How does RankEngine access my store?

Through Shopify’s standard app install. You approve a fixed list of permissions on Shopify’s own screen, and RankEngine can do nothing outside that list. Inside the admin, every request is authenticated with a short-lived Shopify session token, not a cookie.

What store data does it keep?

Catalogue data it needs for SEO: product, collection, page and article titles, descriptions, images, handles and SEO fields, plus shop metadata such as name and domain. It does not read or store customer names, emails, addresses or payment details. The privacy policy lists every category.

What does it change, and can I undo it?

Only what you apply, or what an Autopilot rule you switched on applies. Each change records the previous value and the new value and is read back from Shopify before it is marked done. Meta and page-content changes can be undone from Change history for 48 hours. Page titles always wait for your approval.

Does it edit my theme?

Storefront features ship as a theme app embed that you switch on in the theme editor. One fix edits theme code directly: moving a heading that sits in front of the page’s H1. Before writing, RankEngine reads the live file, checks your theme’s own CSS so the page looks the same, and keeps a backup; after writing it reads the file back and restores the original if anything differs. Themes where the change could alter the look are refused.

Where is the data, and how is it protected?

The application and its Postgres database run on Fly.io in the United States, behind Cloudflare. Traffic is encrypted in transit with TLS. Tokens for connected Google accounts are encrypted in the database with AES-256-GCM using versioned keys. Webhooks from Shopify are verified with their HMAC signature before they are processed.

What happens when I uninstall?

Shopify notifies RankEngine, which stops all background work for the store. When Shopify later sends its shop deletion request, every table that holds the store’s data is erased. The GDPR customer data request and customer erasure webhooks are answered as Shopify requires; there is no customer-level data to return or delete.

How do I report a security issue?

Through RankEngine support. Include the store domain and what you found, and please do not test against stores you do not own.