CO8 Product Image

Privacy Policy

CO8 Limited provides CO8 Product Image, a Shopify app that analyzes and optimizes product featured images. This policy explains the data the app uses and how to request access or deletion.

Effective 25 August 2026 · CO8 Limited

Last updated: 16 September 2026.

1. Data we receive from Shopify

After a merchant installs the app, Shopify provides the store domain, installation credentials, and the product information needed to operate the app. We read product IDs, titles, featured images, other gallery images, image dimensions, file metadata, and public storefront product URLs. We write a product image only after the merchant explicitly approves and publishes a candidate.

The app does not request access to customers, orders, payments, checkouts, or customer personal information.

2. Data created when you use the app

We store optimization runs, image quality findings, approval decisions, publication and rollback history, quota usage, generated candidate images, and archived copies of replaced featured images. We also keep limited operational logs used to diagnose errors and protect the service.

3. How we use data

  • To display products and analyze product image quality.
  • To generate replacement candidates and validate image files and dimensions.
  • To publish only the candidate a merchant approves and to support rollback.
  • To verify the published featured image against the live storefront when available.
  • To operate billing allowances, security controls, support, and error diagnosis.

We do not sell merchant data or use it for third-party advertising.

4. Service providers and international processing

Data is processed by service providers only as needed to run the app. These currently include Shopify for the commerce platform and billing, Railway for application and database hosting, Cloudflare R2 for private image storage, and image-generation providers reached through our CO8-operated image gateway. Processing may occur outside the merchant's country.

Product images and related instructions are sent to image-generation providers to create proposals. We validate image files and dimensions within the app; we do not currently send proposals to a separate visual quality-control provider. Merchants review the appearance before approving and publishing. Do not use images you do not have the right to process.

5. Retention and deletion

Data is retained while the app is installed so that optimization history and rollback remain available. After uninstall, Shopify ordinarily sends a shop-redaction request after its required retention window. When that request is received, we delete the shop's sessions, optimization records, generated candidates, and archived originals.

You can request access, correction, export, or earlier deletion by emailing support@co8.ai. We may need to verify that the request comes from the store owner or an authorized representative.

6. Security

Traffic is encrypted in transit. The app uses Shopify session-token authentication, scopes every operation to the installed shop, keeps generated and archived images in private object storage, and restricts candidate previews to authenticated users of the matching shop. No internet service can be guaranteed perfectly secure.

7. Legal rights and changes

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of personal data. Contact us using the email above to exercise those rights. If this policy changes, we update the effective date and provide notice when required by law.