Pagewise ("we", "us", "the app") is a Shopify app operated by Tuokex. This policy explains what data the app collects, how it is used and stored, how we handle Google user data, and how merchants can disconnect or request deletion.
What we collect
When a merchant installs Pagewise and uses its features, we store:
- Shop identifier — the store's
myshopify.comdomain and Shopify shop ID. - Shopify access token — encrypted at rest with AES-256-GCM. Used only to call Shopify's Admin GraphQL API on the merchant's behalf.
- Google authorization (when the merchant connects Google) — an OAuth refresh token, encrypted at rest with AES-256-GCM, used solely to read the merchant's own Search Console and Google Analytics 4 data on their behalf. We request read-only scopes only:
https://www.googleapis.com/auth/webmasters.readonly— Search Console performance datahttps://www.googleapis.com/auth/analytics.readonly— Google Analytics 4 reporting data
- Performance snapshots — whether sourced from the Google connection above or from a manual CSV/Excel upload, we store aggregate page- and keyword-level metrics (URL/slug, query, impressions, clicks, sessions, conversions). This is aggregate data, not individual-visitor data.
- Generated content metadata — the slugs, titles, and metaobject GIDs of pages the merchant publishes through Pagewise.
- Knowledge-base content — merchant-authored product-collection metadata, service-feature copy, internal-link references, and pain-topic strings.
We do not collect or store end-customer personal information (orders, customer profiles, contact or payment data) or individual-visitor analytics on the merchant's storefront.
How we use Google user data
When a merchant connects their Google account, Pagewise accesses their Search Console (search-performance) and Google Analytics 4 (traffic and conversion) data only to compute and display SEO and analytics insights inside the Pagewise dashboard for that merchant.
- We do not use Google user data for advertising.
- We do not sell Google user data, and we do not transfer it to third parties except as required to provide the app, comply with applicable law, or as part of a merger or acquisition.
- We do not use Google user data to develop, improve, or train generalized AI and/or machine-learning models.
- Access is read-only; Pagewise never modifies the merchant's Search Console or Analytics configuration.
Limited Use. Pagewise's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we use the rest of the data
- Render the Pagewise dashboard, page-generation flow, and analytics views.
- Call the Shopify Admin GraphQL API on the merchant's behalf to create and update metaobjects, theme files, and page templates.
- Derive insights (low-CTR pages, opportunity keywords) for display inside the app.
We do not sell merchant data, do not share it with third parties beyond the processors that run the service, and do not use it to train any AI model. Page generation uses a server-side LLM provider (OpenRouter); only the structured generation inputs are sent, never Google user data or end-customer data.
Disconnecting Google & revoking access
A merchant can disconnect Google at any time from Pagewise's Settings page, which revokes and deletes the stored refresh token. Access can also be revoked directly at myaccount.google.com/permissions. After disconnection, Pagewise can no longer access the merchant's Google data.
Deletion & GDPR webhooks
Pagewise responds to the three mandatory Shopify privacy webhooks:
customers/data_request— acknowledged; Pagewise stores no customer PII, so there is nothing to export.customers/redact— acknowledged; Pagewise stores no customer PII, so there is nothing to delete.shop/redact— all shop-scoped rows (sessions, settings, pages, knowledge-base entries, GSC/GA4 snapshots, and any stored Google token) are deleted from our database in a single transaction.
Data retention
- Shop data persists until the merchant uninstalls the app and Shopify sends the
app/uninstalledwebhook (the Shopify session is deleted then). Remaining shop-scoped data is removed onshop/redact, which Shopify fires roughly 48 hours after uninstall. - The encrypted Google refresh token is deleted as soon as the merchant disconnects Google, and on uninstall/redaction.
- Encrypted access tokens are rotated whenever the merchant re-authorizes.
Security
- Shopify and Google access/refresh tokens are encrypted at rest using AES-256-GCM with a per-deployment key.
- TLS terminates at the platform edge; traffic between the app and its database uses platform-provided private networking.
- Shopify webhook authenticity is verified via HMAC-SHA256 before any database write.
- Sessions are stored in HTTP-only, Secure, SameSite=Lax cookies.
Contact
Privacy questions: privacy@tuokex.com
Support: support@tuokex.com
To request data deletion outside the Shopify uninstall flow, email the privacy address above with your shop domain.