AI Social Share
Privacy policy
Last updated: 30 July 2026. This policy explains how AI Social Share processes merchant data when the Shopify app is used.
Data we process
We process the installing shop’s domain, name, timezone and currency; public product and article fields needed to create social posts; merchant-selected automation settings; connected social-account and destination identifiers and display labels; encrypted Facebook and LinkedIn OAuth credentials; delivery identifiers; and operational audit records. LinkedIn profile-picture URLs are not retained during destination discovery. The app does not request Shopify customer, order, payment, or write-product access.
Why and how we use it
Data is used only to provide content discovery, caption drafting, merchant-controlled posting, billing, security, support, and abuse prevention. LinkedIn drafts remain editable and a LinkedIn API request is made only after a merchant explicitly clicks to post.
Storage, subprocessors, and retention
Production data is stored in an isolated application database. OAuth tokens are encrypted at rest and redacted from logs. Shopify, Meta, LinkedIn, and OpenAI (when optional AI caption suggestions are enabled) receive only the data required for the requested operation.
Detailed terminal publication and delivery data—including stored message text, link snapshots, provider post identifiers and response hashes, and error detail—is scrubbed after the configured detailed-history period, which is 365 days by default. Expired OAuth state is removed after about one day and webhook receipt metadata after 90 days. Minimal publication and delivery status, usage/quota, and subscription evidence may be retained as needed to operate limits and billing, resolve disputes, and meet legal obligations.
Your controls
Merchants can disconnect social accounts in the app. Disconnecting or uninstalling removes provider credentials, anonymises stored social identity fields, disables destinations, and stops queued work. A validated Shopify shop/redact request deletes the shop record and cascades deletion through its tenant data. To request access, correction, deletion, or export, contact support@fleeta.co.uk.
Security and contact
We use tenant isolation, least-privilege Shopify scopes, HTTPS, encrypted secrets, HMAC-verified webhooks, replay protection, bounded retries, and security monitoring. No internet service can promise absolute security. Questions can be sent to support@fleeta.co.uk.