Privacy policy
SEOBoss Blog Engine - App Privacy Policy
Effective date: 17 July 2026
This Privacy Policy explains how Dotcom Publishing, trading as SEOBoss ("SEOBoss", "we", "us", or "our"), collects, accesses, uses, stores, shares, and deletes information when a merchant installs or uses the SEOBoss Blog Engine Shopify application (the "App") and its related services (together, the "Services").
The Services include the embedded Shopify Admin app, supported Shopify theme or app-extension features, content generation and publishing workflows, media-generation features, optional Google Search Console features, and the systems used to operate and support them.
This policy applies to information processed through the Services. It does not replace the privacy policy of a merchant's own Shopify store.
1. Who we are and how to contact us
Dotcom Publishing, trading as SEOBoss
Email: robbie@seoboss.com
Address: 4 Ranfurly Terrace, Mount Cook, Wellington, New Zealand
Questions, privacy requests, and deletion requests can be sent to the email address above.
2. Our role
Shopify merchants control the information in their stores and are generally the controller of that information. SEOBoss processes merchant and store information to provide the Services and may act as a processor or service provider on the merchant's behalf. SEOBoss may act as a controller for limited information used for account administration, security, support, billing administration, legal compliance, and service operations.
If you are a customer of a merchant using SEOBoss, please contact that merchant first about your personal information.
3. Information we collect or access
A. Information accessed from Shopify
When a merchant installs or uses the App, SEOBoss accesses Shopify information only as needed to provide the Services. Depending on the features used, this may include:
- shop identifiers, such as the store's
myshopify.comdomain and related tenant identifiers; - store profile and configuration information;
- products and product information, including titles, descriptions, URLs, images, availability, and other product details used for store-aware content and media features;
- pages and blog content, including titles, URLs, article bodies, tags, metadata, publication state, and featured images;
- Shopify Files or media-library information needed to upload, select, or attach article and social-media images;
- app installation, subscription, billing-plan, and entitlement information used to enable features and enforce allowances; and
- Shopify access credentials required to operate the App for the merchant. Offline Shopify access tokens are stored encrypted at rest.
SEOBoss does not request access to Shopify Orders or Payments and does not require access to Shopify customer lists. Payment-card information is handled by Shopify and is not received or stored by SEOBoss.
B. Information provided by merchants
Merchants or their authorised staff may provide information such as:
- contact and onboarding information;
- language, market, niche, audience, tone, keyword, publishing, and content preferences;
- article titles, writing intent, briefs, instructions, reference URLs, exclusions, and other editorial direction;
- product priorities, brand facts, claims or topics to avoid, and other store knowledge;
- drafts, edits, approvals, publishing choices, image choices, and regeneration instructions; and
- support messages and information provided when asking us for help.
C. Google Search Console information
Connecting Google Search Console is optional. If a merchant chooses to connect it, SEOBoss requests the read-only permission https://www.googleapis.com/auth/webmasters.readonly. This permission allows SEOBoss to view Search Console information for properties the Google user is authorised to access. It does not allow SEOBoss to modify Search Console properties, settings, or search results.
Depending on the feature used, SEOBoss may access and store:
- the list of Search Console properties available to the connected Google account and the property selected for the store;
- search-performance information such as pages, queries, clicks, impressions, click-through rate, average position, and reporting dates;
- derived performance signals, such as pages or topics with existing traction, potential opportunities, or limited visibility;
- URL Inspection results and cached indexing-status information requested through the App; and
- connection status, synchronisation timestamps, and encrypted Google OAuth refresh credentials needed to maintain the optional connection.
SEOBoss uses Google Search Console information only to provide merchant-facing search-performance, visibility, indexing, editorial-planning, and content-opportunity features within the App. Relevant performance signals may be included in a request to our AI service provider solely to generate or improve the merchant-facing recommendation or content feature requested through SEOBoss.
We do not sell Google user data, use it for advertising, use it to determine creditworthiness, or make it available to data brokers. SEOBoss personnel do not routinely review an individual merchant's Google Search Console data. Human access is limited to situations where the merchant authorises support, where access is necessary to investigate security or abuse, where required by law, or where information is aggregated for legitimate service operations.
A merchant can disconnect Google Search Console within SEOBoss. Disconnecting revokes the connection on a best-effort basis and deletes the stored Google OAuth connection credential, stopping future collection through that connection. Previously synchronised performance or indexing records may remain with the merchant's other shop-scoped operational data until they are deleted under the retention and deletion practices below. A user can also review or revoke Google Account access through Google's account-permissions controls.
SEOBoss's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
D. Reference URLs and third-party content
If a merchant supplies a reference URL, SEOBoss may retrieve publicly available content from that URL to help produce the requested title or article. The merchant is responsible for ensuring that they are authorised to use any non-public or restricted material they provide. SEOBoss instructs its generation systems to use reference material as context and not to reproduce it unnecessarily.
E. Generated content and media
SEOBoss stores information needed to create, review, regenerate, publish, and manage content. This may include article ideas, reasoning, writing briefs, generated drafts, FAQs, metadata, internal-link suggestions, image briefs, generation prompts, generated images, social-media assets, quality information, publication state, and related job records.
F. Operational, usage, and security information
We may collect and store:
- request and job identifiers, timestamps, status, retries, and processing diagnostics;
- feature usage and allowance information;
- provider usage and cost records used to operate and account for the Services;
- error and security logs used to troubleshoot, prevent abuse, and protect the Services; and
- standard technical information received by online services, such as IP address, user agent, request time, and referring information.
We aim to avoid placing access tokens, passwords, full article content, or unnecessary personal information in operational logs.
G. Shopify compliance webhooks
Shopify may send mandatory privacy webhooks, including customers/data_request, customers/redact, and shop/redact. Depending on the request, these payloads may contain shop identifiers or limited customer identifiers. We use this information only to authenticate, process, record, and comply with the applicable request.
4. How we use information
We use information described in this policy to:
- connect and operate the App for the correct Shopify store;
- understand store products, pages, published content, editorial memory, and merchant direction;
- generate and manage article ideas, titles, briefs, drafts, FAQs, metadata, internal links, and related content;
- generate, store, and apply article-aware or product-aware hero and social-media images;
- create Shopify drafts or publish content when the merchant has enabled and authorised that workflow;
- display Google Search Console performance, visibility, indexing, and editorial insights when connected;
- provide optional automation, scheduling, assistant, and content-pipeline features;
- authenticate users and requests, verify signatures and webhooks, and protect the Services;
- administer subscriptions, feature access, trials, and allowances;
- measure service usage and provider costs;
- provide support, diagnose faults, and improve the reliability and user experience of the Services; and
- comply with legal, regulatory, Shopify, and Google requirements.
We do not sell personal information or merchant store data.
5. Artificial intelligence processing
SEOBoss uses artificial-intelligence API services to generate merchant-requested content, recommendations, article briefs, images, and related outputs. To perform these features, relevant merchant inputs and store context may be sent to an AI service provider. This can include product, page, or article information; editorial instructions; reference material; selected Google Search Console signals; and image references where needed for a requested image feature.
SEOBoss does not use merchant store data, customer data, or Google Search Console data to train its own general-purpose AI models. Our current primary AI provider is accessed through its business API. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer explicitly opts in. AI providers may temporarily retain limited API data for security, abuse prevention, legal compliance, or service delivery in accordance with their applicable terms and data controls.
Generated outputs may be inaccurate. Merchants remain responsible for reviewing and approving content, claims, links, images, and publication settings before relying on or publishing them. SEOBoss includes review controls and does not treat generated content as professional legal, medical, financial, or other regulated advice.
6. How we share information
We share information only as reasonably necessary to provide, secure, and support the Services, including with:
- Shopify, to authenticate the App, read or write authorised store content, manage billing information, upload media, and receive webhooks;
- Google, when a merchant chooses to connect or revoke Google Search Console access;
- AI service providers, to generate merchant-requested text, recommendations, and images;
- cloud hosting, database, storage, workflow, monitoring, and security providers that operate components of the Services;
- support providers, when a merchant requests assistance and sharing is necessary to resolve the request;
- professional advisers, authorities, or other parties when required by law or reasonably necessary to establish, exercise, or defend legal rights; and
- a successor in connection with a merger, acquisition, financing, reorganisation, or sale of all or part of the business, subject to applicable law and appropriate notice or consent where required.
Service providers are permitted to process information only for the services they provide to us and must handle it under their applicable contractual and security obligations.
7. International data transfers
SEOBoss is based in New Zealand. Our service providers may process information in New Zealand, Australia, the United States, Europe, or other locations where they or their infrastructure operate. Where required, we use contractual, organisational, or other safeguards intended to protect information transferred across borders.
8. Data retention and deletion
We retain information only for as long as reasonably necessary to provide the Services, maintain security and reliable operations, comply with legal and platform obligations, resolve disputes, and enforce agreements.
- While the App is installed: We retain shop-scoped content, configuration, credentials, generation records, media records, performance information, usage records, and operational data needed to provide the Services.
- Google Search Console disconnection: We stop future access through that connection and delete the stored Google OAuth connection credential. Previously synchronised shop-scoped records may remain until the merchant requests deletion or the shop-data deletion lifecycle applies.
-
App uninstall: Shopify's uninstall event deactivates App operation and automation. Some shop-scoped data may be retained temporarily to support a possible reinstall and to meet operational or legal obligations. Uninstall is separate from Shopify's later
shop/redactprivacy event. -
Shop redaction or deletion request: When we receive a valid
shop/redactrequest from Shopify, or otherwise determine that shop-scoped data must be deleted, we delete or de-identify the applicable merchant data unless retention is required by law. Minimal records may be retained where necessary to demonstrate compliance, prevent fraud, or protect legal rights, provided they do not contain unnecessary store content. - Operational and security records: Logs and diagnostic records are retained only for a limited period appropriate to troubleshooting, security, fraud prevention, and legal obligations.
- Backups: Residual copies may remain temporarily in protected backups until those backups are overwritten under the applicable backup cycle.
A merchant may request earlier deletion where legally permitted by contacting robbie@seoboss.com. We may need to verify the requester's authority over the relevant store before acting.
9. Security
We use reasonable technical and organisational safeguards designed to protect information, including HTTPS/TLS in transit, encryption of Shopify and Google OAuth refresh credentials at rest, access controls, tenant-scoped application logic, authenticated webhooks, and operational monitoring. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
10. Privacy rights and requests
Depending on applicable law, merchants and individuals may have rights to access, correct, delete, restrict, or object to the processing of personal information, or to receive a portable copy of certain information.
Merchants can submit a request to robbie@seoboss.com. We may ask for information needed to verify identity, authority over the store, and the scope of the request. If the request concerns a customer of a merchant's store, the customer should normally contact the merchant first. We will assist merchants with valid requests as required by applicable law and Shopify's privacy processes.
Individuals may also have the right to complain to an applicable privacy regulator. In New Zealand, information about privacy rights is available from the Office of the Privacy Commissioner at privacy.org.nz.
11. Children
The Services are designed for Shopify merchants and authorised business users. They are not directed to children, and we do not knowingly collect personal information directly from children through the App.
12. Changes to this policy
We may update this Privacy Policy when the Services, providers, legal requirements, or data practices change. We will publish the updated policy at this URL and update the effective date. Where required, we will provide additional notice or request renewed consent before using information for a materially different purpose.
13. Contact
Questions or requests about this Privacy Policy or SEOBoss data practices can be sent to:
Dotcom Publishing, trading as SEOBoss
Email: robbie@seoboss.com
Address: 4 Ranfurly Terrace, Mount Cook, Wellington, New Zealand