Data and privacy
Last updated: 7 October 2026.
MerchSift is operated by Ben Hybert.
What the app processes
With the merchant’s permission, MerchSift reads product titles, descriptions, vendor names, product types and selected product images. Merchants can also submit text and images manually. Please remove personal details before submitting customer messages.
AI processing
Cloudflare hosts the app, its database and background jobs. Product photos pass through Cloudflare Images to resize them before AI processing.
Inputs are sent to OpenAI’s Decisions API to return categories, probabilities or scores. Raw text and images are not stored in our database. OpenAI processes inputs under its API data policies, including any applicable abuse-monitoring retention.
What we retain
We store the shop domain, Shopify session credentials, processing preferences, trial dates, subscription verification, usage accounting, and decision results. Results, product references and privacy-request receipts are retained for up to 90 days. Completed job metadata is retained for seven days. Customer profiles, orders and raw customer inputs are not stored.
Control and deletion
Disable AI processing in Settings to stop new checks. Uninstalling revokes our store sessions and removes saved results and queued jobs. Shopify’s shop deletion webhook removes remaining shop configuration and usage records. Customer deletion requests remove manual decision history. Existing product tags remain in Shopify and can be removed there.
Billing and access
Shopify manages subscriptions and payment details. We do not receive card numbers. We use subscription information to enforce plan allowances. Usage limits and service safeguards can pause AI processing.
Contact
For access, deletion or privacy questions, contact merchsift@cnnct.uk.