Legal, privacy & security
Clear and transparent. Designed for privacy and safe access.
CMOgpt helps ecommerce merchants understand their business performance, benchmark key metrics, and receive AI-assisted business insights.
This page is a plain-English summary of how CMOgpt works, what data we collect, what data we store, and how your data is handled when you use CMOgpt, including through our MCP server.
This is a summary only. Full details are set out in our Terms of Service, Privacy Policy, and Data Processing Addendum.
Key things to know
Read-only access by design
CMOgpt is designed to read business data for analysis.
CMOgpt does not modify your Shopify store, transactions, products, inventory, customer records, campaigns, or settings.
CMOgpt does not execute business actions on your behalf.
You remain responsible for all decisions made using the insights provided by CMOgpt.
Metrics-first data access
CMOgpt is a business performance and strategy tool.
We use ecommerce metrics, performance data, benchmarks, scoring logic, and business context to help you understand what is happening in your store and what to focus on next.
Where possible, CMOgpt works with business metrics and aggregated data, not raw customer records.
What CMOgpt collects
CMOgpt may read or receive the following data when you use the service:
-
Shopify order data
-
Product and inventory information
-
Store performance metrics
-
Google Analytics 4 metrics, where connected by you
-
Marketing spend entered by you
-
Business targets entered by you
-
Business questions, prompts, or context entered by you
-
CMOgpt scores, assessments, benchmarks, and derived metrics
We collect this information to calculate performance metrics, assess marketing efficiency, identify performance gaps, and provide business strategy recommendations.
What CMOgpt does not collect
CMOgpt does not collect customer-identifiable information such as:
-
Customer names
-
Customer email addresses
-
Customer phone numbers
-
Delivery addresses
-
Payment details
-
Card information
-
Passwords
-
Shopify admin credentials
CMOgpt is not designed to be a customer data platform.
provide business strategy recommendations.
How MCP access works
CMOgpt may provide selected business data to authorised AI tools, such as Claude or ChatGPT, through our MCP server.
When you use CMOgpt through an MCP connection, we provide business context that helps the AI model answer your questions. This may include:
-
Business metrics
-
CMOgpt scores and assessments
-
Industry benchmarks
-
Business targets
-
Performance gap analysis
-
CMOgpt decision logic, scoring matrix, and proprietary analytical frameworks needed to support machine reasoning
The MCP server is designed to expose business performance context, not customer-identifiable records.
AI-assisted insights
CMOgpt uses AI to help interpret business data and explain what the metrics mean.
AI-generated outputs may not always reflect every part of your business context. They should be reviewed alongside your own judgement and commercial experience.
CMOgpt does not provide legal, accounting, tax, investment, or financial advice.
Your data stays yours
We do not sell merchant data.
We do not use merchant data for advertising.
We do not use merchant data to train public AI models.
Merchant data is used only to provide CMOgpt services within your account, including analytics, benchmarking, business insights, and AI-assisted responses.
Data retention
Different data is kept for different periods.
In general:
-
Business metrics are retained while your signup, trial, or subscription is active.
-
Shopify order data is retained for 30 days to support margin and profitability modelling.
-
Shopify customer data is not extracted and not retained.
-
GA4 metrics are retained while your signup, trial, or subscription is active.
-
Marketing spend and business targets are retained while your signup, trial, or subscription is active.
-
MCP and system logs may be retained for a limited period for security, debugging, and audit purposes.
-
Billing and legal records may be retained where required by law.
You can disconnect integrations or cancel your subscription at any time.
Contact
For questions about privacy, security, data handling, or legal terms, contact: