Privacy policy
How we collect, use, and protect personal data when you use our website, free tools, and Shopify apps.
Last updated: September 9, 2026
This Privacy Policy describes how Ninety 9 LTD ("we", "us", "our") collects, uses, discloses, and protects personal data when you:
- visit ninety9.dev;
- use our free tools on this website (the CRO Audit for Shopify stores and the ChatGPT SEO check for Shopify stores); or
- install or use our Shopify apps (Addy, Addly, Goalify, Monet, or Reviso).
It applies to merchants and store staff, website visitors, and — where an app processes shopper data — end customers of merchants (in practice, primarily through Reviso).
1. Controller and processor roles
Where we process personal data about a merchant's customers solely to provide an app for that merchant, the merchant is the controller and we act as processor / service provider.
We act as an independent controller for our own business records, including merchant account and billing records, support communications, security logs, website analytics (where consented), free-tool reports we generate on this website, and records we keep for legal compliance.
2. Personal data we collect
2.1 Website visitors
- Server logs — IP address, user agent, requested URL, and timestamp, kept briefly by our hosting provider for security and abuse prevention.
- Cookie preference — a local browser record of your analytics cookie choice so we do not re-prompt on every visit. It is not used to identify you.
- Analytics (only if you accept) — Google Analytics 4 may process page path, device type, approximate region, referrer, and a client identifier. If you reject or do nothing, the analytics script is not loaded and no analytics cookies are set.
- Contact messages — if you email us (including via a mailto contact flow on this site), we receive the content and address you send through your email provider.
2.2 Free website tools
When you run the CRO Audit for Shopify stores or the ChatGPT SEO check for Shopify stores, we process:
- the store or page URL you submit;
- an optional storefront password you provide for a password-protected shop (used only to open that check, then discarded — not stored in reports, logs, or share links);
- public page content needed to perform the check (for the CRO audit: product/cart views a shopper can load, and optional screenshots; for the SEO & AI Audit: public HTML, robots.txt, and llms.txt);
- your IP address and browser type for rate limiting;
- for the CRO audit only: a report stored for about 90 days (title, handle, URL, score, findings, optional screenshots, share id). Anyone with the share link can view that report. A short-lived cache may avoid repeating the same live fetch. An aggregate success count is kept without tying it to your identity.
These tools do not access Shopify admin, checkout, orders, or customer personal data. Do not submit URLs you are not authorised to have checked. Merchants may opt out with a meta tag in their theme (ninety9-audit and/or ninety9-readiness); the CRO audit opt-out also stops the SEO & AI Audit.
2.3 Shopify apps
Each app requests only the Shopify API scopes disclosed on its App Store listing. Depending on the app, we may process:
- Store and merchant account data — store name, domain, staff/owner contact details, and identifiers needed to operate the install.
- Catalogue and storefront configuration — products, collections, variants, discounts, theme/locale settings needed to run the app.
- Order data — order identifiers, line items, product/variant data, prices, and fulfilment status as needed for the app. Addy, Addly, Goalify, and Monet do not store customer names, emails, phone numbers, or addresses on our servers.
- Customer personal data (Reviso only) — name, email, shipping/contact details, and related fields required to process approved post-purchase order changes.
- App configuration and activity records — settings, edit-request history, timestamps, approvals, and similar records for support, disputes, and compliance.
- Technical and usage data — app interactions, session/device signals, IP-related security signals, crash reports, and logs.
- Billing records — subscription/usage charge records via Shopify Billing. We do not receive full payment card numbers or CVV/CVC.
- Support communications — emails, chat, and troubleshooting materials you send us.
3. Data we do not collect
- Full payment card numbers or card security codes.
- Shopify account passwords or login secrets.
- Customer names, emails, phones, or addresses on our servers for apps other than Reviso.
- Admin, checkout, order, or customer databases through the free website tools — only publicly reachable storefront content (and an optional storefront password used transiently).
4. How we use personal data
- To provide, operate, secure, and support the website, free tools, and apps.
- To process billing through Shopify and maintain merchant accounts.
- To generate and (for the CRO audit) temporarily store and share reports you request.
- To communicate service, security, and support notices.
- To detect and prevent fraud, abuse, and security incidents.
- To comply with law, Shopify requirements, and our contracts.
- With consent, to measure website usage via Google Analytics.
We do not sell personal data, rent or trade it, share it with advertising networks, or use merchant store data to train third-party models.
5. Legal bases
Where required (including GDPR), we rely on:
- Contract — to provide the apps and related support you request.
- Legitimate interests — security, abuse prevention, reliability, support, and protecting our services and users.
- Legal obligation — tax, accounting, regulatory, and lawful requests.
- Consent — where required, including analytics cookies on this website.
6. Sharing
We share personal data only as needed with:
- Shopify (platform, billing, compliance, support);
- Google (Analytics 4), only if you accept analytics cookies;
- infrastructure providers (hosting, databases, monitoring, email, support tools) under contract;
- professional advisers where needed;
- authorities when required by law or to protect rights and safety;
- parties to a corporate transaction, under appropriate safeguards;
- authorised contractors/subprocessors bound by confidentiality and data-protection terms.
A current subprocessor list is available on request at [email protected].
7. Cookies
You can change your analytics choice anytime via the Cookies link in the footer.
- Necessary — local storage of your cookie preference (
n9-consent). No consent required. - Analytics — Google Analytics 4 cookies and related processing only after you accept.
We do not load Google Fonts from a third-party host. Search Console verification, if present, is a static ownership tag and is not used for tracking.
8. Retention
- CRO audit reports (including screenshots): about 90 days, then deleted. Rate-limit/cache records: minutes to about a day.
- SEO & AI Audit checks: no long-lived shareable report store.
- App data: while the install/subscription is active, then deleted per Shopify's mandatory webhooks (
shop/redactwithin 48 hours of Shopify's retention window; customer redaction within 30 days). - Other records: only as long as needed for support, security, disputes, and legal obligations, then deleted or anonymised.
9. Security
We use reasonable technical and organisational measures appropriate to the risk, including access controls, encryption in transit where appropriate, secure storage practices, and monitoring. No method of transmission or storage is perfectly secure.
10. International transfers
Data may be processed in countries other than your own, including where our providers operate. Where required, we use appropriate safeguards (such as standard contractual clauses or adequacy mechanisms).
11. Your rights
Depending on your location (including GDPR and CCPA/CPRA), you may have rights to access, correct, delete, restrict or object to certain processing, portability, withdraw consent, lodge a complaint with a supervisory authority, and (under CCPA/CPRA) not be discriminated against for exercising rights. Some rights are limited where processing is required to provide the service or meet legal duties.
Shoppers whose data is processed through Reviso should contact the merchant first (the merchant is usually the controller). We assist merchants with verified requests where required.
Contact [email protected] to exercise rights we control or to request merchant assistance.
12. Shopify compliance
We process Shopify-related personal data only as needed to provide the apps and meet Shopify and legal requirements. Mandatory GDPR webhooks (customers/data_request, customers/redact, shop/redact) are implemented for every app.
13. Children
Our services are business software for merchants and are not directed at children. We do not knowingly collect personal data directly from anyone under 16. If we learn we have, we will delete it.
14. Third-party services
Links to Shopify or other third parties are governed by those parties' own policies. We are not responsible for their practices.
15. Changes
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date and, where they affect app data handling, communicated in-app, on this website, or by email as appropriate. Continued use after an update constitutes acceptance of the revised policy.
16. Contact
Ninety 9 LTD
ul. "27-mi yuli", No 23
Center Odesos, 9000 Varna
Bulgaria
[email protected]