Privacy policy
Effective: 23 June 2026 · Last updated: 23 June 2026
Who we are
lunalink.ai operates Affina, a Shopify app published under the lunalink.ai brand. This policy explains what data Affina accesses, why, and how it's handled. Questions: hello@lunalink.ai.
What Affina accesses (Shopify permissions)
Affina requests read-only access:
- Read products — To sync your catalogue (title, price, image, tags, type, and cost where available) for generating and ranking recommendations.
- Read orders — Limited to a 60-day window — to learn which products are bought together and to attribute purchases to the recommendations that were (or weren't) shown.
- Read themes — To detect whether you've switched on the Affina recommendation blocks. Affina has no write access to your theme and never edits it.
- Read inventory — To factor real stock and unit cost into recommendations (for example, a margin floor). Optional; Affina works without it.
Affina requests no write permissions and cannot change your products, orders, theme, or settings on the storefront.
What we store
In Affina's database we keep: your shop domain and settings; a synced copy of your product catalogue; order line items within the 60-day window (for attribution and co-purchase learning); storefront interaction events (recommendation impressions, clicks, add-to-cart) tied to an anonymous visitor identifier; the model state Affina learns per placement; and the record of which recommendations were shown (including to the holdout group), so lift can be measured. If you use the in-app Help chat, we also store that conversation and any support request you send, so we can answer and follow up.
What we do not collect
Affina does not collect or store customer personal information — no names, emails, phone numbers, or addresses. It recommends based on what product or cart is being viewed, not on customer identity. Under Shopify's classification, Affina handles Protected Customer Data at Level 1 (it processes no customer PII). The visitor identifier used for attribution is not linked to a customer's personal details.
AI processing
Affina uses OpenAI to generate product embeddings (used to find similar products), to power the in-app assistant, Ask Affina, and to answer questions in the in-app Help chat. What's sent to OpenAI is product and shop-configuration content and the questions you type — never customer personal data. OpenAI does not use this data to train its models (standard API terms). Affina ships on a platform OpenAI key; merchants do not supply their own.
Sub-processors
Affina shares data with these service providers only as needed to operate:
| Provider | Purpose |
|---|---|
| Render | Application hosting and background workers (US). |
| PostgreSQL (Supabase, US us-east-1) | Primary database. |
| OpenAI | Product embeddings and the Ask Affina assistant. |
| Cloudflare | CDN in front of the recommendation API (caches non-personalised content for speed). |
| Resend | Transactional email (e.g. welcome, notifications), if enabled. |
| PostHog | Product analytics (no customer data), if enabled. |
| Sentry | Error monitoring (no customer data), if enabled. |
| Shopify | The platform Affina runs on; Shopify handles billing. |
Data retention
Product and settings data is kept while Affina is installed and refreshed as your catalogue changes. Order data is limited to a rolling 60-day window. Interaction events and lift records are kept so the dashboard can measure results over time. When you uninstall Affina, we delete your data in response to Shopify's shop/redact request (sent about 48 hours after uninstall); we also clear your sessions immediately on uninstall.
Your rights and data deletion
You can request access to or deletion of data we hold. Affina also honours Shopify's mandatory privacy webhooks: customers/data_request (we report what, if anything, is held for a given shopper — which is non-personal interaction data only), customers/redact (we delete the matching visitor records), and shop/redact (we delete all of your shop's Affina data). To make a request directly, email hello@lunalink.ai.
Data location and security
Affina's data is stored in the United States. Connections are encrypted in transit. Access is limited to the running application and the maintainers who operate it.
Billing
Billing is handled by Shopify. Affina does not see or store your payment-card details.
Changes
We'll post any changes to this policy on this page and update the date above.