com from the address on your Shopify account, or tell us which store you are asking about. We will respond within 30 days.

If your request concerns one of your customers rather than your own data, you are the controller for that person. Because we hold no customer data, there will be nothing for us to return or erase, and we will confirm that in writing so you can complete your own response.

13. International transfers

Our servers and database are in the United States. Our AI and analytics providers may process data in the United States and other countries. Where data is transferred out of the UK or the European Economic Area, we rely on the UK International Data Transfer Addendum or the European Commission's Standard Contractual Clauses, as applicable, together with our providers' own transfer safeguards.

14. Cookies

The Maaya admin app sets no cookies of its own. It runs inside Shopify admin and authenticates using Shopify's session tokens. The storefront pixel sets no cookies and uses only short-lived browser session storage to avoid reporting the same visit twice. This marketing website sets no cookies and runs no analytics or advertising trackers.

15. Changes to this policy

If we change how we handle data, we will update this page and move the "last updated" date. For changes that materially affect you, we will tell you in the app or by email before they take effect. Continuing to use Maaya after a change means you accept the updated policy.

16. Contact

Questions, requests, or a data processing agreement: support@maayaseo.com.

Jay Patel, Anand, Gujarat, India. Full postal address available on request from support@maayaseo.com.

Maaya
Privacy Terms Support
© 2026 Maaya SEO