AI Policy
Last updated: September 1, 2026
We build and grow Shopify stores, and we use AI while we do it. We also sell audits that measure how AI systems describe our clients. Both of those give us an obligation to be specific about what we do with your information and what a person is still responsible for.
This is that answer, in plain terms.
1. Purpose
We use AI in parts of how we work, and we sell services that measure how AI systems see our clients’ stores. Both of those deserve a plain answer rather than a paragraph buried in our terms.
This policy sets out where AI is used in our delivery, what we will never put into an AI system, who stays accountable for the output, and what you are entitled to ask us. It is written to be specific enough to hold us to.
2. Scope
This policy applies to everyone doing work in our name — employees, contractors and partners — and to every AI system they use in that work: large language models, coding assistants, research and analysis tools, image and content generators, and any AI features built into the platforms we work in.
It covers work on client stores, our own products and websites, and the free audit tools published under ForgeCRO and RetentionControl.
3. What we never put into an AI system
The following do not go into third-party AI tools, in any form, without a client’s written instruction:
- Your customers’ personal data — names, email addresses, phone numbers, order records, support conversations or anything exported from your store that identifies a person.
- Credentials of any kind: API keys, access tokens, staff logins, collaborator invites, database passwords.
- Your commercial information — contracts, pricing, margin, roadmaps, supplier terms — and anything a competitor could use.
- Your proprietary code, design files or unreleased work, where you have asked that it stay off external systems.
- Audit findings or reports in a form that identifies you, before you have seen them.
Where we need AI assistance on something sensitive, we work from redacted or synthetic examples instead, or we do it by hand.
4. Where we do use AI
Being straight about this matters more than sounding cautious. We use AI:
- In development — coding assistants for scaffolding, refactoring and test generation. Every line is reviewed by the engineer who owns the work before it reaches a repository.
- In research and analysis — summarising documentation, comparing approaches, and working through options faster than reading everything end to end.
- In drafting — first drafts of copy, documentation and reports, always edited by a person before delivery.
- Inside our audit tools — our AI visibility audit queries real AI assistants to see how they describe a store. That is the product working as intended.
We do not use AI to make decisions about people, to score or profile your customers, or to generate anything we present to you as human-only work.
5. A person is always accountable
AI accelerates our work. It does not sign it off. Nothing reaches a client — no code, no report, no recommendation — without a senior engineer who has read it, understood it, and can explain why it says what it says.
If we cannot explain a recommendation without pointing at a tool, it does not ship. Where an output would have real consequences for your revenue, security or customers, the human review is the deciding step, not a formality.
6. Your data is not training data
We do not permit client data to be used to train third-party models. Where we use commercial AI services, we use the business or enterprise tiers whose terms exclude training on submitted content, and we prefer options with limited or zero retention.
We do not sell, license or share client data with AI vendors for any purpose beyond performing the task in front of us. If a vendor changed its terms in a way that conflicted with this, we would change vendor.
7. Ask us, and we will tell you
You can ask, on any piece of work, what role AI played in it, and we will answer specifically rather than generally. If you would rather we did not use AI assistance on your project at all, say so at the start and we will scope it that way — it usually changes the timeline, and we will tell you by how much before you commit.
We will not present AI-generated work as something else, and we will not quietly substitute generated output for the senior time you are paying for.
8. The free tools, and what they collect
Our free audit tools query public information about your storefront and, in the case of the AI visibility audit, ask real AI assistants how they describe your brand. They read what is publicly available; they do not need admin access to your store and we do not ask for it.
Where a tool asks for your email so we can send the result, that address is handled under our Privacy Policy and is not passed to an AI vendor as training material.
9. Security and vendors
AI tools are treated like any other subprocessor: assessed before use, limited to what the task needs, and covered by the same access discipline as the rest of our stack. Access to client environments stays with named people, and is removed when an engagement ends.
Where we act as a processor on your behalf, our Data Processing Agreement governs, and this policy sits underneath it rather than over it.
10. Governance, review and enforcement
This policy is owned by the founder and reviewed at least annually, and sooner when the tools or the law move — which, at the moment, they do often. Anyone working in our name is expected to have read it, and a breach is treated as a serious matter, up to and including ending the engagement or the contract.
If you believe we have fallen short of it on your project, tell us and we will investigate and come back to you in writing.
11. Changes and contact
We will update this page when our practice changes and revise the date at the top. Material changes are worth telling active clients about directly, and we will.
Questions about this policy, or about how AI was used on your project: contact@aqsashahzad.com.