Legal
Privacy policy
Last updated: 13 July 2026
Who we are
Caira ("we", "us") provides an AI-powered Shopify store intelligence service at meetcaira.co.uk. This policy explains how we collect, use, and protect your information.
Information we collect
- Account data: name, email address, and password (stored hashed).
- Shopify data: store domain, access tokens, and data synced from your store (orders, products, customers, inventory, theme assets) as permitted by your OAuth scopes.
- Billing data: subscription status and Stripe customer ID. Payment card details are handled by Stripe — we do not store card numbers.
- Usage data: logs of analysis runs, insights generated, and actions you approve.
Merchant and customer data roles
When you connect a Shopify store, you remain the data controller for your business and your customers' personal data. Caira acts as a data processor on your behalf, accessing only the store data required to provide monitoring, insights, and fixes you approve.
We do not sell personal data. We do not use end-customer data for advertising or unrelated purposes.
Protected customer data we process
To provide store intelligence, Caira may process protected customer data from your Shopify store, limited to what is necessary for the service:
- Customer identifiers: Shopify customer IDs linked to orders.
- Contact fields (where synced): customer email, first name, and last name — used for order analysis, repeat purchase insights, and operational reporting.
- Order data: order totals, line items, dates, and fulfilment status — used for revenue, inventory, and operations insights.
We request and process only the minimum data required for these purposes. We do not request customer phone numbers or addresses unless required by a feature you use.
How we use your information
- To provide store monitoring, insights, and approved fixes.
- To process subscriptions and manage your account.
- To improve Caira's analysis and product experience.
- To communicate with you about your account or support requests.
Third-party services
We use trusted providers including Shopify (store data), Stripe (payments), OpenAI (AI analysis), Neon (database hosting), and Vercel (application hosting). Each processes data under their own privacy policies and our data processing agreements where applicable.
Security
- Encryption in transit: all traffic uses HTTPS (TLS).
- Encryption at rest: data is stored with encrypted PostgreSQL hosting (Neon) and encrypted backups.
- Access controls: production database and hosting access is limited to authorised personnel only.
- Password security: merchant account passwords are hashed; staff accounts use strong, unique passwords and multi-factor authentication where available.
- Environment separation: test and production data are kept in separate environments.
- Access logging: administrative access to production systems and application errors are logged via our hosting and database providers.
- Data loss prevention: customer data is not exported to local devices, is not used in public test environments, and access is restricted to systems required to operate the service.
Security incidents
If we become aware of a security incident affecting personal data, we will investigate promptly, take steps to contain it, and notify affected merchants without undue delay where required by law. Report concerns to privacy@meetcaira.co.uk.
Data retention
We retain your account and store data while your subscription is active. If you cancel and request deletion, we will remove your personal data within 30 days, except where we must retain records for legal or accounting purposes.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal data, and to object to certain processing. Contact privacy@meetcaira.co.uk to exercise these rights.
Contact
Questions about this policy? Email privacy@meetcaira.co.uk.