MerchSift

Data and privacy

Last updated: 7 October 2026.

MerchSift is operated by Ben Hybert.

What the app processes

With the merchant’s permission, MerchSift reads product titles, descriptions, vendor names, product types and selected product images. Merchants can also submit text and images manually. Please remove personal details before submitting customer messages.

AI processing

Cloudflare hosts the app, its database and background jobs. Product photos pass through Cloudflare Images to resize them before AI processing.

Inputs are sent to OpenAI’s Decisions API to return categories, probabilities or scores. Raw text and images are not stored in our database. OpenAI processes inputs under its API data policies, including any applicable abuse-monitoring retention.

OpenAI API data controls

What we retain

We store the shop domain, Shopify session credentials, processing preferences, trial dates, subscription verification, usage accounting, and decision results. Results, product references and privacy-request receipts are retained for up to 90 days. Completed job metadata is retained for seven days. Customer profiles, orders and raw customer inputs are not stored.

Control and deletion

Disable AI processing in Settings to stop new checks. Uninstalling revokes our store sessions and removes saved results and queued jobs. Shopify’s shop deletion webhook removes remaining shop configuration and usage records. Customer deletion requests remove manual decision history. Existing product tags remain in Shopify and can be removed there.

Billing and access

Shopify manages subscriptions and payment details. We do not receive card numbers. We use subscription information to enforce plan allowances. Usage limits and service safeguards can pause AI processing.

Contact

For access, deletion or privacy questions, contact merchsift@cnnct.uk.