CommerceGov is a private software platform providing governance infrastructure for AI-assisted commerce operations. It is not affiliated with, endorsed by, or operated by any government entity.
CommerceGov stores limited shop and product data only for the purpose of operating the application and providing governance for product content updates.
Overview
CommerceGov provides a governance workflow that allows authorized organization users to review, approve, and apply product content updates to Shopify stores before changes are written to production.
CommerceGov may be used by agencies, merchant teams, or other authorized organization operators responsible for product content operations. Access to store data and workflow actions is controlled by shop context, authorization, and governance rules.
Data We Store
CommerceGov stores the following information required for the operation of the service:
- Shop domain, used for tenancy and access control
- OAuth access token for secure access to the Shopify Admin API
- Product mirror and metadata cache used for analysis and governance workflows
- AI-generated product content suggestions created within the application
- Webhook processing records used for reliability and idempotent processing
- Governance and audit records related to review, approval, and applied changes
- Operational job records related to sync, review, approval, apply, and reconciliation workflows
CommerceGov does not store payment card data or Shopify customer personal data.
Shopify App Store Public Review
For the Shopify App Store public review build, CommerceGov does not collect in-app merchant charges. There is no payment card collection, no in-app subscription checkout, and no payment flow on public install surfaces for this review build.
Data Usage
CommerceGov reads product content and product metadata from the Shopify Admin API in order to:
- analyze product content quality
- generate product content suggestions
- enable review and approval workflows
- support governed single or bulk product content operations
- apply approved product updates through the governed workflow
All write operations to Shopify occur only after explicit approval within the application workflow.
Approved writes are executed through worker-controlled jobs and recorded in audit history.
AI-generated suggestions are provided as informational recommendations only and require explicit human approval before any changes are applied to a Shopify store.
Customer Data
CommerceGov is not designed to collect, store, or persist Shopify customer records or customer personally identifiable information.
Shopify customer data protection webhooks, including customers/redact and customers/data_request,
are acknowledged for compliance. Because CommerceGov does not persist Shopify customer records,
these requests do not normally result in stored customer data deletion within CommerceGov.
Data Deletion and Retention
When the app is uninstalled through app/uninstalled or Shopify issues a shop redaction request
through shop/redact, CommerceGov revokes operational Shopify access and clears or redacts uninstall-scoped
operational records.
Uninstall and redaction processing may clear or redact operational data such as:
- OAuth access usability, so the token is deactivated and no longer used for API operations
- webhook processing records used for in-flight reliability handling
- apply plans, sync jobs, onboarding jobs, and other transient operational state
- stored owner or shop contact fields where redaction is required for uninstall safety
CommerceGov may retain governance evidence required for deterministic operations, security, legal integrity, and auditability, including command history, audit history, approval records, and product governance records.
CommerceGov does not claim zero retention. Data handling follows operational necessity, security requirements, and governance integrity requirements for controlled Shopify mutations.
Data Security
CommerceGov uses security practices including encrypted HTTPS communication and restricted access to stored data. Access tokens are stored securely and used solely for communication with the Shopify Admin API.
Third-Party Services
CommerceGov may use external AI service providers to generate product content suggestions. Only product content required for generating those suggestions is transmitted to such providers.
CommerceGov does not intentionally transmit payment card data, Shopify customer records, or Shopify customer personal data to AI service providers.
Support
For questions regarding this policy or data handling, contact commercegov.dev@gmail.com.