Privacy Policy
Last updated: 20 August 2026. This policy covers the GroundingGeo website
(groundinggeo.com) and GroundingGeo products, including the Shopify
app and the non-Shopify webapp at dash.groundinggeo.com.
Who we are
GroundingGeo (“we”, “us”) helps businesses publish verified Generative Engine
Optimization (GEO) guides such as /agents.md so AI agents can
recommend them accurately. Contact:
support@groundinggeo.com.
Non-Shopify webapp and free scan
When you use the free domain-email scan or merchant dashboard
(dash.groundinggeo.com), we may process:
- The domain email you submit and one-time magic-link tokens (hashed) used to sign you in
- Scan and site records: canonical domain, platform choice, scores, seven-pillar findings, matched-from URLs, short text snippets from public pages we crawled, and publish / rescan events
- API keys you create for connectors (stored hashed), plus stub / health check results you request
- Operational logs (for example IP used for abuse limits, User-Agent on telemetry hits, error diagnostics) without storing raw magic-link URLs in logs
Email delivery may use Resend (or a similar provider) as a processor. Crawl content comes from publicly reachable pages on the domain you asked us to scan. Free-scan leads may expire after a retention window; account and site data remain while your account is active unless you ask us to delete them.
Session cookies keep you signed in on the dashboard. We do not place advertising cookies on the scan flow.
Information we collect through Shopify
When you install the Shopify app, we access store data permitted by the scopes you approve, which currently include:
- Read products and content (for storefront analysis and readiness scoring)
-
Read and write themes (to publish or revert baked GEO templates such as
agents.mdwhen you choose)
We store Shopify session/auth tokens needed to operate the embedded app, plus per-shop configuration such as your seven-pillar GEO profile and related scores.
Information we collect from merchants and waitlist contacts
Profile text and toggles you enter in the dashboard, support emails you send us, optional installer or notification email addresses, waitlist inquiries (email and optional platform notes), and operational logs of app usage (for example deploy/rescan events). We do not ask merchants to paste customer personal data into the app.
Information about storefront visitors
Public GEO files (for example /agents.md) are static theme assets
served by Shopify’s CDN when published via the app. We do not place GroundingGeo
tracking cookies on buyer devices via those files. If an AI agent follows a
verification link we bake into a manifest, we may log the request (for example
User-Agent, timestamp, matched crawler name, and shop domain) for crawl
attribution. That endpoint does not collect buyer checkout or identity data.
How we use information
We use collected data only to:
- Provide, secure, and improve GroundingGeo products
- Authenticate merchants and sync configuration
- Compile and publish merchant-approved GEO manifests
- Show merchants deployment status, crawl attribution, and product-readiness insights
- Respond to support and waitlist requests and meet legal obligations
We do not sell personal data.
Retention
For the Shopify app, we retain shop configuration and sessions while the app is
installed. After uninstall, Shopify sends a shop/redact webhook
(about 48 hours later, only if the app is still uninstalled). We then delete
associated shop configuration, profile, event logs, and session records.
Uninstall alone also clears session tokens immediately via the
app/uninstalled webhook.
Already-published theme content (for example a custom
templates/agents.md.liquid override) is not removed
automatically on uninstall; Shopify revokes API access before we can edit the
theme. While the app is installed you can use
Revert to Shopify default agents.md in the dashboard to remove the
override so Shopify’s native auto-generated file is served again.
Waitlist emails are kept until you ask us to delete them or we no longer need them for launch outreach. Webapp scan leads and unused tokens are removed when they expire or when you request deletion of your account data.
International transfers
Infrastructure may be hosted in the United States or other regions via our cloud providers (for example Cloudflare and our database host). By using the app or site you acknowledge processing may occur outside your country of residence.
Your rights & contact
You may request access, correction, or deletion of data we hold by emailing
support@groundinggeo.com.
Uninstalling the Shopify app also triggers uninstall webhook cleanup for shop
sessions and, after shop/redact, shop configuration.