Sub-processors
Last updated: 2026-09-11.
VIBE Search and Discovery (“VIBE”) uses a small number of third-party service providers (“sub-processors”) to operate the app. Each sub-processor is engaged for a specific purpose and receives only the data needed for that purpose. VIBE acts as a data processor on the merchant’s behalf. Shopify is the primary platform provider.
The table describes the service integrations used by the app, including optional integrations. Organizations hosting or managing the application infrastructure also process service data. For how data is collected, see the Privacy policy. For how long VIBE keeps its own copies, see Data retention.
Sub-processor list
Section titled “Sub-processor list”| Provider | Purpose | Data shared | Location | Retention |
|---|---|---|---|---|
| Shopify | Primary commerce platform; source of catalog, theme, order, market, and locale data, and merchant authentication | Data exchanged through the Shopify Admin and Storefront APIs under the app’s granted scopes (product catalog, themes, orders, markets, locales, storefront filters, signed-in customer IDs, B2B company/location identifiers and membership checks) | Per Shopify’s own terms and sub-processor notices | Governed by Shopify’s terms. VIBE-held copies follow the Data retention schedule |
| VIBE AI API | Generates numeric representations (embeddings) of products and search text, translates search text, and suggests Explore controls and taste groups | Product text (titles, descriptions, category, options, metafields) and product images; search text together with a target language; images a shopper uploads for visual search; references to the products a shopper saved in Your Vibe | Provider-hosted processing region(s) | VIBE’s Shopify app stores returned embeddings in its search index and cache. Request retention within the AI service depends on its hosting and upstream provider configuration |
| Anthropic (Claude API) | Three uses. (1) Theme analysis: finds the theme’s search surfaces and the product card render call. (2) Search configuration drafting: decides which product fields carry searchable meaning for the store. (3) Your Vibe: names the recommendation groups built from a shopper’s saved products | (1) Excerpts of the theme’s source files that relate to search and product cards: Liquid sections, snippets, blocks, templates, and JavaScript assets, plus the analyzed file names. (2) A catalog sample: product titles, descriptions, category, product type, vendor, collections, option names and values, selected metafield values, the store’s filter names, and product image URLs, which Anthropic fetches. (3) The titles, vendors, and product types of a shopper’s saved products. No customer, order, visit, or attribution data is sent in any of the three | Provider-hosted processing region(s) | Search configuration drafting requires the Anthropic key. Theme analysis and Your Vibe naming fall back to built-in logic when the key is not configured. No durable storage of prompts is configured by VIBE |
| Resend | Sends operational email to the merchant (install and uninstall confirmations, welcome, usage warnings, limit and overage alerts, inactivity alerts, weekly and monthly summaries, review request, privacy result notification) | Merchant email address (from Shopify shop details, with the Shopify session email as fallback) and the message content (store domain, usage figures, top searches in summaries) | Provider-hosted processing region(s) | Retained per Resend’s processing of transactional email. VIBE stores the merchant email in shop settings and may also hold it in Shopify session records. Email features are skipped when no Resend key is configured |
| Logtail (Better Stack) (Optional) | Application log aggregation when configured | Operational application logs. Access tokens, passwords, cookies, and authorization headers are masked before logging. Search text is not masked, but the application does not intentionally log it | Provider-hosted processing region(s) | Engaged only when a Logtail source token is configured, in which case logs are forwarded as an additional destination. When it is absent, logs go only to the standard application output. Retained per the configured Logtail source |
Sentry is not an engaged sub-processor. There is no Sentry client library installed, no runtime Sentry configuration, and no code path that initializes Sentry or transmits error messages, stack traces, or diagnostic data to it. If a Sentry integration is ever added, Sentry will be added to this list before any data is sent.
Database, search and queue infrastructure
Section titled “Database, search and queue infrastructure”PostgreSQL (application database), Typesense (search index), and Redis (job queue and cache) are software components of VIBE’s infrastructure. These software names do not identify the organizations hosting or managing them. Typesense holds one search index per store with product metadata (title, description, vendor, product type, tags, category, price, availability, variants, image URL, collections, markets, options, and selected metafields) and the product embeddings. The index is deleted with the store’s data.
What VIBE does and does not collect from shoppers
Section titled “What VIBE does and does not collect from shoppers”- VIBE does not build shopper profiles containing names, email addresses or postal addresses. Signed-in customer and B2B company/location identifiers are processed to authorize products and prices; authorization and contextual pricing caches use opaque store-specific hashes and expire after 60 seconds.
- Every search request carries a random visit identifier from the browser’s
sessionStorage, which expires after 30 minutes of inactivity, and the shopper’s IP address, which VIBE uses only for abuse limits and does not write to its database. - When the shopper allows analytics through Shopify’s Customer Privacy API, VIBE stores search events. Sales attribution additionally requires marketing permission and uses a random attribution identifier (
vibe_aidinlocalStorage, also carried as the cart attribute__vibe_aid). These contain no personal details, but they can link one browser’s activity to an order. - The data VIBE shares with sub-processors is limited to what each provider needs for its stated purpose.
Retention and erasure
Section titled “Retention and erasure”VIBE enforces retention windows for the data it stores, and a weekly purge job removes data past those windows (Sundays at 03:00 UTC). The main windows are:
| Data | Retention |
|---|---|
| Search events and product impressions | 90 days |
| Operational events (not billing or error) | 90 days |
| Billing and error events | 1 year |
| Merchant email delivery records | 90 days |
| Redacted order markers | 90 days |
| Daily analytics aggregates | 3 years |
| Monthly billing records | 3 years |
| Customer privacy request results | 7 days after the result is ready |
| Shopify session records | Expired sessions are purged on the weekly job |
The full schedule, including cache and queue entries, is on the Data retention page.
Erasure and uninstall. Uninstall schedules deletion of VIBE’s stored shop data for 30 days later as a fallback. Shopify normally sends shop/redact after 48 hours, starting deletion earlier. Reinstallation preserves configuration only while it still exists; there is no guaranteed 30-day recovery period. Cleanup removes shop-specific Redis caches and queued/retained work before the index and database records, and waits for active jobs. Trial-eligibility and internal staff audit records follow their separately stated retention periods.
Hosting and processing location
Section titled “Hosting and processing location”VIBE’s application services (database, search index, and job queue) run on hosted infrastructure. The providers listed above may process data in the regions described by their own terms, data processing agreements, and sub-processor notices.
Encryption
Section titled “Encryption”Shopify access and session refresh tokens, Storefront API access tokens, the merchant’s storefront password and customer privacy request data are encrypted at rest using AES-256-GCM.
Data Processing Agreement (DPA)
Section titled “Data Processing Agreement (DPA)”For questions about a Data Processing Agreement, processing instructions or contractual documentation for your store, contact support@coi.se. This provider list describes the implementation and does not itself establish a separately executed Data Processing Agreement.
Changes to this list
Section titled “Changes to this list”We may update this sub-processor list as the app evolves. When we add or change a sub-processor, we will update this page and revise the “Last updated” date above.