Affina

Privacy policy

Effective: 23 June 2026 · Last updated: 23 June 2026

Who we are

lunalink.ai operates Affina, a Shopify app published under the lunalink.ai brand. This policy explains what data Affina accesses, why, and how it's handled. Questions: hello@lunalink.ai.

What Affina accesses (Shopify permissions)

Affina requests read-only access:

  • Read productsTo sync your catalogue (title, price, image, tags, type, and cost where available) for generating and ranking recommendations.
  • Read ordersLimited to a 60-day window — to learn which products are bought together and to attribute purchases to the recommendations that were (or weren't) shown.
  • Read themesTo detect whether you've switched on the Affina recommendation blocks. Affina has no write access to your theme and never edits it.
  • Read inventoryTo factor real stock and unit cost into recommendations (for example, a margin floor). Optional; Affina works without it.

Affina requests no write permissions and cannot change your products, orders, theme, or settings on the storefront.

What we store

In Affina's database we keep: your shop domain and settings; a synced copy of your product catalogue; order line items within the 60-day window (for attribution and co-purchase learning); storefront interaction events (recommendation impressions, clicks, add-to-cart) tied to an anonymous visitor identifier; the model state Affina learns per placement; and the record of which recommendations were shown (including to the holdout group), so lift can be measured. If you use the in-app Help chat, we also store that conversation and any support request you send, so we can answer and follow up.

What we do not collect

Affina does not collect or store customer personal information — no names, emails, phone numbers, or addresses. It recommends based on what product or cart is being viewed, not on customer identity. Under Shopify's classification, Affina handles Protected Customer Data at Level 1 (it processes no customer PII). The visitor identifier used for attribution is not linked to a customer's personal details.

AI processing

Affina uses OpenAI to generate product embeddings (used to find similar products), to power the in-app assistant, Ask Affina, and to answer questions in the in-app Help chat. What's sent to OpenAI is product and shop-configuration content and the questions you type — never customer personal data. OpenAI does not use this data to train its models (standard API terms). Affina ships on a platform OpenAI key; merchants do not supply their own.

Sub-processors

Affina shares data with these service providers only as needed to operate:

ProviderPurpose
RenderApplication hosting and background workers (US).
PostgreSQL (Supabase, US us-east-1)Primary database.
OpenAIProduct embeddings and the Ask Affina assistant.
CloudflareCDN in front of the recommendation API (caches non-personalised content for speed).
ResendTransactional email (e.g. welcome, notifications), if enabled.
PostHogProduct analytics (no customer data), if enabled.
SentryError monitoring (no customer data), if enabled.
ShopifyThe platform Affina runs on; Shopify handles billing.

Data retention

Product and settings data is kept while Affina is installed and refreshed as your catalogue changes. Order data is limited to a rolling 60-day window. Interaction events and lift records are kept so the dashboard can measure results over time. When you uninstall Affina, we delete your data in response to Shopify's shop/redact request (sent about 48 hours after uninstall); we also clear your sessions immediately on uninstall.

Your rights and data deletion

You can request access to or deletion of data we hold. Affina also honours Shopify's mandatory privacy webhooks: customers/data_request (we report what, if anything, is held for a given shopper — which is non-personal interaction data only), customers/redact (we delete the matching visitor records), and shop/redact (we delete all of your shop's Affina data). To make a request directly, email hello@lunalink.ai.

Data location and security

Affina's data is stored in the United States. Connections are encrypted in transit. Access is limited to the running application and the maintainers who operate it.

Billing

Billing is handled by Shopify. Affina does not see or store your payment-card details.

Changes

We'll post any changes to this policy on this page and update the date above.

Contact

hello@lunalink.ai