Privacy Policy
Last updated: September 2026
This policy explains what information SpeedPilot ("the app", "we") collects when a merchant installs it on a Shopify store, why we collect it, and how it's handled. It applies to the SpeedPilot Shopify app and its public website.
Information we collect
Store and account information
When you install SpeedPilot, Shopify provides us with your store's domain, an access token that lets the app act on your behalf within the permissions you approve, and the list of permissions (scopes) granted. We also store your selected plan and billing status. Your access token is encrypted at rest and is never shared with any third party.
Performance scan data
When you run a scan, SpeedPilot loads pages from your live storefront (or a theme-preview URL you've selected) using an automated browser, the same way a real visitor's browser would. From that scan we store: performance metrics (load times, Core Web Vitals), a list of detected issues, a small screenshot of each scanned page, and - where relevant to a fix - the contents of specific theme files SpeedPilot reads or edits, along with a backup of the original content so any change can be rolled back.
Real-visitor performance data
If you enable SpeedPilot's optional storefront extension, it collects Core Web Vitals measurements (load time, responsiveness, visual stability) from real visitors' browsers as they use your store, so you can see field data alongside lab scans. This collection is limited to the page URL and the performance numbers themselves - it does not collect names, email addresses, IP addresses, device identifiers, or any other information that identifies a specific visitor.
Information you choose to provide
Some SpeedPilot features are optional and only store data if you turn them on: a storefront password (if your store is password-protected and you want scans to be able to reach it), a target theme selection, scan frequency/device preferences, and a Slack webhook URL (if you want notifications). Anything you provide here is encrypted at rest where it could be used to access your store or another service.
How we use this information
We use the information above solely to operate the app: running the scans you request or schedule, diagnosing performance issues, applying the fixes you approve, keeping backups so changes are reversible, showing you before/after results, and sending the notifications you've configured. We do not sell store data, and we do not use it for advertising.
Third-party services
SpeedPilot shares a limited amount of data with the following services, only as needed to provide the features described above:
- Shopify - the platform SpeedPilot is built on; all store access goes through Shopify's own APIs and permission system.
- Anthropic (Claude API) - when you request an AI-generated recommendation or prioritization for detected issues, the issue's category, title, and description are sent to Anthropic to generate that text. No customer or visitor data is included in these requests.
- Google PageSpeed Insights - if configured, a scanned page's public URL may be sent to Google's PageSpeed Insights API as a secondary, on-demand performance check.
- Slack - if you connect a Slack webhook, SpeedPilot sends notification messages to that webhook. This goes only to the Slack workspace you configured; we have no access to your Slack workspace beyond that one webhook URL.
Data storage and security
Data is stored in a Postgres database on Railway's hosting infrastructure. Sensitive fields - your Shopify access token, storefront password, and Slack webhook URL - are encrypted at rest. All traffic to and from the app is encrypted in transit (HTTPS). Access to production data is limited to the app's operator.
Data retention and deletion
We keep your store's data for as long as the app is installed, so scans, history, and settings remain available to you. If you uninstall SpeedPilot, Shopify notifies us and we permanently delete your store's data - scans, issues, backups, settings, and any real-visitor performance data - shortly afterward, in accordance with Shopify's data protection requirements. SpeedPilot does not knowingly collect personal information about your customers, so there is generally no customer data to separately request or delete; if you believe otherwise, contact us using the details below.
Your rights and choices
You can review, change, or remove most of what SpeedPilot stores directly from the app: update your target theme and scan preferences in Settings, remove your storefront password or Slack webhook at any time, and roll back any applied fix from the Optimizations page. Uninstalling the app triggers deletion of your store's data as described above. You can also contact us directly to ask what data we hold about your store or to request its deletion.
Children's privacy
SpeedPilot is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect information from children.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date above. Continued use of the app after a change means you accept the updated policy.
Contact us
Questions about this policy or your data can be sent to virani.nayan@gmail.com.