Skip to content

Legal

Privacy Policy

This policy explains how Kinect collects, uses, stores, and protects merchant and shopper data across our Shopify app, storefront assistant, merchant dashboard, connected Google Ads accounts, landing pages, and website, and the rights you have over that data.

Last updated: September 8, 2026

1. Who We Are & Scope

Kinect, Inc. (“Kinect,” “we,” “us”) provides an AI commerce platform for brands, including a Shopify admin app, a storefront shopping assistant, and a merchant dashboard for analytics, connected advertising accounts, and landing pages. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It covers these services and this website (trykinect.ai). The merchant is the data controller for its store, shopper, and connected advertising account data; Kinect acts as a data processor that handles that data on the merchant’s behalf and in line with our agreement with the merchant.

2. Information We Collect

We collect only the information needed to operate and improve the service:

  • •Merchant & store data (via Shopify APIs): When a merchant installs the app, we access store data permitted by the access scopes the merchant approves — products, collections, product listings, store content and policies, themes, and order data. We request read-only scopes and only the scopes needed for the app to function. We do not request write access to a merchant’s storefront, customers, or checkout.
  • •Shopper & conversation data: When a shopper interacts with the on-store assistant, we process the messages they send, the AI responses, products viewed or compared, an anonymous visitor identifier, and basic technical data (such as A/B test cohort and coarse session context). Conversations are keyed to anonymous visitor IDs, not to Shopify customer accounts. If a shopper is logged in and the merchant has enabled it, a conversation may be linked to a Shopify customer ID so the merchant can recognize returning customers.
  • •Connected Google Ads data: When you authorize Google Ads access, we retrieve advertising account information and ad creatives to display in your dashboard and help you build landing pages. Section 6 explains the data, permissions, storage, sharing, and controls for this optional integration.
  • •Website & inquiry data: On trykinect.ai, we collect information you voluntarily submit through forms (such as a demo request, audit request, or waitlist sign-up) — typically your name, email, store URL, and any message — along with referrer and basic analytics data.

3. How We Use Information

We use the information above to: provide and operate the AI shopping assistant and merchant dashboard; generate AI responses and product recommendations; build per-store knowledge and configuration so the assistant reflects the merchant’s catalog, voice, and policies; produce commerce analytics and insights for the merchant; display imported ad creatives and generate landing pages at the merchant’s request; maintain security, prevent abuse, and enforce rate limits; provide support and respond to inquiries; and improve the reliability and quality of the service. We do not sell personal information, and we do not use shopper data to build cross-merchant advertising profiles. Google Ads data is used only as described in Section 6.

4. AI Processing & Subprocessors

Kinect uses large language models to power the shopping assistant and generate landing pages. Shopper messages and relevant store context are sent to AI model providers to generate assistant responses. When a merchant requests a landing page based on an imported ad, the selected ad copy and relevant merchant and product context are sent to model providers to generate that page. We rely on the following categories of subprocessors to deliver the service:

  • •AI model routing & providers: Vercel AI Gateway routes inference requests to LLM providers (such as Anthropic, OpenAI, and Google) to generate assistant responses and landing pages.
  • •Hosting & infrastructure: Vercel and Fly.io host our websites, applications, and APIs.
  • •Database: A managed PostgreSQL database (Supabase) stores conversations, store configuration, analytics, advertising account connections, imported ad records, and landing pages.
  • •Voice transcription (optional): If a shopper uses push-to-talk voice input, the audio is transcribed via a speech-to-text provider (Groq Whisper).
  • •Email & forms: Transactional and inquiry email is sent via Resend; website form submissions are stored in Supabase.

5. How We Share Information

We share information only as needed to run the service: with the merchant whose store a shopper is interacting with; with the subprocessors listed above, who are bound by contract to protect the data and use it only to provide their service to us; and where required by law or to protect the rights, safety, and security of Kinect, merchants, or shoppers. Customer data collected through Shopify-hosted surfaces remains accessible to the merchant in their Kinect dashboard. We do not sell or rent personal information to third parties.

6. Google Ads Data

Connecting Google Ads is optional. Google’s permission screen describes access to manage your Google Ads accounts because that is the permission its API provides. Kinect’s integration uses that access to read account and creative data; it does not create or edit campaigns, change budgets, or publish changes to Google Ads.

  • •What we access: We discover advertising accounts you can access, including account IDs, names, currencies, and manager-account relationships. For the account you select, we read campaign, ad group, ad, and Performance Max asset-group identifiers, names, formats, statuses, and approval information; creative text such as headlines and descriptions; image and thumbnail URLs; video references; and destination URLs.
  • •How we use it: We use this data to let you select an account, import and browse its creatives, track which ads have associated Kinect pages, and prefill a landing-page brief from an ad you choose. If you request AI page generation, we use that brief to generate the page. We do not sell Google Ads data or use it to build advertising profiles across merchants.
  • •What we store: We store account details, imported campaign and creative records, media and destination references, connection and sync status, and links between ads and Kinect pages in our database. We also store the Google refresh token that allows continued authorized access, encrypted before it is saved. Data is encrypted in transit and at rest.
  • •Who receives it: Imported data is available to authorized users in your Kinect workspace and is processed by the hosting and database providers listed in Section 4. When you request AI page generation, the selected ad copy and relevant merchant context are sent through Vercel AI Gateway to the model provider generating the page. If you publish a page, the content you choose to publish is visible to visitors. We may also disclose data where required by law or necessary to investigate security incidents or abuse.
  • •Retention and disconnecting: We retain imported Google Ads records and pages while they are needed to provide your Kinect workspace. Disconnecting Google Ads in Kinect deletes the saved refresh token and stops future access through that connection. It does not automatically delete previously imported ads or pages. You can also revoke Kinect’s access in your Google Account’s third-party connections settings. Revoking access does not itself delete data already stored in Kinect.
  • •Requesting deletion: Contact hello@trykinect.ai to request deletion of imported Google Ads data and associated page records. We will verify your authority over the workspace and delete the requested data, except where retention is required by law or necessary for security obligations.

7. Shopify Protected Customer Data

Where Kinect accesses protected customer data through Shopify’s APIs, we comply with Shopify’s Protected Customer Data requirements and the Shopify API License and Terms of Use. We collect only the data required for the app to function, use it solely to provide the features the merchant has enabled, limit staff and system access, encrypt data in transit and at rest, and apply data-retention and deletion controls. We do not use protected customer data for advertising or for any purpose unrelated to the service the merchant installed.

8. Data Retention

We retain store configuration and conversation data for as long as the merchant’s app remains installed and the data is needed to provide the service, and as required to meet legal, security, and accounting obligations. When a merchant uninstalls the app, or upon a valid deletion request, we delete or redact the associated data through the processes described below. Website inquiry data is retained for as long as needed to respond and maintain our business records. Retention and deletion of Google Ads data are described in Section 6.

9. Data Deletion & Mandatory Webhooks

Kinect implements Shopify’s mandatory privacy webhooks so merchants and shoppers can exercise data rights:

  • •customers/data_request: When a shopper requests their data through a merchant, we locate and make available the conversation data we hold that is linked to that customer.
  • •customers/redact: When a merchant requests redaction of a customer, we delete or anonymize the conversations and related records tied to that customer.
  • •shop/redact: After a merchant uninstalls the app, Shopify sends a shop-redaction request and we delete the store’s data from our systems.

10. Your Rights

Depending on where you live (for example, under GDPR in the EU/UK or the CCPA/CPRA in California), you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. Shoppers should direct requests to the merchant whose store they interacted with, since the merchant controls that data; the merchant can fulfill the request using the tools described above. You may also contact us directly at hello@trykinect.ai and we will help route or fulfill the request. We do not discriminate against you for exercising these rights.

11. Data Security

All data exchanged between clients and our servers is encrypted in transit using TLS/SSL, and data is encrypted at rest. We follow least-privilege access controls, validate request origins, rate-limit our public endpoints, and use authenticated, verified webhooks. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.

12. Cookies & Tracking

The embedded Shopify admin app functions without third-party cookies. The storefront widget uses a first-party visitor identifier to maintain conversation continuity and assign A/B test cohorts; it does not require third-party cookies. Our website may use first-party cookies and privacy-respecting analytics to understand site usage and improve content.

13. International Data Transfers

Kinect is based in the United States, and our subprocessors may process data in the United States and other countries. Where personal data is transferred across borders, we rely on appropriate safeguards (such as standard contractual clauses) and require our subprocessors to maintain comparable protections.

14. Children’s Privacy

Kinect is built for merchants and their adult customers. The service is not directed to children under 13 (or the minimum age in the applicable jurisdiction), and we do not knowingly collect personal information from children.

15. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date below and, where appropriate, notify merchants. Continued use of the service after an update constitutes acceptance of the revised policy.

Contact Us

Questions about this policy or a data request? Reach us at hello@trykinect.ai.

Kinect, Inc. — San Francisco, CA
Contact: hello@trykinect.ai