GDPR Compliance
Last updated: July 30, 2026
1. Our approach
AI Lead Gen is designed with data minimization in mind: our core flow only accesses a connected store's own products, not its customers' personal data. We do not request Shopify's Protected Customer Data scopes as part of the standard connection.
2. Data you control
Any lead/contact data (names, emails, phone numbers) processed through the platform is data you — the customer — choose to upload, import, or message. You act as the data controller for that contact data; we act as a data processor on your behalf.
3. Your rights under GDPR
If you or your contacts are located in the EU/UK, you have the right to access, correct, export, restrict, or request deletion of personal data we hold. To exercise any of these rights, email saboorafzal94@gmail.com and we will respond within a reasonable time.
4. Sub-processors
Data is processed by the infrastructure providers listed in our Privacy Policy — currently Supabase, Vercel, Groq, and whichever email/SMS provider you connect (Brevo, or your own Twilio/Plivo account). We do not sell data to third parties.
5. Data deletion
You can request full account and data deletion at any time by contacting us. Disconnecting a store or SMS provider immediately stops any further syncing from it.
6. Current status
AI Lead Gen is an early-stage platform. We have not yet appointed a formal EU representative or Data Protection Officer. If your organization requires a signed Data Processing Agreement (DPA) or has specific compliance requirements before using the platform, contact us and we will work with you directly.
7. Contact
Questions about GDPR compliance can be sent to saboorafzal94@gmail.com.