Last updated: September 18, 2026
This Privacy Policy explains how klipp.tech (“we”, “us”, or “our”) collects, uses, and shares information when you visit instaindex.app, install or use the InstaIndex Shopify app, or contact our team. Together, these are the “Service”.
Our role
We are responsible for personal information we use to operate our website, manage merchant relationships, provide support, and administer the Service. When we process storefront visitor information on a merchant’s behalf, the merchant is responsible for deciding how that information is used, and we process it to provide the enabled features.
If you are a shopper with a question about a store’s privacy practices, please contact that store first. Its privacy policy governs its relationship with you.
Information we collect
The information we process depends on the features you use and the permissions you grant.
Merchant and store information
When you install or use InstaIndex, we receive information from Shopify, such as your store name, domains, contact information, store settings, subscription status, and app permissions. We also store the authentication credentials needed to maintain the authorized connection to your store.
We process store content needed for the features you enable, including products, collections, pages, blog posts, URL redirects, localized URLs, and structured data settings. We use this information to submit changed URLs, generate or inspect schema markup, and provide related reports.
Shopify manages app subscription billing. We receive subscription and billing-status information, rather than your full payment card details.
Storefront monitoring information
If a merchant enables real user monitoring, we collect technical performance measurements from storefront visits. These may include page and resource URLs, page-view identifiers, timestamps, browser and device categories, country, loading and interaction timings, and technical details about page elements associated with performance issues.
If a merchant enables 404 monitoring, we collect missing-page URLs, referring URLs, browser user-agent information, and timestamps. Revalidation also records the status of checked URLs and any redirect destinations.
URLs, referrers, and technical diagnostics can contain personal information if it is included in the underlying page or request. Merchants should avoid placing personal or confidential information in URLs or content submitted to these features.
AI feature information
For AI visibility tracking and AI-assisted tools, we process the prompts, brand and competitor details, store content, and other inputs relevant to the feature. We also store results such as generated responses, citations, recommendations, and visibility measurements.
Relevant inputs are sent to the AI providers needed to perform the requested analysis or generation. Do not submit passwords, payment details, sensitive personal information, or content you are not authorized to share.
Support and communications
When you contact us, submit feedback, or book a call, we collect the information you provide, such as your name, email address, store details, message, attachments, and appointment information. We use it to respond, provide support, and manage your request.
Website support messenger
We use Intercom and its Fin AI agent to provide website support. The messenger only loads after you allow the optional Preferences (support chat) category in our site-wide cookie controls. While that choice remains valid, the messenger loads automatically on subsequent visits, including before you open the chat. Loading it sends technical information such as your IP address, browser and device information, and the page address to Intercom so it can provide and secure the messenger.
If you use the chat, Intercom processes your messages and any contact details or attachments you provide to respond to your request, maintain conversation history, and support AI-assisted responses or team follow-up. Our website integration does not pass your WordPress account name, email address, or user ID to Intercom automatically. Browser identifiers may still allow Intercom to recognize a returning visitor or associate a visit with an existing support conversation. Please avoid sending sensitive information that is not needed for your request.
Intercom’s use of cookies and browser storage is described below. Further information about its processing is available in Intercom’s Privacy Policy.
Website and service usage
Our website and service infrastructure may process IP addresses, browser and device information, requested URLs, timestamps, and diagnostic or security logs when handling requests. We use this information to deliver the Service, troubleshoot problems, and protect against abuse.
WordPress comments and avatars
Our website uses WordPress. If you leave a comment where comments are enabled, we collect the information entered in the comment form, including your name, email address, optional website URL, and comment, along with your IP address and browser user-agent information. We use this information to publish and moderate comments, recognize follow-up comments, and help detect spam or abuse.
Approved comments, the name you provide, any website link you include, and your avatar may be publicly visible. Your email address is not displayed as part of the public comment. Avoid including personal or confidential information in comments that you do not want published.
We use Gravatar to display comment avatars. An identifier derived from your email address (a hash) is included in requests to Gravatar to look up your avatar; this identifier is not a guarantee of anonymity. When a visitor’s browser loads an avatar, Gravatar also receives request information such as the visitor’s IP address and browser details. Gravatar is operated by Automattic; see its Privacy Policy.
WordPress accounts
If you have a website account, WordPress stores the information in your user profile and information needed to authenticate and administer your account. Authorized website administrators can access and manage profile information. This website account is separate from your Shopify merchant account. If you request a website password reset, WordPress includes the IP address used for the request in the reset email sent to the account’s email address.
Embedded content and uploaded media
Where articles or pages include embedded third-party content, such as videos, images, or articles, loading or interacting with that content may send information to the third-party provider. The provider may collect request information, use cookies, and track interactions, including associating them with an account you are signed into with that provider. Its own privacy policy applies to that processing.
If you are authorized to upload images to the website, avoid including embedded location information such as EXIF GPS data. Visitors may be able to download publicly available images and extract metadata retained in those files.
How we use information
We use information to:
- Provide the features you enable and display reports about your store.
- Authenticate connections, manage subscriptions, and enforce plan limits.
- Respond to support requests and arrange setup or support calls.
- Send service notices, security alerts, and subscription-related communications.
- Diagnose errors, maintain reliability, and improve the Service.
- Prevent fraud or misuse and comply with legal obligations.
Where applicable data protection laws require a legal basis, we rely on performance of our contract with you, legitimate interests such as securing and maintaining the Service, compliance with legal obligations, or consent where required. You may withdraw consent for consent-based processing without affecting processing that occurred before withdrawal.
Google Analytics connection
Connecting Google Analytics is optional. If you connect it, we request read-only access to Google Analytics. We access available account and property information and reporting data for the property you select, including traffic sources, sessions, visitors, engagement, key events, and revenue metrics.
We use this data to provide AI traffic monitoring, including reports about referrals from AI platforms and their share of your store’s traffic. We do not modify your Google Analytics configuration or reporting data.
We store authorization tokens to maintain the connection; tokens are encrypted at rest. Stored analytics aggregates are retained for up to 13 months to support historical reporting.
Google user data is used only to provide and improve the user-facing Google-connected feature. We do not sell it, use it for advertising, or use it to train generalized AI or machine-learning models. We do not send your Google Analytics reports to AI model providers as inputs to our AI features. Access and sharing are limited to what is permitted by the Google API Services User Data Policy, including its Limited Use requirements.
You can disconnect Google Analytics in the settings on the AI traffic monitoring page. Disconnecting initiates revocation of our authorization and deletion of stored connection credentials and imported analytics data; it does not delete data in your Google Analytics account. You can also revoke access through your Google account permissions. Revoking access through Google stops future authorized access but may not itself delete previously imported data; contact us to request deletion if needed.
When we share information
We do not sell personal information. We disclose information where needed in the following circumstances:
- Service providers: We use providers for hosting, storage, analytics infrastructure, error monitoring, communications, and customer support. These include Intercom for website and in-app support, including its Fin AI agent and AI providers for the AI features described above. Providers receive information needed for their role, subject to applicable contractual and legal restrictions.
- Shopify and connected services: We exchange information with Shopify and services you authorize, such as Google Analytics, to operate the relevant integration.
- IndexNow submissions: URL submission sends store URLs and the verification information needed by IndexNow to participating search engines. Those search engines independently decide how to crawl, index, retain, and use submitted URLs. Do not submit private URLs or URLs containing personal information.
- Legal and safety purposes: We may disclose information when legally required or reasonably necessary to protect rights, investigate abuse, or address security threats.
- Business transfers: Information may be transferred in connection with a merger, acquisition, or sale of the business, subject to applicable privacy obligations.
- Your instructions: We may disclose information when you direct us to do so.
Third-party websites and services have their own privacy policies for information they process independently.
Cookies and similar technologies
We use Complianz to manage cookie choices across this website. Necessary storage supports the website and remembers your consent choices; optional categories remain off until you allow them. Preferences includes website support chat. If we add website analytics, it will be managed separately under Statistics. You can reject optional categories and continue using the website, or change and withdraw your choices using “Cookie preferences”. We remember your choices for up to 180 days, unless you clear them sooner or we need to request consent again. Withdrawing support chat consent stops the messenger and clears its accessible browser identifiers; it does not delete existing support records or undo earlier processing. The Help Center is a separate website with its own privacy and storage behavior.
The Service and integrated providers may use cookies, browser storage, and similar technologies for authentication, preferences, security, and support functionality. Optional analytics or other non-essential technologies require consent where applicable law requires it.
You can manage cookies through your browser and any consent controls provided on the website. Blocking necessary storage may prevent some features from working. Merchants are responsible for providing appropriate notices and obtaining any required visitor consent before enabling storefront monitoring.
Intercom messenger storage
Our website support messenger uses first-party cookies and browser storage on our website domain to recognize visitors, maintain support sessions, restore conversations, and help prevent abuse. After you allow the support chat category, these identifiers can be created when the messenger loads, before you open it or send a message.
Intercom documents a default session duration of one week and a device-identifier cookie duration of 270 days, refreshed through successful messenger activity. An anonymous visitor identifier stored in local storage has no automatic expiry. Browser settings and changes to our Intercom configuration may affect these durations. See Intercom’s messenger storage documentation for details.
You can clear this storage or block it through your browser settings, which may affect conversation continuity and messenger availability. Clearing storage does not delete support records already held by us or Intercom. You can request deletion as described in this policy. For support without using the messenger, email support@klipp.tech.
WordPress website cookies
WordPress uses the following cookies when the relevant website features are used. These cookies are separate from technologies used on a merchant’s storefront:
- Comment preferences: If you select the option to save your details when commenting, cookies remember your name, email address, and website URL so you do not need to re-enter them. These cookies normally last for one year. You can leave the checkbox unselected and still submit a comment.
- Cookie support test: Visiting the login page sets a temporary cookie to check whether your browser accepts cookies. It contains no personal information and is normally discarded when you close your browser.
- Login and authentication: Signing in sets cookies that identify your authenticated session. Without “Remember Me,” the browser cookies are session cookies and WordPress normally limits authentication to two days. Selecting “Remember Me” normally keeps you signed in for two weeks. Logging out removes the login cookies.
- Account preferences: For signed-in users, WordPress may store interface and display preferences in cookies that normally last for one year.
- Editing content: When an authorized user edits or publishes content, WordPress may set an additional cookie containing the ID of the item being edited, rather than personal information. This cookie normally expires after one day.
These are WordPress’s default durations; browser settings may remove cookies sooner. You can remove saved comment preferences and other cookies through your browser settings.
Retention and deletion
We retain information for as long as needed to provide the Service and for the purposes described in this policy. Retention depends on the type of information, enabled features, security needs, and legal obligations. Monitoring and reporting data are subject to feature-specific retention limits; Google Analytics retention is described above.
WordPress comments and their associated metadata do not have an automatic expiry and may be retained indefinitely to preserve discussions and support moderation, unless we remove them or act on an applicable deletion request. Website account information is retained while the account is maintained and afterward only as needed for the purposes described in this policy. You may request an export or deletion of personal information associated with your website account or comments by contacting us; applicable legal, administrative, and security exceptions may apply.
Uninstalling the app starts the applicable Shopify uninstall and data-redaction process. Deletion is not necessarily immediate. Records needed for legal compliance, billing, security, or resolving disputes may be retained for those purposes, and backup copies may remain until their normal expiry.
You can request deletion by contacting privacy@klipp.tech. We may need to verify your identity and authority over the store before acting. Deletion from our systems does not remove content already published on your storefront or independently retained by search engines or other third parties.
Security and international processing
We use reasonable technical and organizational measures to protect information. No internet transmission or storage system is completely secure, and we cannot guarantee absolute security.
We operate from India and use service providers that may process information in other countries. Where applicable law requires safeguards for international transfers, we use the legally required transfer mechanisms and protections.
Your privacy rights
Depending on where you live and the laws that apply, you may have rights to access, correct, delete, or obtain a copy of your personal information; restrict or object to processing; withdraw consent; or complain to your local data protection authority. These rights may be subject to exceptions.
To make a request, email privacy@klipp.tech. Storefront visitors should normally direct requests to the merchant whose store they visited; we assist merchants with applicable requests concerning information processed on their behalf.
Children
The Service is intended for businesses and their authorized representatives, not children. We do not knowingly collect personal information directly from children through merchant accounts or our website. Contact us if you believe a child has provided personal information to us.
Changes to this policy
We may update this policy as the Service or legal requirements change. We will update the date above and provide notice of material changes where required. Where consent is legally required for a new use of information, we will seek it rather than treating continued use as consent.
Contact
For privacy questions or requests, contact klipp.tech at privacy@klipp.tech.
For product support, contact support@klipp.tech. See also our Terms of Service.