Privacy Policy — ViewForge: YMM Search & Filter
Last updated: September 7, 2026
ViewForge: YMM Search & Filter (“the App”) is developed by CunningOrb (“we”, “us”, “our”). This policy describes what data the App accesses, how it is used, and your rights regarding that data.
What data we collect
Merchant data (Shopify admin users)
When you install the App, Shopify provides us with:
- Shop domain and access tokens — required to authenticate API requests on your behalf.
- Admin user name and email — provided by Shopify’s OAuth flow for session management.
This data is stored in an encrypted database and used solely to operate the App within your Shopify admin.
Fitment data (product-level)
All fitment records — templates, taxonomy nodes, and entity assignments — are stored as Shopify metaobjects and metafields within your Shopify store. The records themselves are never copied to our servers: you retain full ownership and can delete them at any time through the Shopify admin.
A limited amount of product text — product titles, and the make and model designations read out of them — is sent to services we operate, so that the App can tell a real vehicle model from a part number and can draft page copy. This is described in full under AI processing. No customer data is involved in any of it.
Storefront visitor data
The App’s theme extension stores vehicle selections and garage entries in the visitor’s browser localStorage. This data:
- Never leaves the visitor’s browser.
- Is not transmitted to our servers or any third party.
- Can be cleared by the visitor at any time through their browser settings.
What we do NOT collect
- Customer personal information (names, emails, addresses, payment details).
- Analytics, tracking pixels, or behavioral data.
- Cookies.
- Product descriptions, prices, inventory levels, images, or order data — none of these are read by the AI features described below.
How we use data
| Data | Purpose |
|---|---|
| Shop domain and access tokens | Authenticate Shopify API calls, manage your fitment configuration |
| Admin user session info | Maintain your logged-in session within the embedded app |
| Fitment metaobjects/metafields | Provide fitment search, filtering, and garage functionality on your storefront |
| Browser localStorage | Remember the visitor’s vehicle selection and garage between page loads |
| Make and model text from product titles | Ask an AI model whether a designation is a real vehicle model or a part number, so junk fitment is kept off your review screen |
| Product titles the parser could not read | Improve the parser’s vocabulary, so the same titles become readable for every merchant |
| Shop name, fitment path, product count and titles | Draft SEO titles, meta descriptions and page introductions for review (Pro+ plans) |
| Shop contact email | Send onboarding and milestone emails about your installation |
AI processing
Two features in the App use an AI language model. Both run on Cloudflare Workers AI, inside infrastructure we operate in our own Cloudflare account. No other AI provider receives your data — not OpenAI, not Anthropic, not Google, not any other vendor.
Cloudflare’s published commitment for this service is that “Cloudflare does not use your Customer Content to (1) train any AI models made available on Workers AI or (2) improve any Cloudflare or third-party services” (Workers AI data usage).
Smart Parse
When the App reads fitment out of your product titles, some results are genuinely ambiguous: a code sitting next to a make in a title may be a real model designation, or it may be a part number. Smart Parse asks a model that one question about results the ordinary parser has already produced.
What is sent:
- The make and model designation already extracted from a product title.
- One sample product title per distinct make/model pair, truncated to 300 characters, as context for that question.
Questions are deduplicated first, so a catalogue of several thousand products typically produces a few hundred distinct questions rather than one per product.
The model can never create or improve a fitment record. A verdict can only remove a low-confidence record from your review screen. It cannot add a fitment, raise a confidence score, or publish anything. If the model is unavailable, times out, returns something unexpected, or the daily processing budget is spent, the App behaves exactly as it would with the feature switched off.
Improving the parser’s vocabulary
Product titles the parser could not read are sent to the same service, so that we can see which vocabulary is missing and add it. We cannot guess what a parser is failing on; we can look at what failed.
These titles are stored on our infrastructure. No shop domain is stored with them — only a salted hash, which lets us count how many distinct stores saw a given title without recording which stores they were.
SEO page copy (Pro+ plans)
On Pro+ plans, the App can draft copy for the fitment landing pages it generates: an SEO title, a meta description, and a short factual introduction.
What is sent:
- Your shop name.
- The fitment path and labels for the page — for example a make, a model and a year.
- The number of products on that page.
- A bounded set of product titles from that page.
Product descriptions are not sent. Neither is customer, order, pricing or inventory data.
Drafted copy is never published automatically. It is shown to you as a proposal and is saved only when you accept it. The model does not decide product compatibility, cannot add or remove products from a page, and cannot change your product descriptions.
Why product text cannot hijack the App
Product text is treated as untrusted input. Text placed in a product title cannot change the model’s instructions or cause the App to take any action, because the only thing a response is allowed to do is answer the narrow question it was asked. That is a property of the design rather than a filter that has to catch things: even a deliberately hostile product title has no action available to it.
Third-party services
The App contains no advertising, no tracking pixels and no analytics SDKs, and we do not sell, rent or trade your data. Besides Shopify’s own APIs, these providers process data on our behalf:
| Provider | What it receives |
|---|---|
| Cloudflare | Hosts the Smart Parse service and provides the Workers AI models behind the features above. Receives product title text and the make/model designations read from it. Does not train on it. |
| Resend | Delivers onboarding and milestone email. Receives your shop’s contact email address and the message itself. No product or customer data. |
| NHTSA vPIC | A free United States government vehicle database. When VIN decoding is used (Premium plans), the VIN is sent to it to resolve the vehicle. No shop or customer identifier accompanies it. |
Data retention and deletion
- Session data is retained while the App is installed. When the App is uninstalled or a shop redact request is received from Shopify, all session records for that shop are deleted.
- Fitment data (metaobjects and metafields) persists in your Shopify store. Uninstalling the App does not delete this data — you can remove it through the Shopify admin if desired.
- Theme extension blocks are automatically removed by Shopify when the App is uninstalled.
- Browser localStorage persists on the visitor’s device until they clear it. It is not affected by App installation or removal.
- Smart Parse verdicts — the answer to “is this make and model a real vehicle” — are cached so the same question is not asked twice. The cache holds the make, the model designation and the answer. It is keyed on the question and carries no shop identifier, so it is not associated with your store and is not removed by uninstalling.
- Unreadable product titles collected to improve the parser are retained while that vocabulary work is outstanding. They are stored against a salted shop hash rather than a shop domain. You may ask us to remove titles originating from your store at any time using the contact address below.
GDPR compliance
The App responds to all mandatory Shopify GDPR webhooks:
- Customer data request — The App stores no customer personal data, so no data is returned.
- Customer redact — No customer data to delete; the request is acknowledged.
- Shop redact — Session records for the shop are deleted.
The AI features described above never receive customer personal data, so a customer data request or redact has nothing to return or erase from them. What they process is product catalogue text and the shop’s own identifiers.
Your rights
You may request access to, correction of, or deletion of any data we hold about your store by contacting us. Since all fitment data lives in your Shopify store, you have direct control over it at all times.
Changes to this policy
We may update this policy to reflect changes in the App’s functionality. The “Last updated” date at the top will be revised accordingly.
Contact
For privacy questions or data requests, contact us at:
Email: info@normalview.pro