Privacy Policy
Effective 2026-10-08
This Privacy Policy explains how Boily (보일리, “Boily”, “we”) collects, uses and protects information when a merchant installs and uses Boily for Commerce on Shopify or Cafe24 (the “Service”), and when shoppers visit a store that uses the Service. It applies to boily.app, commerce.boily.app and the apps distributed through the Shopify App Store and the Cafe24 App Store.
In short: we work with your product catalog and store information, not your customers. We do not collect shoppers’ names, email addresses, phone numbers, postal addresses or payment details, and we never sell data.
1. Information we access and collect
From the merchant’s store (via the platform API, with the permissions you approve at install):
- Product catalog: titles, descriptions, images, variants, prices, availability, vendor/brand, product type, tags, SKUs/GTINs, and translations of these.
- Store information: shop name, store domain(s), store owner/contact email, primary locale and enabled languages/markets, and currency.
- Theme information needed to confirm our app embed is enabled (we do not edit your theme code).
- Metafields that we write ourselves (for example the repair content, structured data and tracked-product list under the
boilyapp namespace), and the product description block we add on Cafe24. - Access tokens issued by the platform, stored encrypted (AES-GCM) at rest.
From public storefront pages: we fetch your public product and home pages, as an AI crawler would, to read product facts, check whether AI crawlers can access them, and detect your brand’s public social profiles (which you confirm before use).
From the store’s visitors (web pixel / beacon): on Shopify our web pixel runs only after the shopper has allowed analytics under Shopify’s customer privacy settings; on Cafe24 a lightweight script is installed through the Cafe24 ScriptTags API. They send the following events so we can attribute traffic from AI assistants:
- Page views and product views, add-to-cart, and checkout completed.
- For checkout completed: the order ID, order amount and currency only.
- Landing page URL, referrer and UTM parameters (used to classify the visit as coming from ChatGPT, Perplexity, Gemini, etc.), a random session identifier, and the browser user-agent string.
- The visitor’s IP address is never stored. We keep only a salted, daily-rotated one-way hash of it, used to de-duplicate events and filter bots.
- We do not collect customer names, email addresses, phone numbers, shipping/billing addresses, payment information or line-item personal data. The Shopify app does not request the
read_ordersor customer scopes.
From you directly: report recipient email addresses you add, settings you choose (tracked products, languages, feed connection status, brand profiles), and messages you send to support.
Billing: charges are processed by Shopify Billing or the Cafe24 App Store. We receive the subscription/charge status and identifiers, never your card details.
Cookies: boily.app uses only a strictly necessary session cookie for the Cafe24 merchant screen; the Shopify app uses Shopify session tokens. We use no advertising cookies.
2. How we use information
- To provide the Service: generate and freeze a set of buyer questions for each tracked product, query AI assistants on a fixed schedule (every two weeks), and measure whether and how your product is mentioned or recommended.
- To generate and publish on-page repair content (direct answer, FAQ, specifications, structured data) and product feeds, and to roll them back on request.
- To attribute storefront visits and orders to AI assistants in your report.
- To send trend reports and service notices by email, handle billing status, provide support, keep the Service secure, and comply with law.
We do not use your data to train AI models, and we do not sell or rent it or use it for cross-context behavioural advertising.
3. Processing by AI providers
To measure AI visibility we send buyer-style questions (for example “best fragrance-free toner for sensitive skin under $30”) to OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini) and Perplexity through their business APIs. Questions are about product categories and needs; brand-intent questions may include your brand or product name. To generate repair content we also send your public product information (title, description, attributes, and product images where the description is image-only).
No personal data is sent to AI providers — no shopper data, and no merchant contact details. Under the business API terms of these providers, API inputs and outputs are not used to train their models by default. We store the AI responses we receive (answer text, cited sources) to compute your results.
4. Retention
| Data | Retention |
|---|---|
| Launch waitlist email (platform pages; email, platform, language, time) | Until the platform launches and we notify you, or until you ask us to delete it; at most 12 months |
| Raw AI responses, frozen question sets, measurement results | 24 months, so that trends stay comparable |
| Pixel / beacon events (hashed IP, no customer PII) | 13 months |
| Repair content history and backups (for rollback) | While installed |
| Store data, tokens, settings | While installed; deleted as described below after uninstall |
| Billing and transaction records | As required by law (up to 5 years under the Korean E-Commerce Act) |
Uninstall: when you uninstall, we stop measurement, revoke use of the access token, and stop future charges. All shop data (store info, tracked products, measurements, AI responses, repair history and beacon events) is deleted within 30 days of uninstall, and in any case when we receive Shopify’s shop/redact request, except records we must keep by law. Repair content already written to your store remains your content; you can roll it back from the app before uninstalling, and our app embed stops rendering it once the app is removed.
5. GDPR / CCPA and platform privacy webhooks
We support Shopify’s mandatory privacy webhooks:
customers/data_request— we hold no customer personal data (no names, emails or addresses; beacon events carry only a random session ID and a hashed IP), so there is nothing that can be linked to the customer. We verify and acknowledge the request.customers/redact— because we store no customer PII, there is no customer record to erase. We verify and acknowledge the request.shop/redact— we delete the shop’s data as described in section 4.
For data we process on a merchant’s behalf (pixel events), the merchant is the controller and Boily acts as a processor/service provider. For merchant account data (store contact email, settings), Boily is the controller. Under the GDPR/UK GDPR our legal bases are performance of the contract with the merchant and our legitimate interest in providing and securing the Service. Under the CCPA/CPRA we do not sell or share personal information. You may request access, correction, deletion, restriction, portability or objection by emailing contact@boily.co.kr; we respond within 30 days. You may also complain to your local data protection authority.
6. Subprocessors
| Subprocessor | Purpose | Location |
|---|---|---|
| Vercel Inc. | Application hosting, CDN, serverless functions | United States (global edge) |
| Neon (Databricks, Inc.) | Managed PostgreSQL database | United States |
| Resend, Inc. | Transactional email (reports, notices) | United States |
| OpenAI, L.L.C. | AI answers (measurement) and content generation | United States |
| Anthropic, PBC | AI answers (measurement) and content generation | United States |
| Google LLC | AI answers (Gemini measurement) | United States |
| Perplexity AI, Inc. | AI answers (measurement) | United States |
| Cloudflare, Inc. | DNS, network security | United States (global edge) |
Shopify and Cafe24 are independent controllers of the data they hold under their own privacy policies. We will update this list before adding a new subprocessor.
7. International transfers
Boily is based in the Republic of Korea and our subprocessors operate mainly in the United States. Data is transferred over encrypted connections (TLS) and stored encrypted at rest. Where the GDPR applies, transfers rely on the European Commission’s Standard Contractual Clauses or the EU–US Data Privacy Framework as offered by each subprocessor, and Korea’s adequacy decision for data received in Korea.
8. Security
Access tokens and secrets are encrypted at rest; administrative access is restricted and authenticated; IP addresses are hashed; feed URLs and report links use unguessable signed tokens. No method of transmission or storage is 100% secure, but we notify affected merchants and authorities of a breach as required by law.
9. Children
The Service is for businesses and is not directed to children. We do not knowingly collect children’s data.
10. Korean Personal Information Protection Act (PIPA) notice
- Items, purposes and retention: sections 1, 2 and 4. Data is destroyed without delay once the retention purpose ends (electronic files by irreversible deletion).
- Entrustment of processing and overseas transfer: section 6 (recipient, country, purpose, transfer over network at time of use, retained for the period in section 4). You may refuse the overseas transfer, but the Service cannot be provided without it.
- Your rights: access, correction, deletion and suspension of processing, via the contact below.
- Privacy officer (개인정보 보호책임자): Deokgi Kim (김덕기), contact@boily.co.kr.
- Remedies: Personal Information Infringement Report Center (privacy.kisa.or.kr, 118), Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972).
11. Changes and contact
We will post changes on this page and, for material changes, notify merchants by email or in the app at least 7 days in advance. Questions: contact@boily.co.kr · Boily (보일리), 서울특별시 성동구 뚝섬로3길 6, 101동 1610호 (Unit 1610, Building 101, 6, Ttukseom-ro 3-gil, Seongdong-gu, Seoul, Republic of Korea).