BuyRecord (buyrecord.app) is operated by Stéphane Rix EI (entrepreneur individuel, micro-entrepreneur), 20 allée Corneille, 63370 Lempdes, France. Contact: stephane.rix@buyrecord.app. See also the legal notice.
The short version
BuyRecord publishes how often products are kept or returned. It does not collect personal data about shoppers.
We never request shopper names, email addresses, postal addresses, phone numbers, or device or location data from stores.
Order numbers and receipt references are turned into one-way salted hashes as soon as they arrive, used only to detect duplicates, and never stored in readable form.
We use no cookies, no analytics and no advertising trackers.
Data we receive from stores (Shopify)
When a store installs the BuyRecord app, we read:
Store: shop domain, store name, and whether it is a development (test) store.
Products: title, product page URL, SKU, barcode (GTIN), category and price, stored as a price band.
Orders, last 60 days: which products were bought, when, whether the order was cancelled or a test, refund and return status and return reasons, and the order number and confirmation number (used only, as a salted hash, to verify outcomes that buyers' agents report).
Our requests to Shopify name only these fields; the customer, contact, address and device fields of an order are never requested. Each order line becomes one anonymous outcome record (kept, returned, with reasons) keyed by a salted hash of the store, order and line identifiers.
The access token Shopify issues to the app is stored encrypted. Development stores are flagged as test merchants and their data is never published.
Data we receive from AI agents and API users
Outcome submissions (with an API key, which identifies the submitting agent, not a shopper): product, outcome, reasons, and a proof. For a Shopify order the proof is the shop's domain, the order number and the order confirmation number; we check them against the shop's order record and keep only a salted hash of the two numbers. For a confirmation email, the agent sends the merchant's original email: it is read in memory to verify its signature, order number and product, then discarded. It is never stored or logged; this is the only moment buyer details (such as the name and address in the email) pass through our server. We keep only the merchant's domain, the product name, the purchase date and a salted hash of the order. For a payment receipt, the reference is hashed on arrival and never stored, and the purchase date is converted to "days since purchase".
Technical data: IP addresses are used in memory to apply rate limits and are not written to our logs. For traffic statistics we record, for each request, the time, the page or API operation, the response status and time, the user agent (browser or bot name) and a salted one-way hash of the IP address, never the address itself. These records are kept 90 days and are only visible to us. Other server logs rotate automatically in small, size-limited files.
What we publish
Product scores, numbers of outcomes, outcome breakdowns, top return reasons, product titles and URLs, and per-store return rates, through the API, the MCP server and product pages. All of it is aggregated: no record identifies a shopper.
Where data is kept
Servers: Hetzner Online, Germany. Nightly database backups are kept on the server for 14 days. DNS: Cloudflare (DNS only; Cloudflare does not see site traffic). HTTPS certificates: Let's Encrypt.
Sharing
We do not sell data and do not share it with third parties beyond the hosting providers above. Published aggregates are public by design.
Retention and deletion
When a store uninstalls the app, its access token is deleted immediately and its products stop appearing on product pages.
When Shopify sends a store deletion request (shop/redact), we delete that store's data within 30 days.
Shopify customer data requests (customers/data_request, customers/redact) are acknowledged; we hold no customer data to return or delete.
Your rights
Depending on where you live (for example under the GDPR or US state laws such as the CCPA), you may have rights to access, correct or delete personal data. Because we do not hold shopper data, most requests will find nothing to act on, but you can always write to stephane.rix@buyrecord.app. You can also lodge a complaint with the French data protection authority, the CNIL (cnil.fr), or with the authority where you live.
Changes
We will post changes on this page with a new date.