Kernvel LabsKernvel Labs
Home AuctionAI Terms

Privacy Policy

Last updated: February 12, 2026

Kernvel Labs ("we," "our," or "us") operates the AuctionAI application and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Shopify applications and visit our website (kernvellabs.com).

1. Information We Collect

1.1 Store Data (via Shopify API)

When you install our app, we access certain data from your Shopify store as authorized by Shopify's OAuth process:

  • Store information (name, domain, email, plan)
  • Product data (titles, descriptions, prices, images, inventory)
  • Customer data (names, emails — only for auction participants)
  • Order data (draft orders created by auctions)

1.2 Auction & Bidding Data

  • Bid amounts, timestamps, and auction participation history
  • Bidder IP addresses and device fingerprints (for fraud detection)
  • Auction preferences and watchlist data
  • WebSocket connection metadata

1.3 Analytics Data

  • Page views, feature usage, and interaction patterns
  • Performance metrics and error logs
  • Aggregated, anonymized usage statistics

1.4 Communication Data

  • Email addresses for auction notifications
  • Email engagement metrics (opens, clicks) via SendGrid/Klaviyo
  • Support correspondence

2. How We Use Your Data

  • Auction Operations: Processing bids, managing auctions, creating draft orders, sending notifications
  • AI & Machine Learning: Training and improving our ML models for price suggestions, fraud detection, market insights, and recommendations. Models are trained on aggregated, anonymized data — never individual store data in isolation.
  • Fraud Detection: Real-time analysis of bidding patterns to protect merchants and buyers from fraudulent activity
  • Email Marketing: Sending auction-related emails (outbid alerts, win notifications, campaigns) when enabled by the merchant
  • Service Improvement: Analyzing usage patterns to improve features, fix bugs, and develop new capabilities
  • Support: Responding to your inquiries and providing technical assistance

3. Third-Party Services

We share data with the following third-party services as necessary to operate our platform:

  • Shopify: Store data is accessed and managed through Shopify's API. Shopify's privacy policy applies to data stored on their platform.
  • SendGrid (Twilio): Email delivery for auction notifications and marketing campaigns. Email addresses and engagement data are processed by SendGrid.
  • Klaviyo: Optional email marketing integration. When enabled, customer emails and auction activity are synced with Klaviyo for segmentation and campaigns.
  • OpenAI: Product descriptions and content may be processed through OpenAI's API for NLP features. No personally identifiable information is sent to OpenAI.

We do not sell your personal data to any third party.

4. Data Retention & Deletion

  • Active accounts: Data is retained for as long as your app is installed and your account is active.
  • After uninstall: We delete your store data within 30 days of app uninstallation. Aggregated, anonymized data used for ML model training may be retained.
  • Bidding data: Auction and bidding records are retained for 12 months after auction completion for dispute resolution, then deleted.
  • Backups: Encrypted backups may retain data for up to 90 days after deletion before being purged.
  • On request: You may request immediate deletion of your data at any time by contacting us.

5. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Object: Object to processing of your data for certain purposes.

To exercise any of these rights, contact us at support@kernvellabs.com. We will respond within 30 days.

6. CCPA Compliance (California Users)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

  • Right to know what personal information we collect and how it is used
  • Right to request deletion of your personal information
  • Right to opt-out of the sale of personal information (we do not sell personal data)
  • Right to non-discrimination for exercising your privacy rights

7. Cookies & Tracking

Our website uses minimal cookies:

  • Essential cookies: Required for app functionality (session management, authentication)
  • Analytics cookies: Anonymized usage tracking to improve our services

We do not use third-party advertising cookies. You can control cookie preferences through your browser settings.

8. Data Security

We implement industry-standard security measures including:

  • TLS/SSL encryption for all data in transit
  • AES-256 encryption for data at rest
  • Regular security audits and penetration testing
  • Access controls and authentication for all systems
  • Automated threat monitoring and intrusion detection

9. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

  • Email: support@kernvellabs.com
  • Company: Kernvel Labs
© 2026 Kernvel Labs. All rights reserved. | Home | Terms | Privacy