Privacy Policy
What we hold, what we don't, and who else sees it
Mercopilot connects to your Shopify store and works through the AI assistant you already use. That means data moves between three places — your store, us, and your assistant — and this page is about which parts stop here.
- Effective
- July 29, 2026
- Last updated
- July 29, 2026
This policy covers mercopilot.com, the Mercopilot dashboard, and the Mercopilot MCP server at https://api.mercopilot.com/mcp. "We" and "us" mean Mercopilot. If anything below is unclear, email [email protected] and we will explain it in plain words.
1. What we collect
Your account
- Email address. Required — it is the identifier you sign in with, and how we reach you about your subscription.
- Name. Optional, and only if you give us one.
- Passkeys. For each passkey you register: its public key, its credential id, a signature counter, and the device label shown in your account. There is no password on a Mercopilot account, and the private half of a passkey never leaves your device — we could not read it if we wanted to.
- Google sign-in, if you use it. Your Google account id, the email address on it, and your profile picture URL. We do not receive your Google password, and we ask Google for nothing beyond who you are.
- Sessions. A one-way hash of each login token — not the token itself — with its expiry, when it was last used, and the browser user-agent string it was issued to, so you can recognise your own sessions.
Stores you connect
- The store's name, its
.myshopify.comdomain, its Shopify store id, and the contact email Shopify holds for it. - The access token Shopify issues when you approve the install. This is what lets us read the store, and it is only ever used to answer a request you or your assistant made.
What your AI assistant does
Every call an AI client makes to our MCP server is logged, and you can read the same log yourself under Activity in your dashboard. Each entry holds the client's name, the store it concerned, the tool that ran, the arguments it was given, whether it succeeded, how long it took, and the error message if it failed.
Arguments are stored; results are not. The record shows that your assistant asked to set a product's price to $24, not what the analysis it ran came back with. We keep this so that there is an account of anything that changed your store, and so you can see which assistant did it.
Billing
Payments are handled by Polar, who take the card details on their own hosted page. We never see or store a card number. What we keep is the subscription itself: its status, the amount and currency, the billing period, the dates it runs between, and the ids Polar uses to identify it.
The website
Our servers log ordinary request data — IP address, browser, and the pages requested — as any web server does. See cookies and analytics below for what runs in your browser.
2. Your store's data stays in your store
This is the part most worth reading. When you ask your assistant something, we call Shopify at that moment, work out the answer, and return it. We do not copy your catalog, your orders, or your inventory into a database of our own — there is no warehouse of your store here to leak, and nothing to go stale.
We never ask Shopify for your customers. Order data is read for totals and line items only; the customer attached to an order is deliberately left out of every query we make. Names, email addresses, and shipping addresses of the people who buy from you do not reach us.
The install asks Shopify for these permissions, and no others:
- read_products — Read your catalog — titles, descriptions, prices, status.
- read_orders — Read order and line-item totals to work out what is selling.
- read_inventory — Read stock levels to spot stockouts and slow movers.
- read_discounts — See which discounts are already running before suggesting another.
- write_products — Apply an approved change to a price, title, description, or publish state.
- write_inventory — Apply an approved stock adjustment.
- write_discounts — Create an approved discount code.
3. What your AI assistant's provider sees
Mercopilot is the tool; the assistant is yours. When Claude, ChatGPT, or any other MCP client calls us, our answer goes back to that client — which means it passes through, and is handled by, whoever makes it. Their privacy policy governs that half of the conversation, not ours. If your assistant asks us which products are slow movers, that list is now in your chat with them.
The reverse is worth saying too: we do not send your store data to an AI model. Every analysis and recommendation Mercopilot produces is computed on our own servers from the figures Shopify returns. We are not an OpenAI or Anthropic customer passing your numbers along; your assistant is the only model involved, and you chose it.
Authorizing an AI client also creates a record of that client — the name it registered under, the addresses it may return to, and the access tokens issued to it.
4. How we use it
- To run the service: answer your assistant's requests, and make the changes you approve.
- To sign you in and keep you signed in.
- To take payment and manage your subscription.
- To show you your own activity log.
- To keep the service up and secure, and to debug it when it breaks.
- To email you about your account or a material change to this policy.
We do not sell your data, we do not share it with advertisers, and we do not use your store's figures to train anything.
5. Who else handles it
Four services, each for one job:
- Shopify — The store you connect. We hold the access token Shopify issues and read your store through it.
- Polar — Payments and subscriptions. Your payment details go to Polar, never to us. We keep the subscription’s status and amount.
- Google — Optional sign-in, and website analytics. If you sign in with Google, your Google account id, email, and profile picture. Analytics covers the marketing pages only.
- Our hosting and database providers — Running the service. Everything described above is stored on servers we rent.
Beyond those, we disclose data only where the law requires it, and if Mercopilot is ever sold or merged, the account records would transfer with it — we would tell you before that happened.
6. Cookies and analytics
Signing in does not set a cookie. Your login token is kept in your browser's local storage and sent to our API with each request; clearing your browser data signs you out.
Our marketing pages use Google Analytics to count visits and see which pages are read. It measures traffic in aggregate — it is not tied to your account, and it does not run on the dashboard. Browser settings and extensions that block it work fine here; nothing on the site depends on it.
7. How long we keep it
Account details, connected stores, and your activity log are kept for as long as your account exists. Sessions and the short-lived codes issued during sign-in expire on their own. Billing records outlive the account where tax and accounting rules require it.
Uninstalling Mercopilot from your Shopify admin cuts off our access to that store immediately — the token stops working the moment you do it. Email us if you also want the store record removed from your account.
8. Security
Everything travels over HTTPS. Login tokens are stored only as hashes, so a copy of our database does not hand anyone a working session. Sign-in is passwordless by design: passkeys cannot be phished or reused across sites, and there is no password of yours for us to lose. Sessions expire after 30 days and you can revoke them by signing out.
No system is perfect. If we ever discover a breach affecting your data, we will tell you what happened and what to do about it.
9. Your choices
You can ask us to:
- Show you everything we hold about you.
- Correct anything that is wrong.
- Delete your account and the data attached to it.
- Send you a copy in a portable format.
There is no self-serve delete button yet, so these go through [email protected]. We will confirm within 30 days. Depending on where you live you may also have a statutory right to complain to a data protection authority; nothing here is meant to limit that.
In your dashboard today you can remove a passkey, disconnect your Google account, sign out everywhere, and cancel your subscription without asking anyone.
10. Children
Mercopilot is a tool for running a business and is not directed at children. We do not knowingly collect data from anyone under 16.
11. Where your data is held
Our servers, and the services listed above, may be located in a different country from you — including outside your own. Using Mercopilot means your data may be processed there.
12. Changes to this policy
When we change this page we update the "last updated" date at the top. If a change materially affects what we collect or who sees it, we will email account holders rather than rely on you noticing.
13. Contact
Mercopilot
Email: [email protected]
Web: mercopilot.com
The other half of the agreement
This page covers what we hold. The terms cover what Mercopilot may do to a store, what a subscription costs, and where the limits are.
Read the terms of serviceQuestions about any of this? Email [email protected] and a person will answer.