AI Policy

Last updated: September 1, 2026

We build and grow Shopify stores, and we use AI while we do it. We also sell audits that measure how AI systems describe our clients. Both of those give us an obligation to be specific about what we do with your information and what a person is still responsible for.

This is that answer, in plain terms.

1. Purpose

We use AI in parts of how we work, and we sell services that measure how AI systems see our clients’ stores. Both of those deserve a plain answer rather than a paragraph buried in our terms.

This policy sets out where AI is used in our delivery, what we will never put into an AI system, who stays accountable for the output, and what you are entitled to ask us. It is written to be specific enough to hold us to.

2. Scope

This policy applies to everyone doing work in our name — employees, contractors and partners — and to every AI system they use in that work: large language models, coding assistants, research and analysis tools, image and content generators, and any AI features built into the platforms we work in.

It covers work on client stores, our own products and websites, and the free audit tools published under ForgeCRO and RetentionControl.

3. What we never put into an AI system

The following do not go into third-party AI tools, in any form, without a client’s written instruction:

Where we need AI assistance on something sensitive, we work from redacted or synthetic examples instead, or we do it by hand.

4. Where we do use AI

Being straight about this matters more than sounding cautious. We use AI:

We do not use AI to make decisions about people, to score or profile your customers, or to generate anything we present to you as human-only work.

5. A person is always accountable

AI accelerates our work. It does not sign it off. Nothing reaches a client — no code, no report, no recommendation — without a senior engineer who has read it, understood it, and can explain why it says what it says.

If we cannot explain a recommendation without pointing at a tool, it does not ship. Where an output would have real consequences for your revenue, security or customers, the human review is the deciding step, not a formality.

6. Your data is not training data

We do not permit client data to be used to train third-party models. Where we use commercial AI services, we use the business or enterprise tiers whose terms exclude training on submitted content, and we prefer options with limited or zero retention.

We do not sell, license or share client data with AI vendors for any purpose beyond performing the task in front of us. If a vendor changed its terms in a way that conflicted with this, we would change vendor.

7. Ask us, and we will tell you

You can ask, on any piece of work, what role AI played in it, and we will answer specifically rather than generally. If you would rather we did not use AI assistance on your project at all, say so at the start and we will scope it that way — it usually changes the timeline, and we will tell you by how much before you commit.

We will not present AI-generated work as something else, and we will not quietly substitute generated output for the senior time you are paying for.

8. The free tools, and what they collect

Our free audit tools query public information about your storefront and, in the case of the AI visibility audit, ask real AI assistants how they describe your brand. They read what is publicly available; they do not need admin access to your store and we do not ask for it.

Where a tool asks for your email so we can send the result, that address is handled under our Privacy Policy and is not passed to an AI vendor as training material.

9. Security and vendors

AI tools are treated like any other subprocessor: assessed before use, limited to what the task needs, and covered by the same access discipline as the rest of our stack. Access to client environments stays with named people, and is removed when an engagement ends.

Where we act as a processor on your behalf, our Data Processing Agreement governs, and this policy sits underneath it rather than over it.

10. Governance, review and enforcement

This policy is owned by the founder and reviewed at least annually, and sooner when the tools or the law move — which, at the moment, they do often. Anyone working in our name is expected to have read it, and a breach is treated as a serious matter, up to and including ending the engagement or the contract.

If you believe we have fallen short of it on your project, tell us and we will investigate and come back to you in writing.

11. Changes and contact

We will update this page when our practice changes and revise the date at the top. Material changes are worth telling active clients about directly, and we will.

Questions about this policy, or about how AI was used on your project: contact@aqsashahzad.com.