Revenue Reactor
Home Terms

Revenue Reactor

Privacy Policy

Effective date: July 11, 2026

Revenue Reactor helps Shopify merchants identify product-page issues, estimate organic revenue risk, assess SEO and AEO readiness, generate AI-assisted drafts, and apply only merchant-approved changes. Revenue Reactor is operated by Revenue Reactor Labs LLC ("we," "us," or "our"). This policy explains what information we access, use, store, and share.

Who We Are

Revenue Reactor is operated by Revenue Reactor Labs LLC. Our mailing address is 801 East Baseline Road, Lafayette, Colorado, USA. Privacy questions and requests can be sent to hello@revenuereactorapp.com.

Scope and Privacy Roles

This policy applies to the Revenue Reactor website, Shopify app, support interactions, and optional Google integrations. For merchant store data, the merchant generally determines why the data is used and Revenue Reactor processes it to provide the app. Revenue Reactor separately controls information used for its own account administration, security, billing, support, and legal obligations.

Merchants remain responsible for their own storefront privacy notices, permissions, and legal obligations to customers, employees, and other individuals.

Information We Collect

Depending on the features a merchant chooses, we may process:

  • Shop and account data: Shopify store domain, installation status, selected plan, billing status, granted scopes, Shopify session and access-token data, and authorized user details Shopify makes available, such as user ID, name, email, locale, and account role.
  • Product catalog data: product IDs, titles, handles, descriptions, SEO titles, meta descriptions, tags, vendor, product type, category, status, images and alt text, options, variants, collections, metafields, and related product facts.
  • Analysis and draft data: SEO scores, score history, issue flags, estimated revenue-risk signals, draft reasoning summaries, rewrite plans, generated and approved fields, AEO answer packs, claim-support records, quality decisions, validation results, model and prompt versions, before-and-after change records, and timestamps. Draft reasoning and rewrite plans may contain conclusions drawn from optional Google performance signals when those integrations are connected.
  • Usage and support data: syncs, approvals, applied changes, feature usage, AI-credit usage, subscription records, event and security logs, support messages, contact details, and internal support notes.
  • Optional Google Search Console data: OAuth tokens, granted scope, verified properties, selected site, page URLs, search queries, clicks, impressions, click-through rate, average position, comparison periods, and derived lost-click or risk signals.
  • Optional Google Analytics 4 data: OAuth tokens, account and property identifiers, selected property, product or landing-page paths, item identifiers and names, Organic Search sessions, revenue and purchase metrics, item revenue, quantity purchased, currency, date ranges, and derived attribution or risk signals.
  • Website and technical data: IP address, browser and device information, request timestamps, referring pages, and security or diagnostic information that may be processed by our hosting and security providers.

The app currently requests Shopify product read and write permissions. It does not request Shopify customer, order, address, or payment-card scopes. Shopify handles app billing and payment information; Revenue Reactor does not receive full payment-card details. If a merchant voluntarily places personal information in product content or a support request, that information may be processed as part of that content.

How We Use Information

We use information to:

  • Authenticate merchants and operate the embedded Shopify app.
  • Sync and analyze product data, calculate SEO and AEO readiness, and identify product-page issues.
  • Display optional Search Console and GA4 performance context and estimate which products may present greater organic revenue risk.
  • Generate source-backed rewrite drafts, metadata, product facts, image-alt suggestions, tags, AEO answer packs, and supporting analysis.
  • Let merchants review and edit saved drafts, approve and apply changes one at a time, or use the separate bulk-draft and bulk-apply steps available on eligible plans.
  • Administer plans, usage limits, support, service communications, security, fraud prevention, diagnostics, and legal compliance.
  • Maintain app reliability, safeguards, scoring, and user-facing features. We do not use connected Google data to train a generalized AI model.

Legal Bases Where Applicable

Where a law requires a legal basis, we process information as needed to perform our agreement with the merchant, pursue legitimate interests in operating and securing the service, comply with law, and honor consent for optional connections such as Google Search Console and GA4. A merchant can withdraw an optional Google connection by disconnecting it, although prior lawful processing remains valid.

Google User Data and Limited Use

Google Search Console and Google Analytics 4 (GA4) are optional, read-only integrations. Revenue Reactor uses connected Google data only for merchant-requested features shown in the app, such as search-performance insights, organic revenue-risk calculations, product prioritization, and rewrite analysis requested by the merchant.

When a merchant requests an AI rewrite, Revenue Reactor may send OpenAI the Shopify product information needed for that rewrite together with limited product-level signals derived from connected Google data. Examples include clicks, impressions, click-through rate (CTR), average ranking position, current-versus-prior-period comparisons such as lost clicks, relevant product search queries, organic-issue and confidence signals, and applicable organic-performance or revenue-risk estimates. OpenAI does not receive the merchant's Google OAuth tokens, Google credentials, or direct access to the merchant's Google account.

We do not sell Google user data, use it for advertising, or use it to train our own generalized AI models. Revenue Reactor's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.

Merchants can disconnect either integration inside Revenue Reactor and can also revoke Revenue Reactor's access through their Google Account. The specific records removed on disconnect, uninstall, and full shop redaction are described below.

AI Processing and Merchant Approval

When a merchant requests an AI-assisted rewrite, Revenue Reactor may send OpenAI relevant Shopify product data, source facts, image URLs or image evidence, existing product copy, internal quality rules, and the limited performance signals described above. OpenAI returns a proposed rewrite package and supporting analysis, which Revenue Reactor stores with the merchant's shop records. AEO answer-pack content is stored separately and is not applied to Shopify by the current apply workflow.

Generating a draft does not update Shopify. In the one-product workflow, the merchant reviews and approves a saved draft before applying it. Eligible paid plans also provide a two-step bulk workflow: Bulk Draft first creates saved drafts, and Bulk Apply is a separate action that presents the batch for confirmation. After the merchant confirms that batch, Revenue Reactor may approve the draft-ready copy in that confirmed batch and apply each saved draft one product at a time. The bulk workflow does not require a separate individual approval click for every draft in the confirmed batch.

AI output can be inaccurate, incomplete, or unsuitable. Merchants are responsible for reviewing saved drafts before using individual or bulk apply. Revenue Reactor does not currently provide a restore or revert feature for an applied rewrite.

OpenAI's current API data controls state that API inputs and outputs are not used to train OpenAI models unless the API customer opts in. OpenAI's published controls also describe retention for Responses API application state and abuse-monitoring logs; those provider rules apply to data sent for a requested rewrite.

How We Share Information

We disclose information only as reasonably necessary to operate the service, including to Shopify; Google when a merchant connects Google services; OpenAI for requested AI features; and hosting, database, security, monitoring, billing, and support providers acting for us. These providers may process information only for the services they provide to us and under their applicable agreements.

We may also disclose information to comply with law or valid legal process, protect rights and safety, investigate abuse or security incidents, enforce agreements, or complete a merger, financing, acquisition, reorganization, or sale of assets subject to appropriate confidentiality and notice obligations.

No Sale or Targeted Advertising

We do not sell merchant, shopper, Shopify, or Google user data. We do not share it for cross-context behavioral advertising or use connected Google data for advertising. If our practices materially change, we will update this policy and provide legally required choices before beginning the new use.

Data Retention, Google Disconnection, Uninstall, and Full Deletion

We keep active app records for as long as reasonably needed to provide Revenue Reactor, maintain merchant-requested draft and change history, secure the service, comply with law, resolve disputes, and enforce agreements. What is removed depends on the action the merchant takes:

  • Disconnect Search Console: Revenue Reactor deletes the stored Search Console OAuth tokens and connection details, selected site and property information, imported Search Console metrics, Search Console integration activity records, and stored draft reasoning summaries and rewrite plans that may contain Google-derived reasoning.
  • Disconnect GA4: Revenue Reactor deletes the stored GA4 OAuth tokens and connection details, selected GA4 property information, imported GA4 metrics, GA4 integration activity records, and stored draft reasoning summaries and rewrite plans that may contain Google-derived reasoning.
  • Records kept after a Google disconnect: Disconnecting Google does not delete the merchant's Shopify product data, the actual generated rewrite copy, approved rewrite fields, or changes already applied to Shopify. Those are merchant product and app records rather than stored Google metrics.
  • Uninstall Revenue Reactor: When Revenue Reactor receives Shopify's app-uninstalled notice, it marks the shop as uninstalled and runs the same removal process for both Google integrations. Uninstalling does not by itself delete every non-Google Revenue Reactor record.
  • Full Shopify shop redaction: When Revenue Reactor receives a valid Shopify shop-redaction request, it deletes the shop's stored app data from the primary application database, including Shopify sessions, products, rewrite drafts, product-change records, product metrics, AI and feature-usage records, subscriptions, support records, internal notes, app activity, Google records, and the shop record.

The deletion actions above remove records from Revenue Reactor's active application database. Limited copies may remain temporarily in service-provider logs or backups where maintained for security, recovery, legal compliance, or abuse prevention, and are handled under the applicable provider retention process and law.

Merchants may request access, correction, or deletion by emailing hello@revenuereactorapp.com. We may need to verify the request and the requester's authority.

Security

Google OAuth access and refresh tokens are encrypted before they are stored. Revenue Reactor refuses new Search Console and GA4 connections when secure token encryption is not configured, and it does not fall back to storing new Google tokens in plaintext. Stored tokens in an unrecognized or unsafe format cannot be used and require reconnection.

We also use reasonable administrative, technical, and organizational safeguards designed to protect information, including access controls, authenticated integrations, transport security, and production-secret management. No online system is perfectly secure. We cannot guarantee that unauthorized access, loss, misuse, or disclosure will never occur.

International Processing

Revenue Reactor and its service providers may process information in the United States and other countries where they operate. Those countries may have different data-protection laws. Where required, we use lawful transfer mechanisms and contractual protections.

Your Rights and Choices

Depending on location and applicable law, an individual may have rights to request access, correction, deletion, portability, restriction, objection, withdrawal of consent, or an appeal of a denied privacy request. We will not discriminate for exercising a legally protected privacy right.

  • Uninstall Revenue Reactor through Shopify.
  • Disconnect Search Console or GA4 inside the app and revoke Google access through Google.
  • Contact us to request access, correction, deletion, or other applicable privacy rights.

Cookies and Similar Technologies

Revenue Reactor may use strictly necessary cookies or similar technologies for authentication, session continuity, security, and essential service operation. Hosting and security providers may process request logs. We do not currently use merchant or Google data for targeted advertising cookies.

Children

Revenue Reactor is a business service for Shopify merchants and is not directed to children. We do not knowingly collect personal information from children under 13 or the minimum age required by applicable law.

Changes to This Policy

We may update this Privacy Policy as the app, providers, or legal requirements change. We will post the revised policy, update the effective date, and provide additional notice or consent when required by law or Google API policy.

Contact

Questions, legal notices, and privacy requests can be sent to:

Revenue Reactor Labs LLC
801 East Baseline Road
Lafayette, Colorado, USA
hello@revenuereactorapp.com

Revenue Reactor Labs LLC Privacy | Terms