What Data Leaves Your Store When a Shopify App Reads Reviews
Shopify app permissions, protected customer data, and what an AI summary app actually sends out. What to check before you install one.
Installing a Shopify app means granting it permissions, and the permission screen is the last honest moment before the app is inside your store. It tells you what the app can reach. It does not tell you what the app actually sends anywhere, how long that data is kept, or who else receives it.
For an app that reads reviews and sends them to an AI service, those three questions are the whole privacy assessment. Here is how to answer them for any app in this category, and what the answers are for Sumzy.
What data leaves your store when a Shopify app summarizes reviews?
It depends on the app, and the scope varies more than the category name suggests. The data Sumzy, an AI review summary app for Shopify, sends to its AI processing service is specifically: the text content of product reviews, the star rating for each review, a coarse recency band indicating the approximate age of the review, a product identifier, and your configured output language and tone settings. No customer names, no email addresses, no reviewer usernames, no order identifiers, no purchase amounts, and no IP addresses leave your store.
That list is the thing to demand from any app you are evaluating. An app that describes what it sends as "your review data" has told you nothing, because "review data" in most review apps includes the reviewer's name and email.
How Shopify's protected customer data rules apply
Shopify treats customer personal information as a separate category with its own rules. An app that requests access to customer data through the Admin API has to declare why it needs each field, meet a set of data protection requirements, and pass an approval step before it can go live. The point of the regime is that an app should not be able to quietly hold your customers' personal data because you clicked install.
The useful consequence for you is that the permission screen is meaningful. If an app never asks for customer or order access, it cannot read your customers through the Admin API at all, whatever its privacy policy says.
The permissions Sumzy asks for at install are write access to products, which is how the summary gets onto the product, and read access to your store's published languages, which is how it knows which languages your store serves. Neither is a customer data permission.
Shopify also requires every app to implement three privacy webhooks: a customer data request, a customer redaction request, and a shop redaction request. Sumzy implements all three. This is a floor rather than a differentiator, since it is mandatory for App Store listing, but an app that handles them properly is an app that has thought about deletion.
What Sumzy sends and what it does not
To be precise about the data scope, in the same terms used for the WooCommerce plugin so that the two cannot drift apart.
Sumzy sends to its AI processing service: the text content of product reviews, the star rating associated with each review, a coarse recency band indicating the approximate age of the review (for example, "recent" or "older"), the product identifier, and your configured output language and tone settings.
Sumzy does not send: customer names, customer email addresses, reviewer usernames, order identifiers, purchase amounts, IP addresses, or any data that identifies the reviewer.
The review text that is sent is the text the reviewer chose to make public when they submitted their review. It is the same text already displayed on your product page for any visitor to read.
On Shopify there is one extra link in that chain, because the reviews are not Shopify's to begin with. They live in your review app, and Sumzy reads them from there. Which reviews the app can reach covers that connection. What matters for privacy is that the reviewer identity fields your review app holds are dropped before anything is sent onward, rather than travelling along and being ignored at the other end.
Data retention. After the AI service processes the review set and returns a summary, the raw review text is not retained by the AI service beyond the processing period. On the Batch API processing path, which is the primary processing method, review data may be held at the AI subprocessor (Anthropic) for up to approximately 29 days as part of the batch processing infrastructure. This is documented in Anthropic's data handling terms and is reflected in Sumzy's privacy policy and sub-processor disclosures at sumzy.io.
Sumzy's own Shopify app records enough about your reviews to know when they have changed: counts, ordering, and a hash. It does not keep the review text.
Where the summary is stored
The finished summary is written to a JSON metafield on the product, in your Shopify store. One metafield holds the whole summary for that product, including any additional languages. It is your store's data, on your store's product, and it is what the theme block renders to shoppers.
The Sumzy backend keeps the derived summary as well, so a generation can be polled to completion and an unchanged review set can be skipped instead of summarized again. What the backend does not keep is the raw review text. That is discarded once the summary is written, and it is the part that matters for a data protection assessment.
Because the summary is stored on the product rather than fetched at render time, no request goes to Sumzy when a shopper loads a product page, which means no shopper IP address reaches Sumzy either. What the app does on the storefront itself covers that render path in more detail. Privacy and page speed happen to point the same way here, which is convenient but not a coincidence: both follow from storing the summary instead of fetching it.
What to check in any app's privacy disclosure
The Shopify App Store listing and the app's own privacy policy are where this should be answerable. Before you install anything that touches review data, look for the following.
A named AI subprocessor. If the app uses AI, some AI service receives your data. The policy should name it. "We use AI" without naming the provider is not a sufficient disclosure, and you cannot sign a data processing agreement with an unnamed entity.
An explicit list of what is not sent. Any app can list what it sends. The list that tells you something is the one that says what it excludes. If a policy does not say whether customer names travel with the review text, assume they do until the vendor says otherwise in writing.
A retention period. "Not retained" and "retained for 30 days" are both acceptable answers. No statement at all is not.
Where the output is stored. An app that stores your summaries only on its own servers has made your product pages dependent on it. An app that writes them into your store has not.
A data processing agreement. If you serve EU customers, you should be able to request a DPA from any app vendor processing data on your behalf. A vendor who cannot produce one is not ready for your store.
For how the apps in this category line up on these points, how these apps compare on what leaves your store puts them side by side. The equivalent breakdown for the other platform, including the GDPR framing in more depth, is in what leaves your server on a WooCommerce store, and the data scope is deliberately identical on both.
Your responsibilities as the data controller
Your store is the data controller for your customers' data. Apps that process it on your behalf are processors. In practice that means three things.
Your privacy policy should disclose that reviews are summarized by an AI service and name the subprocessors involved. You should have a DPA in place with the app vendor. And you should be able to answer a customer's data access request by knowing where their data has been sent, which requires knowing it in advance rather than finding out during the 30 day response window.
For most Shopify stores, review text without identifying fields sits in a low-risk zone, because the text is already public and does not identify the reviewer as a person. The higher-risk processing in your app stack is almost always the review collection app itself, which holds email addresses and order history because it has to. That is where the careful documentation belongs.
A next step
Sumzy offers a 14-day free trial on Shopify. You approve the subscription from your Shopify admin, so there is no separate card to enter and any charge appears on your Shopify bill. The trial becomes a paid plan when the 14 days are up, so cancel before then and you pay nothing. The pricing page has the plans, and the privacy policy and sub-processor list are linked from every page of the site.
Help shoppers decide faster
14-day free trial on WooCommerce and Shopify.