Skip to main content

This is Mention Network v2, the AI visibility solution for e-commerce. Bought a package on v1? [email protected]

See how AI recommends your store and products, then improve it.

What Mention Network can and cannot touch

The app reads your product content. It never touches your customers, your orders or your payments. Not because we promise to behave, but because the app never asks Shopify for those permissions in the first place.

Install onShopify
Read-only accessNo code, no theme editsRuns inside Shopify
The boundary

Two lists, and nothing in between

Every Shopify app has to declare what it wants to reach before you install it. Here is our entire declaration, in plain words.

What the app reads

All read-only. The app cannot change any of it.

  • Product contentTitles, descriptions, images, variants, prices. The same things any shopper already sees on your storefront.
  • MarketsWhich countries and regions your store sells to, so we measure visibility where you actually sell.
  • LanguagesWhich languages your storefront publishes in, so we read the right version of a page.

What the app never touches

Not restricted by policy. Unreachable by permission.

  • Customers and personal dataNames, emails, addresses, phone numbers. The app holds no permission to read any of it.
  • Orders and revenueOrder history, order value, fulfilment status. Out of reach for the same reason.
  • Payments and payoutsCards, gateways, bank details. Shopify never exposes these to an app like ours, and we never ask.
  • Your theme and storefrontThe app ships no theme extension. It cannot inject code, edit a template, or slow your store down.
  • Your other appsNo permission to read or touch anything another app in your store owns.
Why that list is trustworthy

That is not a promise. It is a limit.

"We would never look at your customer data" is a sentence any app can write. It costs nothing and proves nothing. This is a different kind of claim, and you can check it yourself before you install anything.

  1. Shopify writes the list, not usThe permission screen you see at install is generated by Shopify from what the app declared. We cannot edit it, soften the wording, or leave a line out.
  2. A permission we never asked for cannot be usedAccess is enforced by Shopify's platform, above our code. Even if our own code went looking for an order, the request would be refused.
  3. Asking for more is visibleIf a future feature ever needs deeper access, Shopify asks you to approve the new permission first. It cannot appear quietly inside an update.
AI models

Yes, we send your content to AI models. Here is exactly what.

A tool that measures how AI sees your store has to ask AI. Hiding that would be strange, so here is precisely what leaves and what never does.

  • Only what is already publicThe product text on your storefront, the same words ChatGPT can already read when a shopper asks about your store. Nothing private goes out, because nothing private ever came in.
  • Never personal or order dataNot filtered out at the last second. Never held in the first place. The app has no permission to read it, so there is nothing to leak even by accident.
  • Sent through a commercial APIWe call AI providers through their paid business APIs, where content sent to the model is not used to train it by default.
Check OpenAI’s data policy yourself
Data lifecycle

Collected, used, stored, erased

The whole path your data takes, from install to uninstall.

StageWhat actually happens
What we collectYour public product content, your markets and your languages. Plus your store domain, and the results we produce for you: scores, findings and reports.
What we use it forRunning your checks and audits, and showing you your own results over time. We do not sell it, rent it, or share it with other merchants.
Where it livesOn Mention Network's own cloud infrastructure, encrypted in transit. Access is limited to the people who operate the service.
How long we keep itYour results stay for as long as your store uses the app. The raw payloads behind them are cleared automatically by a scheduled job once they are no longer needed.
How it gets erasedUninstall and Shopify notifies us, then your store's data is removed. You can also request access or erasure at any time, without uninstalling.
Compliance

What we have, stated honestly

Plenty of apps write "enterprise-grade security" and stop there. That phrase means nothing and proves less. Here is the real list, including the parts we do not have.

In place today

  • Shopify's data protection requirementsEvery app on Shopify must answer three mandatory privacy webhooks: a data request, a customer erasure, and a shop erasure. Ours are implemented and live, not empty stubs.
  • GDPR-style data rightsBecause those webhooks exist, the machinery behind the rights GDPR cares about, knowing what is held and having it erased, is already wired in and testable.
  • Minimum permission by designThree read permissions, zero writes. The smallest surface the app can run on is the surface it actually runs on.

Not yet, and we will not pretend otherwise

  • SOC 2We are not SOC 2 audited. It is a paid third-party audit and we have not completed it. When we do, this line changes and you will be able to ask for the report.
  • ISO 27001Same answer. Not certified today.

If you ever see a security claim from us that you cannot verify for yourself, treat it as a red flag and tell us.

Check Shopify’s requirement yourselfRead the full privacy policy
Off-store scanning

We look outside your store too, at public pages only

Part of your score comes from how your brand shows up beyond your own website, because that is where AI engines look before they recommend anyone. The rule for that scan is simple.

  • Public web onlyWe read pages anyone can open in a browser. The same pages an AI engine reads when it answers a shopper.
  • Nothing behind a loginNo accounts, no logged-in scraping, no private groups, no paid data brokers.
  • About your brand, not about peopleWe are looking for whether your brand gets mentioned and how. We are not building profiles of individuals.
See what the audit checks

FAQ

Security questions we get asked

Can Mention Network see my customers or my orders?+

No. The app asks Shopify for three read-only permissions: products, markets and languages. Customers, orders and payments are not among them, so that data never reaches us. You can confirm it on the permission screen before you install.

Can the app change anything in my store?+

No. All three permissions are read-only, and the app ships no theme extension. It cannot edit a product, publish a page, touch your theme, or affect your storefront speed. It reads, scores and reports.

Do you send my data to OpenAI or other AI companies?+

We send your public product content to AI models to score it, because that is the only way to measure how AI reads your store. It is content already visible on your storefront. Personal and order data is never sent, because the app has no permission to read it. We use paid business APIs, where content is not used to train models by default.

What happens to my data when I uninstall?+

Shopify notifies us the moment you uninstall, and your store's data is removed. You do not have to email anyone or wait on a support ticket.

Are you SOC 2 certified?+

No, and we will not claim to be. SOC 2 is a third-party audit we have not completed. What we do have: read-only permissions, Shopify's mandatory privacy webhooks implemented, and erasure on uninstall. If SOC 2 is a hard requirement for you, we are not there yet.

Can I ask you to delete my data without uninstalling?+

Yes. You can ask what we hold about your store and have it erased at any time, through the same erasure path the platform requires us to support.

Read-only access. See it before you install.

Shopify shows you every permission the app asks for, before anything connects. Three read permissions is the whole list.

Security: What We Can and Cannot Touch | Mention Network