Legal
How we handle your store data
This is the short version of how Boresha treats your store. The privacy policy and DPA are the formal documents.
01
Proposals, not silent publishes
Everything the AI writes is a proposal. For each listing you choose publish live, save as draft, or discard. Optimizing an existing product is update or leave it alone. Nothing is written to Shopify until that step.
02
What we process
Catalog content, your brand profile, media you upload or we generate, staff identity from the Shopify session, and billing identifiers. Support tickets if you write in.
03
What we never send to models
Customers, orders, and payment cards.
04
Where it runs
Application hosting is Railway in Amsterdam (EU). Generated images and video wait in staging storage (Cloudflare R2). When you accept them they go to Shopify Files, and we delete our staging copy. Analytics events are kept for 180 days.
05
Uninstall and redact
Uninstall stops the app. Shopify’s GDPR shop/redact webhook is how we hard-delete or anonymize that shop’s rows. You can also email support@boresha.app.
Ready to use Boresha? Add Boresha to Shopify