Last updated: 4 October 2026.
CampaignKoi is operated by Joseph McIlhargey, a sole proprietor doing business as CampaignKoi ("CampaignKoi", "we", "us"). This policy explains what we collect when you visit campaignkoi.com or use our web app, which you sign in to separately and connect to your Shopify store; why; and your choices. "Shoppers" below covers people who visit a merchant's store.
Questions or requests: info@campaignkoi.com.
- Account details: your name, email address and password, which we store only in hashed form. If you sign in with Google, we receive your name, email address and profile picture from Google instead of a password.
- Workspaces: who belongs to each one and their roles.
- Security records: sign-in times, IP address and browser details.
- Projects, pages, design settings, and the images and other files you upload.
- Your conversations with Koi, our AI assistant. They belong to your workspace and aren't deleted when you delete a project.
- Feedback you send us.
When you connect a store, you grant us read access to products, inventory, locations, themes and online-store pages. We copy:
- your catalog: products and their details, prices, inventory, locations and collections;
- your store's pages and theme settings, so new pages match your store.
We don't request access to your orders or customer records.
Publishing features ask for extra permissions, such as writing files, pages or products, only when you use them. We write to your store only when you publish content you've approved. When we replace a theme file, we keep a copy of the original.
Shopify bills you. We receive your plan and charge status from Shopify, never your card or bank details.
- AI usage per workspace, to apply plan allowances.
- Setup and publishing progress (such as installed, synced and published) and which Shopify App Store page an install came from, to improve CampaignKoi. We use no third-party tracking for this.
- Error and performance logs, to keep the service working.
When a shopper asks Shopify to see or delete their data, Shopify forwards the request to us. We keep only the shopper's Shopify customer ID (or email address, if no ID is given) and the order numbers named, to answer the request and show that we did.
Pages you publish become part of your Shopify theme and are served by Shopify. Our storefront code sets no cookies, sends nothing to CampaignKoi and collects nothing about shoppers. Your store's privacy policy and Shopify's policies govern shoppers' data. If you're a shopper, contact the store; we'll help the merchant answer your request.
- To provide CampaignKoi: sign-in, drafting and editing pages with Koi, and publishing what you approve.
- To keep accounts and the service secure, and to prevent abuse.
- To apply plan allowances and work with Shopify's billing.
- To answer support and privacy requests.
- To meet legal obligations.
In the EU and UK, our legal bases are our contract with you, our legitimate interest in running and securing CampaignKoi, and our legal obligations.
We don't sell personal information or share it for cross-context behavioral advertising. We don't use your content or store data to train AI models.
To draft and edit pages, we send the relevant parts of your request, content and store data to our AI model providers, OpenAI and Anthropic. Under their business terms, they don't train their models on this data by default, and they keep it only for limited periods set by their policies, mainly to monitor for abuse. See OpenAI's data controls and Anthropic's retention policy.
- Service providers that run CampaignKoi for us: hosting, email delivery and AI models, listed in our Data Processing Addendum. They may use it only to provide their service to us.
- Shopify, to operate the app and publish what you approve.
- Legal and safety: when the law requires it, or to protect the rights, property or safety of users or others.
- Business transfer: if CampaignKoi is sold or reorganized. We'll tell you if this happens.
CampaignKoi is hosted in the United States on Amazon Web Services. If you're outside the United States, your information is transferred there. For merchants in the EU, UK or Switzerland, our Data Processing Addendum includes the standard contractual clauses.
We keep information only as long as we need it to provide CampaignKoi, for security and recovery, or as the law requires, and then delete it. In practice:
- Account information: while your account is open.
- Projects, files and conversations: until you delete them, where the app allows, or close your account.
- Store data: while your store is connected. When you uninstall, we remove our access and delete the store data we copied. About 48 hours later, Shopify asks us to erase the store's data; we then delete the store's connection record and our copies of what we published to it. Pages already published stay in your theme, because they're part of your store.
- Privacy-request records: as long as needed to show we answered, and to stop deleted data being imported again.
- Logs and backups: for limited periods, for security and recovery. Deleted data can remain in backups until they expire.
- You can edit and delete your projects in the app. To close your account, email us.
- Depending on where you live, you can ask to access, correct, delete or get a copy of your personal information, and object to or restrict some processing. California residents have these rights under the CCPA, and we won't treat you differently for using them. EU and UK residents can also complain to their data protection authority.
- We'll answer within the time the law requires, and may need to confirm your identity first.
We use measures suited to the risk, including encryption in transit, encrypted store credentials, access limited to people who need it, and separation of each workspace's data. Annex 2 of our Data Processing Addendum lists them. No system is perfectly secure. If a breach affects your information, we'll notify you and the relevant authorities as the law requires.
CampaignKoi is a business tool, not for anyone under 18.
We'll post changes here and update the date above. If a change is significant, we'll tell account holders by email or in the app before it takes effect.