Kernvel Labs
Live on Shopify
AAuctionAI LListIQ GGateIQ SStockIQ RReturnsIQ SSearchIQ VVendorIQ
In App Review
SSupportIQ
Nearza Platform → Development Services Growth Marketing Developer Platform & APIs
Book a Demo

Privacy Policy

Last updated: July 14, 2026

Kernvel Labs ("we," "our," or "us") operates the Kernvel AI Auction, Kernvel ListIQ, Kernvel GateIQ, Kernvel StockIQ, Kernvel ReturnsIQ, Kernvel Image SearchIQ, and Kernvel AppBuilder applications — together, the Kernvel ecosystem — and related services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use any of our Shopify applications, generated storefront applications, APIs, and website (kernvellabs.com). Each app is governed by this Privacy Policy; where a specific app processes data in a materially different way, we call it out below.

1. Information We Collect

1.1 Store Data (via Shopify API)

When you install our app, we access certain data from your Shopify store as authorized by Shopify's OAuth process:

  • Store information (name, domain, email, plan)
  • Product data (titles, descriptions, prices, images, inventory)
  • Customer data needed for the feature you use, such as bidder, wishlist, return, support, membership, vendor-order, or notification context
  • Order, return, draft-order, payout, invoice, support-conversation, and vendor-order data when an app needs that data to perform its job

AppBuilder's merchant installation uses product, collection, inventory, publication, and store information to create and synchronize the merchant's app. Its current Shopify Admin configuration does not request broad read access to all orders or customers. A shopper who chooses to sign in may separately authorize Shopify Customer Account access for their own profile and order history.

1.2 App-Specific Operational Data

  • Bid amounts, timestamps, and auction participation history
  • Bidder IP addresses and device fingerprints (for fraud detection)
  • Auction preferences and watchlist data
  • Real-time connection metadata
  • Wishlist, saved-product, subscriber, campaign, and demand-signal data
  • Membership, access-rule, approval-request, and gated-content data
  • Inventory, forecast, supplier, purchase-order, alert, and stock-state data
  • Return, refund, exchange, return-reason, fraud-signal, and policy data
  • Visual-search events, indexed catalog metadata, image-search attributes, and demand-cluster data. Shopper-uploaded search images are processed for the search request and are not sold.
  • Vendor, vendor-product, vendor-order, commission, payout, invoice, and marketplace-operation data
  • Support conversations, messages, escalations, knowledge-base content, customer context, product context, and attachments needed to resolve a support request
  • AppBuilder project settings, page and navigation layouts, theme and brand assets, generated content, localization settings, feature configuration, release-readiness results, build status, and published destination metadata
  • AppBuilder shopper data such as account identifiers authorized by the shopper, wishlist items, inbox messages, loyalty and referral activity, app preferences, and deletion requests
  • Push-notification subscription data such as device or browser push tokens, public encryption keys, platform, locale, consent state, delivery status, and notification interactions
  • Encrypted Apple, Google Play, signing, and Firebase configuration supplied by a merchant when the merchant elects to build or release a native app. Secret values are not displayed back in ordinary application responses.

1.3 Analytics Data

  • Page views, feature usage, and interaction patterns
  • Performance metrics and error logs
  • Aggregated, anonymized usage statistics
  • For AppBuilder, install, activation, feature-adoption, app-session, notification, search, catalog-interaction, checkout-handoff, and conversion signals that the application can verify

1.4 Communication Data

  • Email addresses for auction notifications
  • Email engagement metrics (opens, clicks) via SendGrid/Klaviyo
  • Support correspondence

2. How We Use Your Data

  • App Operations: Processing bids, wishlists, memberships, inventory workflows, returns, visual searches, vendor marketplace workflows, support conversations, generated storefront configuration and builds, notifications, and related merchant actions
  • AI & Machine Learning: Generating layouts, content, translations, recommendations, insights, search assistance, fraud signals, and other features requested by the user. We send only the information needed for the selected feature. AppBuilder AI requests are designed to use merchant-authorized brand, configuration, and catalog context without identifiable shopper information. We do not use one merchant's raw private data to train a model for another merchant.
  • Fraud Detection: Real-time analysis of bidding patterns to protect merchants and buyers from fraudulent activity
  • Notifications & Marketing: Sending app-related emails or messages, such as auction alerts, wishlist/restock emails, campaign messages, support notifications, or operational notices, when enabled and allowed by the merchant and applicable consent rules
  • Service Improvement: Analyzing usage patterns to improve features, fix bugs, and develop new capabilities
  • Support: Responding to your inquiries and providing technical assistance

3. Third-Party Services

We share data with the following third-party services as necessary to operate our platform:

  • Shopify: Store data is accessed and managed through Shopify's API. Shopify's privacy policy applies to data stored on their platform.
  • SendGrid (Twilio): Email delivery for auction notifications and marketing campaigns. Email addresses and engagement data are processed by SendGrid.
  • Klaviyo: Optional email marketing integration. When enabled, customer emails and auction activity are synced with Klaviyo for segmentation and campaigns.
  • Third-party AI providers: Some AI features (such as content generation, demand-sensing assistance, and natural-language insights) may process anonymized product and store data through third-party AI providers. No personally identifiable customer information is sent to these providers. We disclose specific AI sub-processors on request — email support@kernvellabs.com for the current list.
  • OpenAI and Amazon Web Services: Depending on the feature and deployment configuration, AppBuilder may use OpenAI or Amazon Bedrock to process the limited merchant-authorized context needed for an AI request. AppBuilder enforces plan and safety limits before provider use.
  • Apple, Google, and browser push services: When a merchant enables a native or web application, Apple Push Notification service, Firebase Cloud Messaging, Google Play, App Store Connect, or a browser's push service may process app identifiers, device tokens, build or listing metadata, and delivery information needed for that function. Their own terms and privacy policies also apply.
  • Codemagic: When a merchant requests a native build, AppBuilder may send encrypted or short-lived build inputs and source configuration to Codemagic for continuous integration, signing, and artifact creation. Access is limited to the requested build workflow.
  • Sentry: We may use Sentry for application error reporting and performance diagnostics. We configure telemetry to avoid intentionally sending shopper content or secret credentials.
  • Tawk.to (live chat): Our website live chat widget is provided by Tawk.to. When you initiate a chat, Tawk.to processes the message content you send, your IP address, and standard browser metadata in order to deliver the conversation in real time. We use these chats only for support and sales inquiries. We do not sell, rent, or share chat transcripts with any other third party. Tawk.to's processing is governed by their own privacy policy at tawk.to/privacy-policy.
  • Google Analytics: We use Google Analytics (GA4) to understand how visitors use our website — pages viewed, time on site, referral source, and approximate location. Google processes this data on our behalf and may set cookies in your browser to distinguish visitors. IP addresses are anonymized. We do not use this data for advertising and do not share it with other third parties. Google's processing is governed by their privacy policy at policies.google.com/privacy. You can opt out site-wide with the Google Analytics Opt-out Browser Add-on.
  • Calendly (meeting scheduling): If you book a call with us through the Calendly widget on our website, Calendly processes the name, email address, and any details you provide, along with your selected meeting time, to schedule and run the meeting. This information is used solely to arrange and conduct the call. Calendly's processing is governed by their own privacy policy at calendly.com/privacy.

We do not sell your personal data to any third party.

4. Data Retention & Deletion

  • Active accounts: Data is retained for as long as your app is installed and your account is active.
  • After uninstall: We delete your store data within 30 days of app uninstallation. Aggregated, anonymized data used for ML model training may be retained.
  • Bidding data: Auction and bidding records are retained for 12 months after auction completion for dispute resolution, then deleted.
  • Backups: Encrypted backups may retain data for up to 90 days after deletion before being purged.
  • On request: You may request immediate deletion of your data at any time by contacting us.
  • AppBuilder credentials and build data: Merchant-supplied release credentials are retained only while the merchant keeps the integration configured or as needed to complete an authorized build, then removed when the merchant disconnects them, deletes the project, or uninstalls the app, subject to the encrypted-backup period above. Build artifacts and diagnostic logs may be retained for a limited support and audit period.
  • AppBuilder shopper deletion: An authenticated shopper may request account deletion in the generated app. AppBuilder first requests erasure through Shopify and, only when that request is accepted, purges the shopper's AppBuilder identity and related scoped data. The shopper may also contact the merchant or Kernvel support.

5. GDPR Compliance (European Users)

If you are located in the European Economic Area (EEA), you have the following rights under the General Data Protection Regulation (GDPR):

  • Right to Access: Request a copy of all personal data we hold about you.
  • Right to Rectification: Request correction of inaccurate personal data.
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten").
  • Right to Data Portability: Request your data in a structured, machine-readable format.
  • Right to Restrict Processing: Request that we limit how we use your data.
  • Right to Object: Object to processing of your data for certain purposes.

To exercise any of these rights, contact us at support@kernvellabs.com. We will respond within 30 days.

6. CCPA Compliance (California Users)

If you are a California resident, the California Consumer Privacy Act (CCPA) provides you with the following rights:

  • Right to know what personal information we collect and how it is used
  • Right to request deletion of your personal information
  • Right to opt-out of the sale of personal information (we do not sell personal data)
  • Right to non-discrimination for exercising your privacy rights

7. Cookies & Tracking

Our website uses minimal cookies:

  • Essential cookies: Required for app functionality (session management, authentication)
  • Analytics cookies: Google Analytics (GA4) sets cookies (e.g. _ga) to measure anonymized, aggregate usage so we can improve our services. IP addresses are anonymized and the data is never used for advertising.
  • Live chat cookies: If you interact with the Tawk.to chat widget on our website, Tawk.to may set cookies on your browser to remember your conversation across page loads. These cookies are set only when you engage with the widget.

We do not use third-party advertising cookies. You can control cookie preferences through your browser settings.

8. Data Security

We implement industry-standard security measures including:

  • TLS/SSL encryption for all data in transit
  • Industry-standard encryption for data at rest
  • Regular security audits and penetration testing
  • Access controls and authentication for all systems
  • Automated threat monitoring and intrusion detection
  • Encryption and redaction of merchant-supplied signing, app-store, and push credentials

9. International Processing

Kernvel Labs operates from Canada and India and uses service providers that may process information in the United States, Canada, the European Economic Area, India, and other countries where they operate. Data-protection laws may differ from those in your jurisdiction. Where required, we use contractual, organizational, and technical safeguards for international transfers and limit each provider to the data needed for its service.

10. Children's Privacy

Our services are not directed to individuals under the age of 16. We do not knowingly collect personal information from children.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on this page and updating the "Last updated" date. Continued use of our services after changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us:

  • Business email: kernvellabs@gmail.com
  • Support email: support@kernvellabs.com
  • Company: Kernvel Labs
Halifax, Nova Scotia, Canada · +1 902 537 0380 Kumar Palms, Kondhwa, Pune, India · +91 74981 07414
© 2026 Kernvel Labs. All rights reserved. | Home | Terms | Privacy