Privacy Policy
Sizo AI reads a Shopify store's sales and inventory data to forecast demand and recommend smarter restocks. This policy explains exactly what we read, what we store, who processes it, and how a merchant can have it exported or deleted.
1. Who we are & scope
Sizo AI ("Sizo", "we", "us") provides an inventory prediction and restock-recommendation application for fashion brands selling on Shopify. The app reads a merchant's store data through the official Shopify Admin API and turns it into demand forecasts and size-ratio recommendations.
This policy applies to the Sizo app installed on a Shopify store and to this marketing website (sizo-ai.com). It is written for the Shopify merchants who are our customers. Questions about this policy or any request relating to your data can be sent to info@sizo-ai.com.
2. What we collect
When a merchant installs Sizo, the app reads store data via the Shopify Admin API to power its forecasts. This includes:
- Products and variants — titles, options, SKUs, sizes, colors, vendors, and prices.
- Inventory levels — on-hand and available quantities, including per-location stock.
- Orders and sales history — line items by SKU and size, quantities, discounts, and refunds/returns.
- Locations and fulfillments — store and warehouse locations and how orders were fulfilled.
We use this data to model real demand by size, exclude items that were unsellable because they were out of stock, and recommend the right size ratio and quantity for the next restock.
We do not collect or store your customers' personal information. The only customer-related value we retain is the pseudonymous Shopify Customer ID (for example gid://shopify/Customer/123…), which we use solely to connect a refund to a later reorder by the same shopper so our return analysis is accurate. We do not collect, store, or process customer names, email addresses, phone numbers, or shipping/billing addresses.
For the merchant's own account we store the store domain and the email address associated with the Shopify session, used for app access, alerts, and support.
Team contact details. During onboarding a merchant may add teammates — names, email addresses, and phone numbers — so Sizo can route alerts and weekly digests to them. Providing these details is voluntary; they are used only for notifications and access roles, and anyone listed can ask to see, correct, or delete their details at any time (see section 6).
3. How we use data
We use store data for two purposes only:
- Inventory optimization analytics — forecasting demand by size, detecting stockouts, measuring lost revenue, and generating restock recommendations specific to your shop.
- An optional AI assistant — a conversational feature that answers questions about your own store's data on request. Queries and the relevant data are processed by our AI subprocessor (see below) to produce an answer for you.
We do not sell your data, and we do not use your data to train third-party AI models for other customers. Your store's data is used to serve your store.
4. Subprocessors
We rely on a small set of trusted providers to operate the service. Each processes data only as needed to deliver their function:
- Shopify — the source platform; we read store data through Shopify's official Admin API.
- Fly.io — application hosting (Amsterdam, Netherlands).
- Aiven — managed PostgreSQL database (AWS infrastructure, EU eu-west region). Each store's data lives in its own isolated schema.
- Anthropic — AI processing that powers the optional AI assistant (United States); inputs are not retained to train models.
- Resend — delivery of email alerts and notifications (United States).
- Microsoft Clarity — usage analytics on this website and inside the Sizo app (heatmaps and session recordings; typed input and sensitive fields such as email addresses are masked before leaving the browser; United States).
Store data is therefore stored in the European Union, with limited processing in the United States by the AI and email providers above.
5. Data retention, deletion & GDPR
We honor Shopify's mandatory privacy webhooks and respond to them automatically:
- customers/data_request — a merchant's request, on behalf of a shopper, for the data we hold.
- customers/redact — a request to delete a specific shopper's data.
- shop/redact — sent by Shopify after a store uninstalls Sizo, instructing us to delete the shop's data.
While the app is installed we retain store data for as long as needed to provide forecasts and historical analysis. After an uninstall we keep the store's data for 48 hours in case of reinstall; when Shopify's shop/redact webhook arrives at the end of that window, the store's entire database schema is deleted. If a store uses Sizo through more than one Shopify app installation, deletion runs when the last installation is removed. Every deletion decision is recorded in an audit log.
Merchants can request an export or deletion of their data at any time by emailing info@sizo-ai.com. If you are in a jurisdiction with data-protection laws such as the GDPR, you may have rights to access, correct, export, or delete your data; we will act on verified requests sent to that address.
6. Israeli Privacy Protection Law (Amendment 13)
Sizo complies with the Israeli Privacy Protection Law, 5741-1981, as amended by Amendment 13 (in force since August 2025). Two roles apply:
- For a store's data (orders, inventory, pseudonymous customer identifiers) the merchant is the database controller (בעל שליטה במאגר) and Sizo acts as a holder (מחזיק), processing the data only on the merchant's behalf and instructions.
- For Sizo's own operational records (merchant accounts, app settings, usage events, configured team contact details) Sizo is the controller.
Notice at collection (Section 11). Wherever the app asks a merchant to enter personal details about people — such as teammates' names, emails, and phone numbers — it states at the point of collection that providing them is voluntary, what they are used for, who receives them, that they are stored outside Israel (in the EU, per section 4), and how long they are kept.
Access, correction, and deletion. Any person whose details we hold may request to review, correct, or delete them — in the app's Settings page or by emailing info@sizo-ai.com.
Security incidents. If a security event affects a store's data we will notify the affected merchants — and, where Israel's Data Security Regulations require it, the Privacy Protection Authority — without undue delay.
7. Security
Data is encrypted in transit over HTTPS and is access-controlled within our infrastructure. We request the minimum (least-privilege) Shopify API scopes the app needs to function, and we use read-only access to Shopify for analysis wherever possible.
No method of transmission or storage is perfectly secure, but we work to protect your data and to limit who and what can access it.
8. Cookies
The Sizo app itself uses only the cookies required for an authenticated session inside Shopify. This marketing website uses a small amount of privacy-respecting analytics to understand aggregate traffic; it does not use advertising or cross-site tracking cookies.
9. Changes to this policy
We may update this policy from time to time. When we make material changes we will revise the effective date above and, where appropriate, notify merchants. Continued use of Sizo after an update means you accept the revised policy.
10. Contact
For any privacy question or request, write to us at info@sizo-ai.com.