Honeypaw SEO Privacy Policy

Effective date: October 9, 2026

Honeypaw SEO ("we", "us") is a Shopify app. It helps Shopify merchants choose the pages they want to grow (products, collections, blog posts, pages and the home page), research the searches those pages should rank for, improve their SEO titles, meta descriptions, product titles and image alt text, and track how they rank in Google, appear in Google's AI Overviews, and come up in ChatGPT and Gemini answers. It also shows which sales came from visitors referred by AI assistants.

This policy explains what data the app accesses, why, where it goes, how long we keep it, and how to have it deleted. It applies to the app and to honeypawseo.com.

1. Who this policy covers

2. Data we access from Shopify

When you install the app, you grant it these Shopify permissions: read_products, write_products, read_orders, read_locales, read_content and write_content.

2.1 Store details

Store name, myshopify.com domain, primary (custom) domain, currency, billing country, and store languages. We use these to pick the right search market and language and to label your data.

2.2 Products, collections, blog posts and pages

We use these to suggest searches for each page, check how each page ranks, and propose better titles, descriptions and alt text.

2.3 Changes the app makes

The app changes your store only when you click to apply a change. It can write SEO titles and meta descriptions (products, collections, blog posts and pages), product and collection titles, and product image alt text. We keep a change log of each write: what changed, the value before and after, the page's search rank at the time, and when. You can see the log in the app and undo changes from it.

2.4 Orders (no customer details)

The app reads paid orders from the last 60 days. From each order it reads only the order ID, date, order total, the products bought (product ID, quantity and amount), and how the visit that led to the order began: the landing page, the referring website and the marketing source.

We use this to:

The app does not request or use customer names, email addresses, phone numbers, shipping or billing addresses, or any other information that identifies the people who bought from your store.

2.5 App session data

To connect to your store, Shopify gives the app an access token and a refresh token to renew it. We store these with your store domain and the permissions you granted, as Shopify's app framework requires. The app uses store-level sessions only, so it does not store the names or email addresses of your staff.

2.6 Billing

Plans are billed through Shopify. We see which plan your store is on and whether it is in a trial. We do not see or store card details.

3. Data you enter in the app

4. Data we access from Google (Search Console)

Connecting Google Search Console is optional. If you connect it, the app asks Google for one permission:

With it, the app reads, for the Search Console property you choose:

We use this data only to show you, inside Honeypaw SEO:

The app cannot change anything in your Search Console account. It does not read data for properties you do not choose.

What we store. We store the Google access and refresh tokens, encrypted with AES-256. From the Search Console data we store each search, the page that ranks for it and its position, as part of your store's rank history. We use impressions to decide which searches matter most, and do not store clicks or impressions.

Who else receives it. To show the search volume and difficulty of the searches your store appears for, we send the search text (not your clicks, impressions or positions) to our keyword data provider (section 5). We also check the most important ones in Google's results to see whether an AI Overview links to your store.

Disconnecting. You can disconnect Google at any time in the app's settings. We then delete the stored tokens and revoke the app's access at Google. Positions already recorded stay in your store's rank history until you uninstall the app (section 7). To have them deleted sooner, email support@honeypawseo.com. You can also revoke access at any time at https://myaccount.google.com/permissions.

4.1 Google API Services User Data Policy

Honeypaw SEO's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, for data we receive from Google APIs:

  1. We use it only to provide and improve the user-facing features described in section 4, which are visible in the app's interface. We do not use it for any other purpose.
  2. We do not transfer it to others except as needed to provide or improve those features (our hosting provider stores it, and our keyword data provider receives search text to return search volume and difficulty, as described above), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
  3. We do not use or transfer it to serve ads, including retargeting, personalized, or interest-based advertising.
  4. We do not sell it, and we do not transfer it to data brokers or information resellers.
  5. We do not use it to determine credit-worthiness or for lending purposes.
  6. We do not use it to develop, improve, or train generalized or non-personalized AI or machine-learning models.
  7. No person on our team reads it unless:
    • you give us explicit permission to read specific data (for example, when you ask for support with a specific problem);
    • it is necessary for security purposes, such as investigating abuse or a security incident;
    • it is necessary to comply with applicable law; or
    • the data is aggregated and anonymized and used for internal operations, in line with applicable privacy and legal requirements.

5. Who processes data for us

We use these service providers. Each receives only what it needs to do its job.

ProviderWhat it doesData it receives
ShopifyHosts the app inside your admin; processes plan billingAs described in Shopify's own privacy policy
Hosting providerRuns the app's servers, hosts its database and keeps server logsAll app data, as our infrastructure provider
Keyword data providerKeyword and search data: search volume, cost per click, related searches, the searches your store's domain ranks for, Google search results and AI Overviews, and answers from ChatGPT and GeminiSearch phrases (taken from your page titles, product types, vendors and tags, searches you type, and the searches your store appears for in Search Console), your store's public domain, the questions you check in ChatGPT and Gemini, and your chosen country and language. It does not receive order data, revenue, customer data, or your Search Console clicks, impressions or positions.
Font providerServes the fonts used in the app's screensYour browser's IP address and browser details, when the app loads

To check how ChatGPT and Gemini answer a question, our keyword data provider asks those assistants the question on our behalf. It does not send your store's name or domain with the question; we look for your store in the answers ourselves.

The app writes its title, description and alt-text suggestions from templates. It does not send your data to any AI model provider to write them.

We do not sell data. We do not share data with advertisers.

Shared keyword data. Keyword metrics we buy from our keyword data provider (for example, "linen dress: 12,100 searches a month in the US") are public market data. We keep them in a shared store so that a search looked up for one store does not have to be bought again for another. A search phrase, including one from your Search Console data, can stay in this shared store with its public metrics after your store's data is deleted. It is not linked to your store, and other stores see it only if they look up the same search themselves.

6. How long we keep data

DataKept
Store, page, keyword, rank, AI answer and change-log dataWhile the app is installed. Deleted 48 hours after you uninstall (section 7).
Product revenue totalsRecalculated from the last 60 days of orders. Deleted 48 hours after you uninstall.
Daily AI-assistant sales totalsWhile the app is installed. Deleted 48 hours after you uninstall.
Keyword explorer history90 days
Search Console positionsAs part of your rank history while the app is installed. Deleted 48 hours after you uninstall, or sooner on request.
Google tokensUntil you disconnect Google or uninstall.
Usage and cost records (store domain, which service was used, units and cost, no store content)Kept for our accounting and billing records.
Server logsUp to 7 days
Database backupsUp to 30 days
Support emailsUp to 2 years after your request is resolved

7. Deleting your data

When you uninstall the app, Shopify notifies us. We immediately delete your store's access token and session, disconnect Google Search Console (deleting the tokens and revoking access at Google), cancel pending background work, and end your plan. If you reinstall within 48 hours, your data is restored.

48 hours after you uninstall, Shopify sends us a deletion request (shop/redact) and we delete all remaining data linked to your store: store details, pages, keyword assignments, rank history including Search Console positions, AI questions and answers, sales totals, the change log, explorer history and settings. We keep only the usage and cost records described in section 6 and the shared keyword data described in section 5.

Uninstalling does not undo SEO changes the app applied to your store. Those are your store's content. Undo any changes you want reversed from the in-app change log before uninstalling.

Shopify privacy requests. Shopify sends apps three mandatory privacy webhooks:

On request. Email support@honeypawseo.com from the store owner's email address to ask what data we hold about your store, or to have it deleted. We will reply within 30 days.

8. Security

No system is perfectly secure. If we learn of a breach that affects your data, we will notify you and, where required, the relevant authorities, without undue delay.

9. Your rights

Depending on where you live (for example, under the GDPR in the EU/UK or the CCPA in California), you may have the right to access, correct, delete, or export personal data we hold about you, and to object to or restrict its use. Email support@honeypawseo.com to make a request. You may also complain to your local data protection authority.

For data about a store's customers, the merchant is the controller and we act as a processor on the merchant's behalf. As described above, the app does not store data that identifies customers.

Our servers and providers operate in the United States and other countries. By using the app, your data may be processed outside your country. Where the law requires it, we rely on our providers' standard contractual clauses for these transfers.

10. Children

The app is for businesses. It is not directed at children, and we do not knowingly collect data from children.

11. Changes to this policy

We will post changes on this page and update the effective date. If a change materially affects how we use your data, we will tell you in the app or by email before it takes effect.

12. Contact

Email: support@honeypawseo.com
Website: https://honeypawseo.com