Ask friends before you buy.
This policy applies to Shopinion’s U.S. mobile application, website, purchase-import features, social commerce features, merchant services, and related support services. Features described as “when available” do not collect data until Shopinion enables them.
Prefer the app? The same policy is available in Shopinion under Privacy Policy. Questions: privacy@shopinion.ai.
Important: Shopinion Is a Social Shopping Network
- Shopinion helps users organize purchases, ask friends for advice, join product discussions, and selectively share shopping information with people or groups they choose.
- Importing a purchase does not automatically make it public. Visibility is controlled by accepted connections, category permissions, item-level choices, audience selections, and explicit public-post settings.
- Before sharing, review the selected audience and fields. A recipient may screenshot, copy, save, forward, or disclose information outside Shopinion, and Shopinion cannot control that recipient after delivery.
- Do not upload or share passwords, full payment-card data, government identifiers, unrelated private mailbox content, or highly sensitive medical, financial, legal, intimate, or reputational information unless a feature is specifically designed for it and you understand its controls.
- Shopinion uses safeguards, but no online service can guarantee absolute security. General AI chat may be processed by disclosed AI providers and may be incomplete or incorrect. Do not submit highly sensitive information through general AI chat.
- Selective sharing can provide trusted advice, product discussions, discounts, rewards, social discovery, and more relevant merchant offers. You control connections, audiences, and optional personalization settings.
This summary highlights important points and does not replace the complete Policy or limit your legal rights.
Privacy at a glance / Notice at Collection
- Shopinion is for adults age 18 and older. We do not offer accounts for minors or a parental-consent account path.
- Shopinion is a social shopping network, but your purchase wallet is private by default. You choose which accepted connections, groups, or public audiences may see selected information.
- Email and Amazon imports are optional. Raw email content is processed transiently and is not written to persistent storage. Gmail-derived data is never used for advertising.
- Shopinion may show contextual, first-party personalized, and clearly labeled sponsored content. It does not currently sell personal data or use advertising networks to target users across unrelated services. If legally regulated targeted advertising is introduced, required controls and opt-outs will be provided first.
- Sensitive purchase categories are private by default. Medical and other health-related purchase data that qualifies as consumer health data is governed by a separate Consumer Health Data Privacy Notice and separate consent; see Section 13 and that Notice for details.
- You may request access, correction, deletion, portability, consent withdrawal, advertising choices, and other applicable rights through privacy@shopinion.ai.
1. Scope and who this policy covers
This Privacy Policy explains how Shopinion Inc. (“Shopinion,” “we,” “us,” or “our”) collects, uses, discloses, retains, and protects personal data when you use the Shopinion mobile application, shopinion.ai, consumer and merchant features, purchase-import features, communications, and support services (collectively, the “Service”).
The Service is intended for use in the United States. This Policy applies to personal data processed by Shopinion. It does not govern the independent privacy practices of merchants, email providers, Amazon, Telegram, app stores, or other third-party services, although this Policy explains how Shopinion handles data received from or sent to those services.
Some features are still being developed. When this Policy says “when available,” Shopinion does not collect the related data until that feature is enabled and you choose to use it.
2. Company and contact details
Shopinion Inc. is a Delaware corporation responsible for the personal data described in this Policy.
| Purpose | Contact |
|---|---|
| Privacy questions and rights requests | privacy@shopinion.ai |
| General support | support@shopinion.ai |
| Security reports | security@shopinion.ai |
| Legal notices | legal@shopinion.ai |
| Telephone | +1 713-859-6242 |
| Mailing address | 1607 Tucumcari Dr, Houston, TX 77090, United States |
3. Eligibility and age restrictions
Shopinion is intended only for individuals who are at least 18 years old. We do not permit anyone under 18 to create or use a Shopinion account, and we do not offer a parental-consent account path.
During registration, we ask for date-of-birth information, age, or an age confirmation to determine eligibility. We may retain the eligibility result and the minimum information reasonably necessary to enforce the restriction, prevent repeat attempts, and meet legal or security obligations.
If we learn that an under-18 person created an account or provided personal data, we may suspend the account and delete the associated data, subject to limited security, fraud-prevention, or legal retention needs. A parent or guardian who believes a minor provided data may contact privacy@shopinion.ai.
Shopinion is not directed to children under 13. Our 18+ rule does not limit obligations that may apply if we obtain actual knowledge that personal information was collected from a child.
4. Personal data we collect
We collect a category only when you use the related feature. We do not ask for full payment-card numbers, government identification numbers, primary mailbox passwords, biometric identifiers, or unrelated mailbox content as part of the current Service. Please do not submit them.
| Category | Examples | Source |
|---|---|---|
| Account and authentication | Phone number; SMS or email verification status; optional email address; one-time verification codes (OTP) issued for each sign-in (temporary and not retained as account passwords); account ID; login and session records; age-eligibility information. | You; Twilio; Shopinion systems |
| Profile and eligibility | Name; username; profile photo; city or ZIP code; optional sex/gender field; student or resident selection; interests and preferences. | You |
| Connections and permissions | Friend invitations and acceptances; blocked users; selected invite contact information; category permissions; item-level visibility; groups; follower and connection activity. | You; other users; Shopinion systems |
| Purchase and receipt records | Merchant; product or service; category; date; price; currency; quantity; order status; product image or link; receipt image; order identifier; warranty, return, rating, note, and visibility fields. | You; merchants; connected email; Amazon when available |
| Connected email information | Email-provider account identifier; encrypted authorization token or provider-supported connection credential; message sender, date, subject, body, and attachment content processed transiently to identify receipts and extract purchase fields. | Gmail and, when available, Yahoo Mail and iCloud Mail after authorization |
| Amazon purchase information | Authorized order-history fields, transfer metadata, authorization status, and tokens, only when the feature is enabled and you connect it. | Amazon after your authorization |
| Content and communications | Questions; polls; responses; ratings; reviews; comments; photos; direct and business messages; service requests; surveys; reports; support communications. | You; other users; merchants |
| Offers, referrals, and rewards | QR scans; offer views and clicks; sponsored-content impressions; coupon codes; redemption status; qualifying connections; Influence; Boost; challenge activity; referral attribution; reward history; personalization choices; universal opt-out signals; anti-fraud signals. | You; merchants; other users; Shopinion systems |
| Merchant and employee data | Business contact details; business profile; employee role and permissions; offers; redemption records; business messages; dashboard and support activity. | Merchant owners, managers, and employees |
| Device, logs, and diagnostics | IP address; operating system; device and browser type; app version; language; time zone; push token; timestamps; request logs; crash and performance information; security events. | Your device; DigitalOcean; Sentry; Grafana Cloud |
| Location | ZIP code or city you provide and approximate location inferred from IP. Shopinion does not currently collect precise location for the core Service. | You; IP address |
| Inferences and classifications | Purchase category; product match; relevance; recommendation signals; offer-interest segment; category influence; source eligibility; fraud and abuse risk; moderation status. | Generated from the data above |
| Sensitive data | Health-related purchases, intimate or sexual-life information, financial or legal-service purchases, or other sensitive information only when you submit or import it and applicable consent has been obtained. | You; authorized imports; user-directed interactions |
5. Sources of personal data
- Directly from you when you register, edit your profile, upload or edit a purchase, create content, communicate, join a reward program, or change privacy settings.
- From other users when they connect with you, respond to you, share content with you, invite you, or report content.
- From participating merchants when you view or redeem an offer, make a purchase recognized through Shopinion, or communicate with a business.
- From Gmail and, when available, Yahoo Mail, iCloud Mail, and Amazon only after you actively connect the source and authorize the requested access.
- Automatically from your device and use of the Service for authentication, security, operation, diagnostics, and limited product measurement.
- From service providers acting on our behalf, such as hosting, SMS verification, monitoring, logging, uptime monitoring, and AI providers.
6. How we use personal data
| Purpose | How data is used |
|---|---|
| Provide and secure the Service | Create accounts; verify sign-in with one-time codes; maintain sessions; deliver purchase wallet, social, merchant, messaging, and support features. |
| Import and organize purchases | Identify receipts and order confirmations; extract and standardize purchase fields; let you review, edit, hide, share, or delete records. |
| Apply privacy choices | Enforce accepted-connection, category, item, blocked-user, sensitive-data, and public-content settings. |
| Calculate rewards and discounts | Determine eligibility, Influence, Boost, challenges, referrals, coupons, redemptions, and fraud checks under disclosed program terms. |
| Personalize within Shopinion | Organize feeds, search, reminders, organic recommendations, and merchant offers using in-Service data permitted by your settings. |
| Show contextual and sponsored content | Select offers from your current search, page, product, merchant, category, approximate location, and Shopinion activity; measure performance; and use eligible imported purchase records only when a separate setting is available and enabled. Gmail-derived data and sensitive categories are excluded. |
| Communicate | Send verification, account, security, connection, question, offer, coupon, privacy-request, and support messages; send marketing only with applicable choices. |
| Protect users and the Service | Prevent fake accounts, coupon abuse, harassment, fraud, security incidents, and policy violations; investigate reports. |
| Operate and improve | Monitor reliability, diagnose errors, understand feature performance, and improve the Service using logs and aggregated or deidentified information. |
| Comply with law and protect rights | Respond to lawful process, audits, disputes, and legal obligations; establish or defend claims. |
7. Email receipt imports
7.1 Optional and user-initiated
Shopinion’s email receipt-import feature is optional and is requested only when you tap an import or connect action. It is not requested as a condition of registration. Supported providers are planned to include Gmail, Yahoo Mail, and iCloud Mail.
7.2 Gmail architecture
- Gmail access uses the read-only Gmail permission requested in context when you initiate import.
- The authorization exchange occurs on Shopinion’s server. The mobile app does not receive or store the provider token.
- Refresh tokens are encrypted at rest and associated with the relevant Shopinion user account.
- Shopinion searches only messages from recognized merchant senders and within a bounded time window. It does not use the connection to send, delete, move, label, mark as read, or modify messages.
- Disconnecting Gmail causes Shopinion to request revocation through Google’s revocation mechanism and delete the Shopinion-held token.
7.3 What is processed and retained
Receipt and order-confirmation content is processed in transit and transient memory to extract limited purchase fields such as merchant, order date, item, quantity, total, price, and order status. Raw email bodies and attachments are not written to Shopinion’s persistent storage and are discarded after parsing. Shopinion retains only the extracted purchase record, the minimum connection metadata, and the encrypted token while the connection remains active.
Shopinion does not create a mailbox archive, use connected email data for advertising, sell connected email data, or use it to train a general-purpose AI model. Routine human reading is prohibited. Human access may occur only with your specific support authorization, for a security or abuse investigation, to comply with law, or for an authorized compliance audit, and access is restricted and logged.
For Yahoo Mail or iCloud Mail, the connection screen will describe the provider-supported authorization method before you connect. Shopinion will not request or store your primary mailbox password. If a provider requires an app-specific credential, the screen will identify that requirement and Shopinion will protect and delete the credential when the connection is removed.
Google user data is handled in accordance with the Google API Services User Data Policy, including the Limited Use requirements, when applicable.
These restrictions apply to raw Google user data and to information aggregated, anonymized, deidentified, or derived from it. Shopinion does not use or transfer Gmail-derived data for serving ads, retargeting, personalized or interest-based advertising, merchant audience targeting, or advertising-profile creation.
8. Amazon purchase import
Shopinion is pursuing Amazon authorization and security review for a U.S. purchase-import feature. No Amazon purchase data is collected until Shopinion enables the feature and you voluntarily connect your Amazon account. When available, the feature will request only the read-only purchase fields needed for the purchase wallet and will display the requested data categories and authorization terms before you approve access.
Possible imported fields include product name, marketplace, order date, price, quantity, order status, return status, order identifier, product image, and product link, depending on Amazon’s authorized scope.
Shopinion will not use the connection to place orders, change your Amazon account, access payment-card details, or post on your behalf.
Authorization credentials will be encrypted, retained only while connected, and deleted or revoked when you disconnect or authorization expires.
You will be able to delete individual Amazon-derived records or all Amazon-derived purchase records without deleting the entire Shopinion account.
Shopinion will use Amazon-derived data for personalized merchant offers only if Amazon’s final authorization and applicable terms permit that use and you separately enable it. Otherwise, Amazon-derived data is used only for the user-facing purchase wallet and related requested features.
9. Purchase wallet, social sharing, audience controls, and privacy risks
Shopinion is designed for selective social sharing. Importing or creating a purchase record does not automatically disclose it to another user, a merchant, or the public.
Private by default
- Your purchase wallet is not a public profile.
- A purchase record becomes visible to another person only through an accepted connection, category permission, item-level choice, group/audience choice, or an explicit public post or review setting.
- Sensitive categories—including medical, intimate, hygiene, financial, and legal/professional purchases—are private or paused by default.
Accepted connections. Basic profile information may be shown to help people find, invite, accept, manage, or block connections.
Category permissions. You choose which purchase categories a particular accepted connection may see.
Item controls. Where available, you may edit, hide, share, pause, delay, or delete an individual purchase record.
Public content. A review, post, photo, or other item is public only when the interface clearly identifies that choice and you affirmatively select it. Public content may be copied or shared by others.
Blocking. Blocking prevents new direct interaction and limits visibility as described in the app, but it may not remove copies already received or records retained for safety and legal purposes.
Audience review. Before sharing, review who will receive the information and which fields will be visible, including product, merchant, price, purchase date, photo, rating, or comment.
Recipient conduct. People who receive shared information may save, screenshot, copy, forward, or disclose it outside Shopinion. Deleting or hiding an item later may not remove copies already obtained by another person.
Sensitive information caution. Do not share passwords, verification codes, full payment-card details, government identifiers, unrelated mailbox content, or highly sensitive medical, financial, legal, intimate, or reputational information through ordinary social, messaging, or general AI features.
10. Merchant offers, advertising, sponsored content, and deidentified reporting
Shopinion may display merchant offers, paid placements, and recommendations inside the Service. The data used and the privacy choices available depend on the type of content described below.
10.1 Types of offers and advertising
| Type of content or advertising | Current status and data use |
|---|---|
| Contextual offers | Shopinion may select an offer from the current search, page, product, merchant, category, or approximate location. This does not use connected purchase history. |
| First-party Shopinion personalization | Shopinion may rank offers or content using actions within Shopinion, such as searches, saves, category interests, offer views, redemptions, questions, friend signals permitted by your settings, and privacy choices. |
| Imported-history personalized offers (when available) | This feature is not enabled unless Shopinion provides a separate setting. It may use eligible non-sensitive purchase records from a source whose terms permit advertising use. Gmail-derived data is excluded. The setting will remain off until you affirmatively enable it. |
| Advertising outside Shopinion | Shopinion does not currently use Shopinion activity to target ads to you on unrelated apps or websites. If introduced, it will have a separate setting that is off by default, required notices and opt-outs, and applicable universal opt-out handling. |
Some in-app personalized offers based on activity from another business or connected source may qualify as targeted advertising or cross-context behavioral advertising under applicable state law even when the merchant does not receive your identity. Shopinion will treat applicable processing as regulated advertising and provide the required choices.
10.2 Gmail and sensitive-data exclusions
Google User Data obtained through Gmail APIs, including data aggregated, anonymized, deidentified, or derived from it, is not used or transferred for advertising, retargeting, personalized or interest-based advertising, merchant audience targeting, or advertising-profile creation.
Shopinion does not use consumer health data, private messages, highly sensitive purchase categories, passwords, government identifiers, or full payment-card information to select advertising or merchant audiences. Amazon-derived data may be used only when Amazon’s terms permit it and the separate user choice described above is enabled.
10.3 Sponsored labels and “Why am I seeing this?”
Paid content will be clearly identified using a label such as “Sponsored,” “Merchant Offer,” “Promoted,” or “Rewarded Recommendation.” A friend recommendation, verified-purchase signal, or social-trust explanation will be displayed separately from the fact that a merchant paid for placement or funded a reward.
Where available, a “Why am I seeing this?” explanation will identify the general factors used, such as your current search, product or category context, approximate area, Shopinion activity, or an optional imported-history setting. The explanation will not reveal another user’s private information.
10.4 What merchants receive
A merchant does not receive your complete purchase history, private messages, or friend list merely because you view or redeem an offer. Depending on the feature, a merchant may receive the coupon or redemption code, the relevant offer and discount, redemption time and status, information you intentionally send in a business message or service request, and limited account information needed to provide a requested service or resolve a redemption.
10.5 Aggregate and deidentified reporting
Shopinion may provide merchants or advertisers with aggregate or deidentified reporting about offer views, clicks, redemptions, repeat activity, broad shopping trends, referral paths, and campaign performance. Shopinion takes reasonable measures to prevent deidentified information from being associated with a consumer or household, publicly commits to maintain and use it in deidentified form and not attempt to reidentify it except to test the effectiveness of deidentification, and contractually requires recipients not to reidentify it. Shopinion also applies minimum group-size and other safeguards where necessary to reduce singling-out risk.
10.6 Advertising and personalization choices
| User control | Effect |
|---|---|
| Personalize my Shopinion experience | Controls optional use of Shopinion activity for recommendations and merchant offers. Core functions and contextual offers based on the current interaction may still operate. |
| Use eligible imported purchase records to personalize merchant offers | When available, this setting will be off until you enable it, will exclude Gmail-derived data and sensitive categories, and may be turned off later. Turning it off stops future use for this purpose. |
| Personalized advertising outside Shopinion | This is not currently available. If introduced, it will be a separate setting that is off by default. Turning it off will not remove contextual offers shown during your current Shopinion interaction. |
Before Shopinion begins any processing that constitutes sale, sharing for cross-context behavioral advertising, or targeted advertising, it will provide a readily accessible “Your Privacy Choices” control, honor applicable browser-based Global Privacy Control signals and equivalent app choices, and continue to accept requests through privacy@shopinion.ai.
10.7 Advertising measurement and future technology
Shopinion may measure offer and sponsored-content performance using first-party event data. Shopinion does not currently use third-party advertising cookies or mobile advertising SDKs to track users across unrelated services. Before introducing a third-party advertising or measurement provider that receives personal data, Shopinion will update this Policy, identify the provider and purpose, implement required contracts, and provide required notice, consent, or opt-out controls.
11. Notice of financial incentive and reward programs
This section is Shopinion’s Notice of Financial Incentive for voluntary merchant-funded discounts, Welcome Rewards, referral rewards, challenges, Influence, Boost, and similar reward programs. The specific enrollment screen or offer will disclose the material terms and value before you opt in.
11.1 Program summary and data involved
Shopinion may provide a discount, free item, access benefit, coupon, status benefit, or other reward when you perform qualifying actions. Qualifying actions may include registering and verifying an account, accepting category connections, inviting friends, sharing selected purchase information, asking or answering shopping questions, completing a purchase-import connection or reviewing imported records, viewing or redeeming an offer, completing a challenge, or generating a verified referral.
Shopinion may use account identifiers, connection and category information, selected purchase or offer activity, social actions, referral attribution, reward history, redemption records, and fraud signals to administer the program. Raw email content, Gmail-derived purchase details, private messages, and consumer health data are not disclosed to merchants or used to select advertising. A disclosed challenge may reward the user-facing act of completing an import connection or reviewing imported records, but Gmail-derived content is not used for merchant audience targeting. Merchants receive aggregate or deidentified reporting rather than identifiable shopping histories.
11.2 How to opt in and withdraw
You opt in by taking the affirmative enrollment or redemption action shown for the program. Participation is voluntary. You may withdraw from future participation through the applicable reward settings when available or by contacting privacy@shopinion.ai. Withdrawal does not reverse a completed redemption, but it may end future eligibility. Deleting information necessary to administer a program may also end participation in that program.
11.3 Good-faith estimate of value
The value of personal data varies by merchant, offer, category, referral, and user activity. Shopinion’s good-faith estimate for a particular program is the value of the benefit disclosed to you before enrollment, subject to the methodology below. The benefit is intended to be reasonably related to the expected value that Shopinion and the participating merchant receive from the qualifying data and activity.
Shopinion estimates value by considering: (a) the merchant’s expected savings in advertising, customer-acquisition, targeting, and market-research costs from aggregated or deidentified shopping signals; (b) expected incremental sales, repeat business, or gross profit attributable to the qualifying activity; (c) Shopinion fees or other revenue attributable to the program; (d) the amount, quality, and usefulness of the data and activity; (e) redemption, attribution, and fraud rates; and (f) the cost to fund and operate the program. The dollar or percentage value shown for the benefit is the program-specific estimate and may vary from one offer to another.
11.4 Non-discrimination and endorsements
Shopinion will not unlawfully discriminate against you for exercising a privacy right. A voluntary program may provide a different price or service level only under disclosed terms and when reasonably related to the value of the relevant data. Rewards are not conditioned on a positive review. When a reward creates a material connection to a post, review, or referral, Shopinion may label the content as rewarded, incentivized, or shared in connection with a Shopinion benefit.
12. Artificial intelligence, automated processing, and AI data boundaries
12.1 Current general AI chat
Shopinion currently uses OpenRouter to route general chat-widget and Telegram-bot requests to Anthropic. These general chat features are separate from the purchase wallet and are not intentionally provided with connected email data, Amazon data, purchase records, or consumer health data. The server-side API key is not exposed to users.
Text that you choose to submit to the chat widget or Telegram bot is transmitted to OpenRouter and Anthropic to generate a response. Provider handling, retention, and model-improvement practices depend on the selected endpoint, account settings, and provider terms. Shopinion has not enabled a contractual zero-data-retention arrangement for this general chat feature. Do not submit passwords, payment data, purchase records, consumer health data, or other sensitive information to the general chat or Telegram bot.
12.2 Other AI-assisted features
Shopinion may later use rules, machine learning, or AI to match products, categorize purchases, suggest privacy redactions, summarize friend responses, assist search or recommendations, detect fraud, moderate content, and help support users. Before a new AI feature uses additional personal data or changes a material purpose, Shopinion will update disclosures and obtain consent where required.
AI-generated categories, summaries, recommendations, and fraud flags may be incomplete or incorrect. You may edit purchase records, report errors, and request review of an account or reward decision. Shopinion does not currently use automated decisionmaking to make significant decisions about employment, housing, credit, insurance, education admission, health-care eligibility, criminal justice, or access to essential services.
12.3 AI data boundaries and user caution
Shopinion controls which product feature may send data to an AI provider. The current general chat does not have direct access to the purchase wallet, connected email accounts, Amazon purchase data, private messages, or consumer health data. If a future AI feature uses purchase or social data for a user-facing function, the feature will provide a purpose-specific notice, use the minimum data reasonably necessary, and obtain consent where required.
No online or AI system can guarantee absolute security or perfect accuracy. Do not enter passwords, verification codes, payment information, government identifiers, private health information, or other highly sensitive information into a general AI chat feature. AI output may be incomplete, incorrect, or unsuitable for your circumstances and should not replace professional medical, legal, financial, or other expert advice.
Shopinion does not authorize AI providers supporting the general chat to use Shopinion data for independent advertising. Provider retention, logging, human-access, and model-improvement practices remain subject to the selected provider endpoint, account settings, and terms described in Section 12.1.
13. Sensitive data and consumer health data
Purchase records can reveal sensitive information, including health conditions, sexual or intimate life, financial circumstances, precise location, citizenship or immigration status, or other protected characteristics. Shopinion uses sensitive data only for the user-requested Service, security, legal compliance, and other purposes permitted by law, and does not use sensitive purchase categories for cross-context advertising or unrelated merchant targeting.
For consumer health data, the separate Shopinion Consumer Health Data Privacy Notice supplements this Policy and controls where it is more specific. Shopinion is not a health-care provider, health plan, pharmacy, or HIPAA covered entity. Purchase and receipt data can nevertheless reveal or permit an inference about a person’s health and may be protected by consumer health data laws outside HIPAA.
Consumer health data may include: health-related purchase information that identifies or reasonably permits an inference about a physical or mental health condition, diagnosis, treatment, medication, supplement, medical device, health-care service, reproductive or sexual health, pregnancy, gender-affirming care, substance use, disability, or similar status; health-related labels and categories you add; health-related content you choose to provide; imported health-related records from authorized email or Amazon sources when available and after required consent; and health inferences only when you request a health-related feature and Shopinion obtains required consent. Ordinary toiletry or household purchases are not treated as health data unless Shopinion processes them to identify or associate you with a health status. Shopinion does not currently collect clinical medical records, health-insurance records, genetic data, biometric identifiers, wearable-device data, or precise location associated with a health-care facility as part of the current product design.
Sources may include you; Gmail and, when available, Yahoo Mail or iCloud Mail after authorization and required consumer-health-data consent; Amazon when the feature is enabled and consented; participating merchants for a health-related transaction you initiate; and other users only when they send health-related content to you or you participate in a health-related discussion. Shopinion uses consumer health data to create and maintain a private purchase record at your request; let you search, organize, correct, hide, delete, or privately share it according to your settings; provide a health-related feature you explicitly request; secure the Service, prevent fraud or abuse, respond to support, and comply with law; and produce aggregated or deidentified statistics only when the information cannot reasonably be linked to a person and Shopinion applies safeguards against reidentification. Shopinion does not use consumer health data to determine eligibility for employment, housing, credit, insurance, education, health care, or essential services.
Before Shopinion enables an email, Amazon, or health-related feature that may collect or retain consumer health data, Shopinion will present a separate, affirmative consent request describing the categories of health data, source, purpose, and how consent may be withdrawn. That consent will not be obtained through acceptance of general Terms of Service or through a preselected control. Consent to share consumer health data is separate and distinct from consent to collect it. Before sharing, Shopinion will identify the data, recipient or category of recipients, purpose, and how you can withdraw consent. You may withdraw consent through the applicable privacy control when available or by emailing privacy@shopinion.ai. Withdrawal does not affect processing that lawfully occurred before withdrawal.
Shopinion does not sell consumer health data and does not use it for advertising-network targeting. Shopinion may share consumer health data only as permitted by applicable law and as described in the Notice: with another Shopinion user when you specifically direct sharing within your visibility settings; with DigitalOcean as Shopinion’s U.S. hosting and storage provider under contractual restrictions; with a merchant when necessary to complete or support a health-related transaction you initiated and the disclosure is identified at the time; with security, legal, or safety recipients when permitted and reasonably necessary; and as part of a corporate transaction only as permitted by consumer health data law and subject to any required notice, consent, or authorization. Sentry and Grafana Cloud are configured not to receive consumer health data as message or purchase content. OpenRouter and Anthropic are used only for the general chat widget and Telegram bot and are not intentionally provided purchase records or consumer health data. Shopinion does not share consumer health data with advertising networks, data brokers, or merchants for unrelated targeting.
Where applicable, you may confirm whether Shopinion is collecting, sharing, or selling consumer health data and access the data Shopinion holds; receive a list of third parties or affiliates with whom Shopinion shared or sold consumer health data when required; withdraw consent for collection or sharing; delete consumer health data and require Shopinion to notify applicable processors and other recipients; appeal a refusal where applicable; and exercise these rights without unlawful discrimination. Submit requests to privacy@shopinion.ai or through an available in-app privacy control. Shopinion generally responds within 45 days after receipt (extendable once by 45 days where permitted). Appeals may be sent to privacy@shopinion.ai with the subject “Consumer Health Data Appeal.”
Raw email bodies and attachments are not written to persistent storage and are discarded after purchase-field extraction. Health-related purchase records remain until you delete the record or account, withdraw consent and request deletion, or the record is no longer needed for the requested purpose. After authenticating a deletion request, Shopinion deletes consumer health data from active systems within 30 days and notifies applicable processors and other recipients so they can honor the request. Rolling backups may retain deleted consumer health data for up to 30 days before rotation.
Shopinion does not implement a geofence around an entity that provides in-person health-care services for the purpose of identifying, tracking, collecting data from, or sending health-related messages or advertisements to a person. Shopinion restricts access to consumer health data to personnel and providers who need it for the consented or user-requested purpose and uses administrative, technical, and physical safeguards appropriate to the nature and volume of the data.
14. Disclosures and service providers
14.1 When we disclose personal data
| Recipient | Purpose and limits |
|---|---|
| Other users | Only according to your connection, category, item, message, group, review, and public-content choices. |
| Participating merchants | To provide offers, redemptions, support, business messaging, and permitted aggregated or deidentified analytics. |
| Service providers | To host, authenticate, monitor, log, secure, support, and operate the Service under access and use restrictions. |
| Connected-service providers | To authorize, operate, or revoke the email or Amazon connection you requested. They have their own privacy practices. |
| Legal and safety recipients | When reasonably necessary to comply with law, valid process, protect rights and safety, investigate fraud or abuse, or defend claims. |
| Corporate transaction participants | In a financing, merger, acquisition, reorganization, bankruptcy, or asset transfer, subject to confidentiality and applicable notice, consent, and health-data restrictions. |
| At your direction | When you request a disclosure or intentionally make content public. |
14.2 Current production providers
| Provider | Purpose | Data |
|---|---|---|
| DigitalOcean | U.S. hosting, database infrastructure, and file/object storage | Account, profile, purchase, content, and technical data as needed to host the Service |
| Twilio | SMS verification (one-time codes) | Phone number, verification request, and delivery/status data |
| Sentry | Error monitoring | Technical error data; Shopinion configures personal-data collection off, but incidental technical information may appear in an error report |
| Grafana Cloud | Application logs and monitoring | Technical logs and security/operational events; logs are not intended to contain purchase or message content |
| OpenRouter | Routes general chat-widget and Telegram-bot prompts to a model provider | Text voluntarily entered into those features and technical request metadata; no intentional purchase or health data |
| Anthropic | Generates responses for the current general chat and bot | Text voluntarily entered into those features and technical request data under provider terms |
| UptimeRobot | External uptime checks | Service availability information; no user personal data is intentionally provided |
Google, Yahoo, Apple/iCloud, and Amazon act as user-directed connected sources when you authorize an import. They are not Shopinion subprocessors for the purchase data they provide. Telegram is a third-party platform whose own privacy policy applies when you use the Shopinion Telegram bot.
15. Cookies, logs, diagnostics, advertising technologies, and Global Privacy Control
Shopinion uses necessary cookies, local storage, session technologies, authentication records, and server logs to sign users in, maintain sessions, remember settings, secure the Service, and operate requested features. Shopinion currently uses Sentry and Grafana Cloud for error and operational monitoring and does not currently use third-party advertising cookies or mobile advertising SDKs to track activity across unrelated services.
If Shopinion later introduces non-essential analytics, advertising cookies, advertising SDKs, or third-party measurement technologies, Shopinion will update this Policy before activation, identify the relevant categories of data and recipients, and provide consent or opt-out controls where required.
Where applicable, Shopinion recognizes Global Privacy Control or another legally recognized universal opt-out mechanism for sale, sharing, or targeted-advertising processing on the website. A universal opt-out signal may not disable contextual offers or core first-party personalization that is not legally subject to the opt-out. If applicable regulated advertising is offered in the mobile app, Shopinion will provide a corresponding in-app privacy choice.
Because Shopinion does not currently sell personal data, share it for cross-context behavioral advertising, or use personal data for targeted advertising outside Shopinion, a universal opt-out signal does not change current processing. It will be honored before and if applicable processing is introduced.
16. Data retention
Shopinion retains personal data only for as long as reasonably necessary for the purpose described, to honor your choices, and to meet security, fraud-prevention, accounting, dispute, audit, or legal needs. The period below applies only when the corresponding feature is active.
| Data | Retention period or criteria |
|---|---|
| Raw email bodies and attachments used for parsing | Not written to persistent storage; processed transiently and discarded after extraction. |
| Email or Amazon authorization tokens | While the connection is active; revoked and deleted when you disconnect or authorization expires, subject to short operational processing time. |
| Account, profile, connections, permissions, and extracted purchase records | While your account or the relevant record exists; deleted or deidentified from active systems within 30 days after a verified deletion request, unless a lawful exception applies. |
| Uploaded images and receipt files | While associated with an active account or record; deleted within the same 30-day deletion cycle after the associated record/account is deleted. |
| Messages, reviews, questions, and other content | While the account or content remains active; deletion or deidentification depends on the request, participant context, safety needs, and legal requirements. |
| Coupons, rewards, referrals, and redemptions when available | For as long as needed to administer the program, prevent fraud, handle disputes, and satisfy applicable accounting or legal obligations; not retained indefinitely. |
| Security, access, and application logs | For the configured period reasonably necessary to secure, diagnose, and operate the Service, or longer for an active investigation or legal obligation. |
| Privacy consents and request records | For as long as needed to demonstrate compliance, honor withdrawal, prevent deleted data from being restored to active use, and meet legal obligations. |
| Backups | Rolling backups may retain deleted data for up to 30 days before rotation. If a backup is restored, deletion requests must be reapplied before ordinary processing resumes. |
17. Disconnecting sources and deleting data
Delete an individual record. You may delete a purchase record through the app when the control is available or request deletion through privacy@shopinion.ai.
Disconnect an email or Amazon source. Disconnecting stops future access and causes Shopinion to revoke or delete the connection credential. You may separately request deletion of previously imported records.
Delete your account. Account deletion requests are accepted at privacy@shopinion.ai. When the in-app Account & Security deletion control is available, it will be an additional request method. Shopinion may require reauthentication with a one-time verification code to prevent unauthorized deletion.
Completion. Shopinion will delete or deidentify active account data within 30 days after verifying the request, subject to documented legal, fraud-prevention, security, accounting, or dispute exceptions.
Shared content and messages. Shopinion will delete or deidentify account-associated content where required. Some conversation context may remain visible to other participants under a “Deleted User” label when necessary to preserve their copy of a conversation, unless applicable law requires further deletion.
Confirmation. Shopinion will confirm receipt and completion of a verified deletion request.
18. Security and data location
Shopinion uses administrative, technical, and physical safeguards designed to protect personal data. These include server-side authorization, encryption in transit, encryption of connection tokens at rest, access controls, role-based permissions, secure handling of one-time verification codes and session credentials, logging and monitoring, backups, change controls, and incident-response procedures appropriate to the company’s size and risk.
Shopinion’s primary production hosting and file storage are located in the United States. Some service providers may process technical or user-submitted data in locations described in their own terms. No security measure is perfect. Protect your one-time verification codes and report suspected account compromise to security@shopinion.ai.
19. Privacy rights and choices
Depending on where you live and whether a particular law applies, you may have the rights below. Shopinion intends to provide these baseline choices to U.S. users subject to identity verification and lawful exceptions.
| Right or choice | Description |
|---|---|
| Access / know | Confirm whether Shopinion processes your personal data and receive a copy or summary. |
| Correction | Correct inaccurate personal data, including imported purchase fields and applicable inferences. |
| Deletion | Delete personal data provided by or obtained about you, subject to lawful exceptions. |
| Portability | Receive certain data in a portable and reasonably usable format. |
| Consent withdrawal | Withdraw consent for connected sources, sensitive data, consumer health data, or other consent-based processing. |
| Opt out | Opt out of sale, sharing for cross-context behavioral advertising, targeted advertising, or qualifying profiling if and when Shopinion engages in those activities. |
| Marketing choices | Unsubscribe from promotional email or SMS and manage push-notification settings. |
| Appeal | Appeal a decision denying or limiting a privacy request where applicable. |
| Authorized agent | Use an authorized agent where permitted, subject to proof of authority and proportionate verification. |
| Non-discrimination | Exercise privacy rights without unlawful discrimination. Voluntary reward programs may offer disclosed differences reasonably related to data value. |
| Social audience controls | Choose accepted connections, categories, items, groups, message recipients, and public-post settings; hiding or deleting later may not remove copies already received by another person. |
| Offer personalization controls | Manage optional Shopinion personalization and, when available, the separate imported-history offer setting. The imported-history setting remains off until you enable it. |
| Advertising transparency and universal opt-out | Use sponsored labels and “Why am I seeing this?” explanations; use Global Privacy Control on the website and corresponding in-app choices for applicable regulated advertising. |
20. How to submit and appeal a privacy request
Submit a privacy request by emailing privacy@shopinion.ai or writing to Shopinion Inc., 1607 Tucumcari Dr, Houston, TX 77090, United States. You may also use available in-app privacy controls. Shopinion does not require you to create a new account to exercise rights, although it may ask you to use an existing account for authentication.
Shopinion will acknowledge requests within the period required by applicable law and generally responds no later than 45 days after receipt. Where permitted, Shopinion may extend the response period once and will explain the reason. Verification may use an authenticated session, phone or email confirmation with a one-time code, or other proportionate information. Shopinion will not request more data than reasonably necessary to verify the request.
If Shopinion denies a request, it will explain the basis and the available appeal method. Submit an appeal to privacy@shopinion.ai with the subject “Privacy Appeal.” Shopinion will respond within the period required by applicable law and will provide regulator complaint information when required.
21. U.S. state-specific disclosures
21.1 California
The categories of personal information collected, sources, business or commercial purposes, categories of recipients, and retention criteria are described in Sections 4 through 16. During the preceding 12 months, Shopinion has not sold personal information and has not shared personal information for cross-context behavioral advertising. Shopinion does not knowingly sell or share personal information of consumers under 16. Contextual offers and first-party personalization within Shopinion do not necessarily constitute sale or sharing. If imported-history personalization, advertising outside Shopinion, or another practice constitutes sale or sharing, Shopinion will provide a clear “Do Not Sell or Share My Personal Information” or equivalent “Your Privacy Choices” method and honor applicable opt-out signals before beginning that processing.
California residents may request access, correction, deletion, and portability, may limit certain uses of sensitive personal information where applicable, and may exercise applicable rights concerning automated decisionmaking. Shopinion’s financial-incentive disclosure is in Section 11. The enrollment screen will link directly to those terms before a user joins a qualifying program.
21.2 Colorado and universal opt-out signals
Where applicable, Shopinion recognizes Global Privacy Control or another legally recognized universal opt-out mechanism for sale or targeted-advertising processing. Because Shopinion does not currently engage in those practices, the signal does not change current processing. If applicable processing is introduced, Shopinion will honor the signal on the website, explain how it is processed, and provide a corresponding app choice where required.
21.3 Texas and other comprehensive state privacy laws
Residents of states with comprehensive privacy laws may have rights to access, correct, delete, obtain a portable copy, opt out of targeted advertising, sale, or qualifying profiling, and appeal a denied request. If Shopinion begins targeted advertising or sale, it will provide clear and conspicuous disclosure and an accessible opt-out method as described in Section 10. Shopinion uses the request process in Section 20 and will provide state regulator complaint information when required.
21.4 Consumer health data states
Washington, Nevada, Connecticut, and other states may provide additional rights for consumer health data and impose separate consent, policy, deletion, processor-contract, and geofencing requirements. The separate Shopinion Consumer Health Data Privacy Notice governs that information.
22. Data relating to other people
Do not upload another person’s private receipt, mailbox content, health information, contact information, photo, or other personal data unless you have the right and appropriate permission to do so. Invitations should be sent only to people you know and should not be used for bulk marketing. If you provide data about another person, you are responsible for having a lawful basis and providing any required notice.
23. Changes to this policy
Shopinion may update this Policy as the Service, vendors, laws, and practices change. We will post the updated version and change the effective or last-updated date. For material changes, we will provide additional notice, such as an in-app message or email, and obtain new consent when required. If a change introduces a new connected-source use, imported-history advertising, advertising outside Shopinion, or AI access to purchase data, Shopinion will provide required notice and choices before beginning the new processing. We will not rely on continued use alone when applicable law requires affirmative consent.
24. Contact us
- Privacy requests and questions: privacy@shopinion.ai
- Security issues: security@shopinion.ai
- General support: support@shopinion.ai
- Legal notices: legal@shopinion.ai
Mailing address: Shopinion Inc., 1607 Tucumcari Dr, Houston, TX 77090, United States.