AI Social Share
Privacy policy
Last updated: 31 July 2026. This policy explains how AI Social Share processes merchant data when the Shopify app is used.
Who controls your data
AI Social Share is operated by Fleeta Limited, a company registered in England and Wales under company number 16675897. Its registered office is 50 Princes Street, Ipswich, England, IP1 1RJ. Contact support@fleeta.co.uk about this policy or your data.
Data we process
We process the installing shop’s domain, name, timezone and currency; public product and article fields needed to create social posts; merchant-selected automation settings; connected social-account and destination identifiers and display labels; encrypted Facebook and LinkedIn OAuth credentials; delivery identifiers; and operational audit records. Facebook post-management audits contain the delivery and provider post identifiers, operation outcome, message hashes, and merchant actor reference rather than a second stored copy of the before-and-after post text. For LinkedIn, LinkedIn authenticates the Page administrator and the app stores only Company Page identifiers, names, approved administrative roles, and access data needed to publish to selected Pages. The app does not request LinkedIn personal-profile data, does not publish to personal profiles, and does not request Shopify customer, order, payment, or write-product access.
Why and how we use it
Data is used only to provide content discovery, caption drafting, merchant-controlled posting and management of app-created Facebook Page posts, billing, security, support, and abuse prevention. LinkedIn drafts remain editable and a LinkedIn API request is made only after a merchant explicitly clicks to post.
We process app-service and billing data to perform our contract with the merchant or take requested pre-contract steps. We process security, reliability, support, and abuse-prevention data for our legitimate interests in operating a safe service. Social-provider data is processed to carry out the merchant’s requested connection and posting actions. Where processing relies on consent, it can be withdrawn by disconnecting the provider, without affecting earlier lawful processing.
Storage, subprocessors, and retention
Production data is stored in an isolated application database on OVHcloud infrastructure administered by Fleeta. OAuth tokens are encrypted at rest and redacted from logs. Shopify, Meta, LinkedIn, and OpenAI (only when optional AI caption suggestions are enabled) receive only the data required for the requested operation. These providers may process data outside the United Kingdom or European Economic Area under their own terms and applicable contractual transfer safeguards.
Detailed terminal publication and delivery data—including stored message text, link snapshots, provider post identifiers and response hashes, and error detail—is scrubbed after the configured detailed-history period, which is 365 days by default. Related Facebook post-operation provider identifiers, message hashes, and actor references are scrubbed on the same schedule. Expired OAuth state is removed after about one day and webhook receipt metadata after 90 days. Minimal publication, delivery, operation-outcome, usage/quota, and subscription evidence may be retained as needed to operate limits and billing, resolve disputes, and meet legal obligations.
Essential cookies and operational logs
The embedded app uses only essential security and session mechanisms, including an encrypted secure session cookie and Shopify session tokens. It does not set advertising cookies. Query strings, request bodies, authorization headers, and referrers are excluded from application access logs. Security logs can include IP address, timestamp, request method and path, response status, size, timing, and a request identifier; production log rotation retains up to 14 daily rotations.
Your controls
Merchants can disconnect social accounts in the app. Disconnecting or uninstalling removes provider credentials, anonymises stored social identity fields, disables destinations, and stops queued work. Facebook users can also remove the app and send a deletion request from Facebook's Apps and Websites settings; AI Social Share verifies Meta's signed callback, anonymises matching Facebook data across shops, and returns a confirmation-status link. A validated Shopify shop/redact request deletes the shop record and cascades deletion through its tenant data. To request access, correction, deletion, or export, contact support@fleeta.co.uk.
Security and contact
We use tenant isolation, least-privilege Shopify scopes, HTTPS, encrypted secrets, HMAC-verified webhooks, replay protection, bounded retries, and security monitoring. No internet service can promise absolute security. Questions can be sent to support@fleeta.co.uk.