Privacy Policy — Inutrail Reviews
Last updated: August 14, 2026
Operator: Carter Chen, an individual developer (“we”, “us”, or “our”)
Product: Inutrail Reviews (the “App”)
Website: https://inutrail.ai
Contact: [email protected]
This Privacy Policy explains how Inutrail Reviews collects, uses, stores, and shares information when merchants install and use the App on their Shopify stores, when store customers interact with review invite emails and review submission pages, and when visitors use our public marketing website at https://www.inutrail.ai.
This document is provided for transparency and Shopify App Store requirements. It is not legal advice. Privacy laws vary by jurisdiction; if you need advice on your obligations, consult a qualified lawyer.
1. Who this policy applies to
- Merchants who install Inutrail Reviews on a Shopify store
- Customers / buyers of those merchants who receive review invite emails or submit product reviews through the App
- Website visitors who browse https://www.inutrail.ai
We process customer personal data primarily on behalf of the merchant to provide review-invite and review-display services for that merchant’s store.
2. Information we collect through Shopify’s APIs
After a merchant installs the App and grants access, we use Shopify Admin APIs and webhooks with the scopes read_orders and read_products.
2.1 Order and customer-related data (via orders/fulfilled and related Admin access)
- Order ID, order number / name
- Customer email and contact email associated with the order
- Customer first name and last name (when provided by Shopify)
- Customer locale (when available)
- Line item ID, product ID, and product title / name
2.2 Shop and product data
- Shop name, myshopify domain, and shop contact email (when fetched from Shopify Admin)
- Product title, handle, and featured image URL (for invite / review context)
- App subscription / billing status (Shopify App Subscriptions)
2.3 Authentication
- Offline Admin API access tokens, stored so the App can continue to operate after the merchant leaves the admin UI (session / token storage)
We do not request scopes beyond what is needed to schedule review invites after fulfillment, send invite emails, and display product-related review context.
3. Information we collect directly from merchants
Through the App’s admin settings and APIs, merchants may provide or configure:
- Shop domain / installation identifiers
- Appearance settings (e.g. star icons, default avatar images uploaded by the merchant)
- Invite page copy and theme settings (titles, body text, labels, colors)
- Moderation settings (e.g. whether reviews require approval before publishing)
- Review invite delay (days after fulfillment before sending an invite)
- Optional manual review request details: customer email, optional customer name, and related order / product identifiers
- Billing confirmation related to the merchant’s chosen plan
Merchant contact email used for operational notices (for example quota warnings or responses to Shopify customer data requests) is typically retrieved from Shopify Admin when needed.
4. Information we collect from merchants’ customers
4.1 From order data (via the merchant’s Shopify store / webhooks)
As described in Section 2, we receive customer email, name, locale, and order / product context to create and send review invite emails after order fulfillment.
4.2 When a customer opens a review invite link
- We may record that the invite link was opened (e.g. an “opened” timestamp) for invite status tracking.
4.3 When a customer submits a review
- Display name / author name
- Star rating
- Optional review title and review body
- Linkage to the related order / line item / invite token (for integrity and privacy fulfillment)
4.4 Cookies and tracking technologies
The App’s API does not drop advertising cookies or use third-party ad / analytics tracking pixels on customer devices for marketing purposes. Authentication for merchant admin use is based on secure tokens (not advertising cookies). Storefront review display uses public read endpoints without requiring customer login cookies from us.
4.5 What we do not do with customer data
- We do not sell personal data.
- We do not use customer personal data to build advertising audiences, interest-based segments, or cross-store marketing profiles.
- Review invite emails are transactional / service messages related to a purchase and requesting product feedback—not third-party advertising campaigns.
4.6 Public marketing website (inutrail.ai)
When you visit https://www.inutrail.ai, we use Google Analytics 4 to understand aggregated site usage (for example pages viewed, approximate region, and device / browser type). Google may set cookies or similar identifiers and process this data on our behalf. We use it to improve the website, not to serve ads or build marketing audiences from App customer data.
See Google’s privacy policy and how Google uses information from sites that use its services.
5. How we use the information
We use the information above to:
| Purpose | Examples |
|---|---|
| Provide the App’s core services | Create review invites after fulfillment; send invite emails; accept and store reviews; show approved reviews on the storefront |
| Merchant configuration | Apply appearance, copy, delay, and moderation settings |
| Deliverability & abuse prevention | Process bounce / complaint signals and maintain an email suppression list so we do not keep emailing failing addresses |
| Billing & plan limits | Enforce invite quotas and Shopify subscription status |
| Legal & Shopify compliance | Respond to Shopify mandatory privacy webhooks (customers/data_request, customers/redact, shop/redact) and merchant uninstall |
| Security & operations | Authenticate API requests; monitor errors and service health via application logs |
| Improve the public website | Understand aggregated traffic and page usage on https://www.inutrail.ai via Google Analytics 4 |
We do not use personal data for unrelated advertising, sale to data brokers, or profiling for interest-based ads.
6. How we share information
We share information only as needed to operate the App:
| Recipient | Role |
|---|---|
| Shopify | Platform where the merchant’s store and OAuth / webhooks / billing run |
| Amazon Web Services (AWS) | Hosting: compute, database, object storage, email delivery (SES), scheduling, and logs — primarily in AWS region ap-northeast-1 (Tokyo) |
| Email delivery (Amazon SES) | Sending review invite emails and certain merchant operational emails (e.g. from [email protected]) |
| Neon (database provider) | Storage of merchant session / offline access tokens used by the App ecosystem |
| Vercel | Hosting of the App’s web UI / review fill pages, and of the public marketing website |
| Google LLC (Google Analytics 4) | Aggregated usage analytics on the public marketing website only |
| The merchant | Merchants can view invite and review data for their own store; for Shopify customers/data_request events we email an export to the merchant so they can fulfill the customer’s request |
We do not sell personal information. We may disclose information if required by law, or to protect the rights, safety, and integrity of the App, merchants, or customers.
7. Where data is stored and international transfers
Primary application data (reviews, review invites, shop settings) is stored and processed in AWS ap-northeast-1 (Tokyo), Japan. Related services (e.g. web UI hosting, session storage) may process data in other regions depending on those providers’ infrastructure.
If you or your customers are located in the European Economic Area (EEA), United Kingdom, or other regions with transfer restrictions, this means personal data may be processed outside the country of origin. We rely on appropriate safeguards as required by applicable law (for example contractual protections with processors). Merchants remain responsible for their own privacy notices to end customers and for deciding whether our processing locations are acceptable for their store.
8. Data retention
| Data type | Typical retention |
|---|---|
| Review invites (including customer email / name on the invite) | Generally until the invite expires (on the order of ~60 days) or is deleted via uninstall / privacy redaction; related idempotency records may be retained longer (on the order of ~180 days) via automated expiry |
| Submitted reviews | Retained while the merchant uses the App, until the merchant uninstalls, or until we fulfill a customers/redact / shop/redact request that covers that data |
| Shop settings / metadata | Settings are cleared on uninstall; a minimal shop record may remain marked as deleted |
| Email suppressions (bounce / complaint) | Retained to prevent repeated delivery to failing addresses |
| Application logs (CloudWatch) | Retained for a limited operational period (currently on the order of 14 days) |
| Uploaded merchant assets (icons / avatars in object storage) | Retained while used for the merchant’s storefront appearance settings |
When a merchant uninstalls the App, or when Shopify sends shop/redact, we delete review and invite data associated with that shop in line with our compliance handlers. When Shopify sends customers/redact, we delete matching customer-related reviews and invites for that shop.
9. Data rights of individuals
Depending on applicable law (e.g. GDPR, UK GDPR, CPRA, and similar laws), individuals may have rights to access, correct, erase, restrict, or port personal data, and to object to certain processing.
How requests are handled
- Customers of a merchant’s store should typically contact the merchant first. Shopify also routes mandatory compliance webhooks to us:
customers/data_request— we locate matching invite / review data and provide an export to the merchant (via email) so the merchant can respond to the customer.customers/redact— we delete matching customer-related data we hold for that shop.shop/redact— we delete shop-associated App data after uninstall, consistent with Shopify’s timelines.
- Merchants may contact us at [email protected] to ask about their App account data, settings, or operational concerns.
We will respond within the timeframes required by applicable law and Shopify’s compliance webhook requirements.
Note on roles: For customer personal data processed to provide the App to a merchant, we generally act as a processor / service provider and the merchant acts as the controller / business. Merchants should disclose the App in their own store privacy policy where required.
10. Children
The App is intended for use by Shopify merchants in a business context. It is not directed at children. We do not knowingly collect personal data from children for the purpose of offering services directly to them.
11. Security
We implement technical and organizational measures appropriate to the nature of the App, including encrypted transport (HTTPS), access controls for Admin APIs, HMAC verification of Shopify webhooks, and least-privilege access to cloud resources. No method of transmission or storage is 100% secure; merchants should also protect their Shopify admin accounts.
12. Marketing and advertising apps
Inutrail Reviews is a product review app. It sends post-purchase review invite emails and displays reviews. It is not an advertising network or interest-based marketing platform.
If marketing or e-privacy laws require consent or opt-out for certain email communications in your jurisdiction, merchants are responsible for ensuring their use of review invite emails complies with those laws (including any consent or transactional-email rules that apply to their store and customer base).
13. Changes to this policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Material changes may also be communicated through the App listing, App UI, or email where appropriate.
14. Contact us
Inutrail Reviews is operated by Carter Chen as an individual developer (not a registered company).
For privacy questions about Inutrail Reviews:
- Email: [email protected]
- Website: https://inutrail.ai
If you are a store customer seeking access or deletion of your data related to a purchase, please contact the merchant you purchased from; they can initiate the appropriate process through Shopify and our compliance webhooks.
Shopify App Store disclosure summary (short)
| Topic | Summary |
|---|---|
| Data from Shopify APIs | Order/customer email & name, locale, order & line item IDs, product metadata, shop contact info, access tokens |
| Data from merchants | Settings, uploaded icons, optional manual invite emails/names |
| Data from customers | Review author name, rating, title, body; invite open events; no ad cookies on App customer flows |
| Marketing website | Google Analytics 4 on https://www.inutrail.ai (aggregated usage; see §4.6) |
| Use | Provide review invites, review storage/display, billing limits, compliance, deliverability |
| Retention | Invites ~60 days (related records up to ~180 days); reviews until uninstall/redact; logs ~14 days |
| Processing location | Primarily AWS Tokyo (ap-northeast-1); other processors as listed above |
| Contact | [email protected] (Carter Chen, individual developer) |