Legal

Privacy Policy

Last updated: May 2026

1. Introduction

GenCodeAI ("we", "our", "the app") is a Shopify application developed by OrkarDev that helps merchants generate and manage bulk discount codes. This Privacy Policy explains how we collect, use, and protect your information.

2. Information We Collect

When you install GenCodeAI, we access the following data through the Shopify API:

Store information: Your store name and domain to identify your account.

Order data (aggregated only): We read your store's order history to calculate aggregate metrics such as average order value, discount redemption rates, and product category performance. We do not store individual order details or customer information.

Discount data: We create and manage discount codes and price rules on your behalf within Shopify.

3. Information We Do NOT Collect

We do not collect, store, or process any personal customer information including names, email addresses, phone numbers, shipping addresses, or payment information from your store's customers.

4. How We Use Your Information

Discount code generation: To create and manage bulk discount codes in your Shopify store.

AI-powered recommendations: Aggregated order metrics are sent to an AI service (Anthropic Claude) to generate discount strategy recommendations. No individual customer data is included in these requests.

Billing: We use Shopify's built-in Billing API to manage subscriptions. We do not process payments directly.

5. Data Storage and Security

Your Shopify access token is encrypted at rest using AES-256 encryption. All data is transmitted over HTTPS/TLS. We use industry-standard security practices including HMAC webhook verification, rate limiting, and input validation.

6. Data Retention and Deletion

When you uninstall GenCodeAI, all your data (including batch history, generated codes, and store information) is automatically deleted from our systems. You can also request data deletion at any time by contacting us.

7. Third-Party Services

We use the following third-party services:

Shopify: For app hosting, billing, and store API access.

Anthropic (Claude AI): For generating discount strategy recommendations using aggregated, anonymized store metrics.

Railway: For hosting our backend server and database.

8. GDPR Compliance

We comply with GDPR and Shopify's data protection requirements. We support all mandatory Shopify webhooks for data deletion requests (shop/redact, customers/redact, customers/data_request).

9. California Privacy Rights (CCPA)

GenCodeAI does not collect, sell, or share personal information of end consumers. We only access aggregated store metrics. California residents may contact us at the email below for any privacy-related inquiries.

10. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated date.

11. Contact

If you have questions about this Privacy Policy, contact us at: info@orkardev.com