Last updated 24 June 2026
Crawlight shows merchants which AI agents visit their store. It is built to do that without collecting personal information about anyone.
The short version. Crawlight records anonymous visit events to classify traffic as human or AI agent and to attribute sales in aggregate. We do not collect or store customer names, emails, phone numbers, or addresses. We do not store raw IP addresses. We never sell data and never use it for advertising.
Crawlight ("Crawlight", "we", "us") is an analytics application for Shopify stores. This policy explains how we handle personal data relating to a merchant's customers, prospective customers, and site visitors when a merchant installs and uses Crawlight. The merchant is the controller of their store's data; Crawlight processes data on the merchant's behalf to provide the app's functionality.
When Crawlight is installed on a store, it records anonymous visit events for each visit to the storefront. A visit event contains:
We do not collect or store personal identifiers. Crawlight does not collect, request, or store customer names, email addresses, phone numbers, or postal addresses. We do not build profiles of individual people.
To show merchants how AI traffic relates to revenue, Crawlight accesses a store's order data through the Shopify Admin API. We use this only to attribute sales in aggregate — connecting an order's value to an anonymous visit session. We store the attribution result (such as order count and order value linked to a classified session); we do not store the personal details of the customer who placed the order. We request order access only for recent orders and do not request a store's full historical order archive.
We process the data above for a single purpose: to provide merchants with analytics on AI-agent and human traffic, including classification, page engagement, and anonymous sales attribution, and to generate optimization suggestions and a weekly summary email. We limit our use of the data to this purpose. We do not sell data, share it with data brokers, or use it for advertising or cross-merchant marketing.
We use a small number of service providers (sub-processors) to run Crawlight. Each processes data only as needed to provide their service to us:
| Provider | Role | What it processes |
|---|---|---|
| Supabase | Database hosting | Stores anonymous visit events and aggregated statistics (Singapore region) |
| Render | Application hosting | Runs the Crawlight application and ingestion service |
| Anthropic | Recommendation text | Receives aggregated, anonymous statistics only (no personal data) to phrase optimization suggestions |
| Resend | Email delivery | Sends the weekly summary email to the merchant's own contact address |
We may also disclose data where required by law or to protect the rights and safety of Crawlight, merchants, or the public.
Crawlight's data is stored in the Southeast Asia (Singapore) region. Where data is transferred or accessed across borders by us or our sub-processors, we rely on appropriate safeguards for such transfers.
Raw visit events (including the ipHash) are retained for up to 180 days, then automatically deleted.
Aggregated statistics (such as daily AI-visit counts, shares, and attributed revenue totals) are de-identified and may be retained longer to power trends and historical reporting. These contain no personal data.
When a merchant uninstalls Crawlight, we delete that store's data upon receiving Shopify's shop/redact request (sent approximately 48 hours after uninstall).
We honor Shopify's customers/redact and customers/data_request webhooks. Because Crawlight does not store customer personal data, these requests typically confirm that no such data is held.
Data is encrypted in transit using TLS (HTTPS) and encrypted at rest by our database provider. Access to production data is restricted to Crawlight's operator. We process the minimum data required to provide the app's functionality, which limits the impact of any potential incident.
Depending on where you are located, you or your customers may have rights under laws such as the GDPR and CCPA, including the right to access, correct, or delete personal data, and to object to or restrict certain processing. Because Crawlight is designed not to store personal identifiers, most requests are satisfied by confirming no such data is held or by deleting a store's data. Merchants can exercise these rights, or ask questions on behalf of their customers, by contacting us below. We respect and apply opt-out decisions where applicable, and we do not sell personal data.
We may update this policy as Crawlight evolves. When we make material changes, we will update the date at the top of this page. Continued use of Crawlight after an update means you accept the revised policy.
Questions about this policy or about how Crawlight handles data can be sent to jaegersjaegers@gmail.com.