Privacy policy
Last updated 16 September 2026
What Gisto does
Gisto connects to a merchant's Shopify store and turns order data into daily comparisons, anomaly detection, a morning email, and answers to the merchant's questions. Gisto is used only by the merchant who installed it. It shows aggregated results and never exposes an individual customer's data.
Data we process, and why
We process the minimum needed to produce sales analytics:
- Orders: order number, dates, amounts, discounts, taxes, shipping, refunds, financial and fulfillment status, sales channel, discount codes, and line items (product, variant, quantity, price).
- Products: title, type, vendor, status.
- Customers: only Shopify's opaque customer ID attached to an order, so we can tell new customers from returning ones. We do not collect names, email addresses, phone numbers, or postal addresses.
- Store: store name, currency, timezone, the merchant's email address for the daily digest, and an encrypted API access token.
Purpose: analytics and reporting for the merchant (period comparisons, insight detection, the daily email, and natural-language answers). We do not use the data for any other purpose, do not sell or share it, and do not use it for advertising.
Retention
Data is kept only while the app is installed. When a merchant uninstalls Gisto, the store's access token is deleted immediately and all of the store's data is erased when Shopify sends its shop/redact request (48 hours after uninstall), and in any case no later than 30 days after uninstall. Customer erasure requests (customers/redact) remove the customer ID from that customer's orders. Data access requests are answered from the same records.
Security
- All data is encrypted in transit (TLS) and at rest, including backups.
- Shopify access tokens are additionally encrypted at the application level with a key that is not stored with the data.
- Test and production data are kept separate.
- Access to production data is limited to the people operating the service.
Service providers
We use Vercel (hosting), Neon (database), Resend (email delivery), and an AI model provider through Vercel AI Gateway (to write the daily narrative and answer questions from aggregated figures). Each processes data only to provide its service to us.
Merchant and customer rights
Merchants can disconnect at any time by uninstalling the app from Shopify. Customers exercise their rights through the merchant; Shopify forwards those requests to us and we honour them as described above. Questions: contact the merchant's Gisto account owner or the address in the app's Shopify listing.