Introduction
At Isi AI (operated by EzTask SpA, hereinafter "we", "our", or "the Company"), we are committed to protecting the privacy of our users and merchants. This Privacy Policy describes how we collect, use, share, and protect personal information when you use our platform and services, including our integrations with Shopify and with Meta platforms (Facebook and Instagram) through the Meta Marketing API.
Information We Collect
Shopify Store Information
- Store name and domain
- Store owner information (name, email)
- Product and collection data
- Order and transaction information
- Store customer data
- Store performance metrics
Meta Information (Facebook and Instagram)
When you connect your Meta account through the Meta Marketing API, we collect only the data you explicitly authorize in the Facebook consent dialog:
- Your Facebook account identifier and public name (public_profile)
- List of Business Portfolios you manage (business_management)
- List of Facebook Pages you manage (pages_show_list)
- Engagement metrics for your Pages: likes, comments, reach (pages_read_engagement)
- Metrics for your advertising campaigns: impressions, clicks, spend, conversions, ROAS (ads_read)
- Campaign, ad set, and creative configuration when you authorize optimization (ads_management)
We do not store Facebook passwords, nor do we access personal data of your pages' fans or followers beyond aggregate metrics. Access tokens are stored encrypted with AES-256 and are used exclusively to sync the authorized data.
User Information
- Name and email address
- Account information and credentials
- Configuration preferences
- Platform usage history
Technical Information
- IP address and approximate geographic location
- Browser and device type
- Pages visited and time spent
- Cookies and similar technologies
How We Use Your Information
We use the information we collect to:
We do not train AI models with your data. The information we collect is used exclusively to deliver the functionality you enable within your account (segmenting your customers, running campaigns, generating reports). We do not use your data, or your customers' data, to train, fine-tune, or improve generalized AI models, whether our own or third-party.
Data Sharing
We do not sell your personal information. We only share data in the following circumstances:
Service Providers
We work with third parties that help us operate our platform (hosting, analytics, payment processing). These providers are contractually obligated to protect your information.
Authorized Integrations
When you connect third-party services (such as Shopify or Meta / Facebook / Instagram), we share the information necessary for the integration to work as authorized by you in each OAuth consent. Each integration follows the terms and privacy policies of the corresponding platform: Shopify Privacy Policy, Meta Privacy Policy. We do not sell or share data obtained from these integrations with third parties.
Legal Requirements
We may disclose information if required by law, court order, or to protect our legal rights.
Data Security
We implement technical and organizational security measures to protect your information:
Your Rights
You have the following rights regarding your personal information:
Access
Request a copy of the data we hold about you
Rectification
Correct inaccurate or incomplete information
Erasure
Request the deletion of your personal data
Portability
Receive your data in a structured format
Objection
Object to the processing of your data for certain purposes
Restriction
Limit how we use your information
To exercise any of these rights, contact us at hola@getisi.ai.
Data Retention
We retain your personal information while your account is active or as necessary to provide you services. If you decide to cancel your account, we will delete or anonymize your information within 90 days, except where we must retain it for legal obligations, to resolve disputes, or to enforce our agreements.
Shopify Integration
When you install our application in your Shopify store, we access certain store data according to the permissions you authorize. This information is used exclusively to:
- Sync your products and customers for AI analysis
- Generate intelligent customer segmentations
- Create and send automated email marketing campaigns
- Provide reports and performance metrics
We comply with the Shopify API Terms and their privacy policies. You can revoke our access at any time by uninstalling the application from your Shopify admin panel.
Google Integrations
Isi.ai integrates with several Google services via OAuth, and in each case we access only the permissions (scopes) that you explicitly approve on the consent screen. Tokens are stored encrypted (AES-256) or discarded after one-time use, depending on the case. You can revoke Isi.ai's access to your Google account at any time from myaccount.google.com/permissions.
Google Analytics (GA4) — analytics.readonly
When you connect a GA4 property, Isi.ai reads only aggregate metrics (sessions, active users, bounce rate, conversions, purchase revenue, average session duration) segmented by date and by campaign dimensions (source, medium, campaign name, channel). This data feeds your unified marketing dashboard within Isi.ai.
We do not access individual user-level data, nor personally identifiable information of your site's visitors. Access is read-only.
Google Ads — adwords
When you connect a Google Ads account, Isi.ai reads aggregate campaign metrics (impressions, clicks, spend, conversions, CTR, CPC, CPM) to feed your cross-channel reporting in the platform.
The adwords scope that Google provides also allows modifying campaigns. Today Isi.ai uses it in read-only mode only. On the roadmap we plan AI-assisted suggestions (budget adjustments, bidding strategies, ad copy); any change to your campaigns will require your explicit approval in the UI — we never apply modifications autonomously.
Google Cloud DNS — ndev.clouddns.readwrite + cloudplatformprojects.readonly
When you configure your sending domain and use Google Cloud DNS as your provider, Isi.ai uses these scopes to automate the creation of the DNS records needed to authenticate your email with SendGrid:
cloudplatformprojects.readonly: lists the GCP projects you have access to, in order to identify which one contains your domain's DNS zone. Read-only access to project metadata — we do not access other Google Cloud resources.ndev.clouddns.readwrite: creates 3 CNAME records in your DNS zone (two for DKIM and one for SendGrid tracking). We do not read or modify other existing records.
It is a one-time flow: the OAuth token is used only during the authorization callback to create the records and is discarded immediately. We do not store refresh tokens for Cloud DNS.
Google Workspace (Gmail) — gmail.send
When you connect your Gmail account to Isi.ai via OAuth, we request only the send permission (gmail.send) and use it exclusively to:
- Send emails on your behalf from your Gmail account (campaigns and communications that you activate within the platform).
Compliance with Google's Limited Use Policy
Isi.ai's use of information received from the Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We do not use Gmail data to train AI models, whether our own or third-party, including generalized models.
- We do not transfer Gmail data to third parties, except where strictly necessary to deliver the functionality you requested, to comply with applicable laws, or as part of a merger/acquisition with notice to affected users.
- We do not use Gmail data for advertising purposes, whether our own or third-party.
- We do not allow humans to read your emails, except: (a) with your express consent for specific support cases, (b) when necessary for security reasons (e.g., investigating abuse), or (c) when required by law.
- We do not access your inbox. The only permission we request is for sending (gmail.send): we cannot read, modify, or delete emails in your account.
No email warming services for Google accounts
Isi.ai does not provide email warming services for Google accounts: we do not send artificial emails or generate automated opens, replies, or engagement to manipulate a sender's reputation — neither from Gmail accounts nor to them. The gradual volume ramp-up ("domain warmup") described on our site applies exclusively to the real marketing email you send to your own contacts through our sending infrastructure (SendGrid) on your verified domain, and consists solely of daily volume limits. It is never applied to Gmail accounts connected via OAuth.
Cookies and Similar Technologies
We use cookies and similar technologies to improve your experience, analyze the use of our platform, and personalize content. You can control cookies through your browser settings.
| Type | Purpose |
|---|---|
| Essential | Necessary for the platform to function |
| Analytics | Help us understand how you use our platform |
| Functional | Remember your preferences and configuration |
Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes through a notice on our platform or by email. We recommend reviewing this policy regularly.
Contact
If you have questions about this Privacy Policy or about how we handle your information, you can contact us:
