Legal
Privacy Policy
Last updated: July 2, 2026
Innovimia Technologies Inc., which owns and operates MigroAI ("MigroAI," "Migro," "we," "us," or "our"), provides an AI-First Commerce Transition Platform — a software-as-a-service (SaaS) platform that helps merchants transition their stores to AI-first commerce so they are discoverable, understandable, trustworthy, comparable, and recommendation-ready for AI systems. The platform's first step is the AI Readiness Audit, which diagnoses how ready a store is. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to our website, our platform, the AI Readiness Audit, and related services (together, the "Services").
By using the Services, you agree to the collection and use of information in accordance with this Policy. If you do not agree, please do not use the Services.
1. Who We Are
Innovimia Technologies Inc. is the data controller for personal information processed through the Services, except where we act as a processor on behalf of a merchant customer (for example, when we analyze catalog or store data you connect to the platform). Where we act as a processor, our handling of that data is also governed by the agreement between Innovimia Technologies Inc. and the merchant.
2. Information We Collect
We collect the following categories of information:
Information you provide
- Account information — name, email address, company name, and login credentials when you create an account.
- Billing information — where you subscribe to a paid plan, billing contact details and payment records (payment card data is handled by our payment processor, not stored by Migro).
- Communications — messages, support requests, and feedback you send to us.
Store and catalog data
- Uploaded content — product catalogs, CSV files, descriptions, pricing, images, policies, and other store content you upload for analysis.
- Connected platform data — where you install or connect Migro from a commerce platform such as Shopify, your store information flows in automatically through that platform's authorized APIs (for example, products, collections, store metadata, and policies) so we can perform the AI Readiness Audit and, over time, ongoing monitoring and re-assessment.
Information collected automatically
- Usage data — pages viewed, features used, audits requested, and actions taken within the Services.
- Device and log data — IP address, browser type, device identifiers, referring pages, and timestamps.
- Cookies and similar technologies — used to keep you signed in, remember preferences, and measure and improve the Services. See the "Cookies" section below.
3. How We Use Information
We use the information we collect to:
- Provide, operate, and maintain the Services, including generating your AI Readiness Audit, scores, and recommendations.
- Analyze your store and catalog data to assess how understandable, trustworthy, and recommendation-ready it is for AI systems.
- Create and manage your account, process subscriptions, and provide customer support.
- Communicate with you about updates, security alerts, and administrative messages, and — where permitted — product news and marketing.
- Monitor, secure, troubleshoot, and improve the Services, including developing new features.
- Detect, prevent, and address fraud, abuse, and security incidents.
- Comply with legal obligations and enforce our terms.
4. AI and Automated Processing
The Services use automated systems, including machine learning and large language models, to evaluate your store data and produce readiness scores and recommendations. These outputs are generated to help you improve your store; they are advisory and do not constitute legal, financial, or professional advice.
We do not use your confidential store or catalog data to train third-party foundation models. Where we use third-party AI providers to process your data, we do so under agreements that restrict their use of that data to providing services to us.
5. Legal Bases for Processing
Where the GDPR or similar laws apply, we process personal information on the following bases: performance of a contract with you; our legitimate interests in operating and improving the Services; your consent (which you may withdraw at any time); and compliance with legal obligations.
6. How We Share Information
We do not sell your personal information. We share information only as described below:
- Service providers — vendors who host our infrastructure, process payments, send communications, provide analytics, and supply AI processing, under contractual confidentiality and data-protection obligations.
- Connected platforms — where you authorize an integration, we exchange data with that platform as needed to deliver the Services.
- Legal and safety — where required by law, legal process, or to protect the rights, property, or safety of Migro, our users, or others.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
7. Data Retention
We retain personal and store data for as long as your account is active or as needed to provide the Services, and thereafter as required to comply with our legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your data as described below; we will delete or anonymize it unless we are required to retain it.
8. Data Security
We use technical and organizational measures designed to protect your information, including encryption in transit, access controls, and hosting with reputable cloud infrastructure providers. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
9. International Transfers
We may process and store information in countries other than your own. Where we transfer personal information across borders, we use appropriate safeguards, such as standard contractual clauses, to protect that information.
10. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. You can exercise these rights by contacting us at the address below. You may also:
- Update your account information in the platform settings.
- Opt out of marketing emails using the unsubscribe link in those messages.
- Disconnect a connected commerce platform at any time through the integration settings.
We will not discriminate against you for exercising your privacy rights.
11. Cookies
We use cookies and similar technologies to operate and secure the Services, remember your preferences, and understand how the Services are used. You can control cookies through your browser settings; disabling some cookies may affect functionality.
12. Children's Privacy
The Services are intended for businesses and are not directed to individuals under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
13. Changes to This Policy
We may update this Policy from time to time. When we do, we will revise the "Last updated" date above and, where appropriate, provide additional notice. Your continued use of the Services after changes take effect constitutes acceptance of the updated Policy.
14. Contact Us
If you have questions about this Policy or how we handle your information, contact Innovimia Technologies Inc. at privacy@innovimia.com.