RealShield AI, LLC ("RealShield AI," "we," "us," or "our") is an AI-powered supplier verification platform for ecommerce merchants. We are organized as a Delaware Limited Liability Company and are committed to responsible data stewardship as a foundational principle — not an afterthought.
This Privacy and Data Protection Policy applies exclusively to the RealShield AI application for SHOPLINE merchants (the "App"), distributed through the SHOPLINE App Store. It describes what merchant information we process, why we process it, how we protect it, how long we retain it, and the rights available to you as a merchant.
This policy does not govern the SHOPLINE platform itself. Merchants should review SHOPLINE's own privacy documentation for information about how SHOPLINE handles store and account data. This policy similarly does not apply to RealShield AI's consumer-facing website (realshieldai.com), which is governed by a separate privacy notice.
By installing and using the App, you acknowledge this policy and the data practices described herein.
RealShield AI processes the minimum information necessary to deliver the App's supplier verification capabilities. We process four categories of merchant information:
When you install the App, SHOPLINE provides us with your store domain (for example, yourstore.myshopline.com) and basic store region information. This identifier is used to associate your account, scan history, supplier profiles, and settings with your store throughout the App.
We do not receive your SHOPLINE account credentials. Authentication is handled entirely by SHOPLINE's OAuth 2.0 system.
We maintain a record of your current subscription tier (Starter, Growth, or Pro), your monthly credit balance, subscription status, and billing cycle dates. This information is necessary to enforce plan limits and present accurate usage data within the App.
All payment processing is performed by SHOPLINE's built-in subscription billing infrastructure. RealShield AI does not collect, transmit, store, or have access to any payment card numbers, bank account details, or other financial information.
When you submit a photo, video, or audio file for analysis, we process the following:
Video submissions are limited to twelve (12) seconds in duration. The raw media file is not retained by RealShield AI beyond the duration of the scan. Our data handling for media files is described in detail in Section 4.
RealShield AI allows you to create and manage supplier profiles within the App. Profile data consists entirely of information you manually enter: supplier name, country of operation, contact notes, status designations (active, flagged, or blocked), and any notes you attach to individual scans. Trust scores displayed within the App are calculated algorithmically from your own scan results — they are derived data, not sourced from external databases.
Supplier profile data belongs to you. It is stored solely to provide the App's functionality and is permanently deleted when you uninstall the App (see Section 10).
We retain scan history records and timestamps to populate your Scan History view, and we store your App preferences and notification settings. We do not collect device fingerprints, browser history, or behavioral analytics beyond what is necessary to present your own activity within the App.
If you use the App's optional Return Verification feature, we process the following information, all of which is manually entered or uploaded by you:
Return Verification records are stored separately from your Supplier Assessment and Scan History records, and submitted return photos are subject to the same zero-persistence media architecture described in Section 4 — purged within twenty-four (24) hours by default unless you explicitly retain them.
Return Verification does not access your store's order data, customer records, or any information from your SHOPLINE account beyond what you manually enter. We do not receive or store any of your customers' personal information through this feature.
Each category of information we process serves a specific, documented purpose. We do not process merchant information for advertising. We do not sell, rent, or trade merchant information to third parties for their independent use.
| Information Category | Primary Purpose |
|---|---|
| Store domain | Account identification; associating all App data with your store |
| Subscription and billing | Enforcing plan credit limits; displaying accurate usage data |
| Media files | Performing the AI deepfake and authenticity analysis you requested |
| Scan results and metadata | Building your scan history; calculating supplier trust scores |
| Supplier profiles | Enabling supplier assessment management within the App |
| App preferences | Delivering notifications and respecting your configured defaults |
RealShield AI is designed around a zero-persistence principle for all media submitted for analysis by default. This is a deliberate architectural decision, not a policy statement.
Static uploads (photo, video, audio): When you submit a file for scanning, the file is transmitted directly to our AI detection partner for forensic analysis. By default, RealShield AI does not write the raw media to persistent storage beyond what is necessary to complete the scan, and raw media is purged within twenty-four (24) hours of submission.
What is retained by default: Following analysis, we store the scan result — your AI risk score, file type, file size, and scan timestamp — to populate your Scan History. We do not retain the raw media by default. You can delete individual scan records or your complete history at any time from within the App.
Optional retention for service improvement. You may choose to opt in, at any time via Settings, to allow RealShield AI to retain your submitted media beyond the 24-hour window. This setting is off by default and requires your affirmative action to enable. When enabled, retained media is used solely to (1) improve and refine RealShield AI's detection models, and (2) recognize previously-scanned media to avoid redundant analysis of identical files, which may reduce your credit costs on repeat submissions. Media retained under this setting is kept for no longer than three (3) years from the date of submission, or until you disable the setting, whichever occurs first. You may disable this setting at any time; media submitted after opting out returns to the standard 24-hour purge. We do not sell or share retained media with third parties beyond what is already disclosed in this Policy.
Retention for your own supplier assessment records. Separately from the setting above, if you tag a scan to a supplier profile, or select "Keep Media" on an individual scan, that scan's media is retained beyond the 24-hour window so it remains available as evidence within your own Supplier Assessments records. This retention exists solely for your own recordkeeping — it is not used to train or improve our detection models — and continues until you delete that scan, remove the retention yourself, or delete the supplier profile. You can release this hold ("Release Hold") or permanently delete the scan at any time from Scan History.
This architecture means that, unless you have opted in to extended retention or a scan is being kept for your own supplier assessment records as described above, even in the event of a security incident affecting RealShield AI's database, the raw media you submitted for scanning would not be exposed — because it is not stored there.
The deepfake detection analysis performed by the App may involve processing voice characteristics and facial geometry present in submitted media. Under the privacy laws of several U.S. states, this activity may constitute processing of "biometric data" or "biometric information." RealShield AI takes these obligations seriously.
We design our biometric data practices to comply with all applicable state biometric privacy statutes, including:
For merchants or individuals located in Illinois: RealShield AI will not collect biometric identifiers or biometric information from Illinois residents without first providing the written disclosure and obtaining the written release required under 740 ILCS 14. If you are an Illinois resident and wish to review our BIPA-compliant disclosure, please contact us at support@realshield.ai.
RealShield AI engages third-party service providers to deliver the App. Each provider is engaged under written agreement that restricts their use of merchant data to the purpose for which it was shared.
We utilize an industry-leading third-party AI detection service to perform forensic deepfake and AI-generated content analysis. We do not publicly identify this provider in order to protect the integrity of our detection methodology. Our AI detection partner is contractually prohibited from: retaining submitted media beyond the duration of the analysis; using submitted media to train, fine-tune, or improve their detection models; sharing submitted media with any third party; or using submitted media for any purpose other than returning analysis results to RealShield AI.
SHOPLINE facilitates App installation, merchant authentication, and subscription billing. Information shared between RealShield AI and SHOPLINE as part of the App Store distribution relationship is governed by SHOPLINE's own privacy policies and the SHOPLINE Partner Agreement.
RealShield AI operates on trusted cloud infrastructure for hosting the App server and storing scan results and merchant data. All infrastructure providers are engaged under data processing agreements. Merchant data is processed and stored in the United States.
RealShield AI is a merchant-facing tool. It operates entirely at the merchant account level. We do not have access to your store's customer-facing data — no customer names, email addresses, mailing addresses, phone numbers, order records, purchase history, or payment information.
The only store-level data we receive from SHOPLINE is your shop domain, provided automatically during the OAuth installation flow. We do not request, store, or process any data from your storefront, customer accounts, or order management system.
Our GDPR data deletion webhooks reflect this architecture: when SHOPLINE sends us a customers/redact request, there is no end-customer data for us to delete, because we never held any. We respond to confirm receipt and record the request.
| Data Type | Retention Period |
|---|---|
| Raw media files submitted for scanning | Purged within 24 hours by default; not written to persistent storage. If you opt in via Settings to extended retention for service improvement, retained for up to 3 years or until you disable the setting, whichever occurs first. If you tag a scan to a supplier or select "Keep Media" on it, that scan's media is instead retained for your own supplier assessment records until you delete the scan or remove the retention yourself |
| Scan results and metadata (risk scores, file type, timestamp) | Retained for the duration of your subscription, or until you delete them within the App |
| Supplier profiles and notes | Retained for the duration of your subscription, or until you delete them within the App |
| Return Verification photos | Purged within 24 hours by default, following the same retention rules as standard scan media (see Section 4) |
| Return Verification order numbers, reasons, and notes | Retained for the duration of your subscription, or until you delete them within the App |
| Merchant store domain and subscription status | Retained for the duration of your active subscription |
| App settings and notification preferences | Retained for the duration of your active subscription |
| All merchant data (all categories) | Permanently deleted within 48 hours of app uninstall |
| Anonymized, aggregated service metrics | May be retained for internal service quality purposes; cannot be attributed to any individual merchant or store |
Anonymized aggregate metrics contain no raw media, no biometric data, and no information that could identify an individual merchant or store. This data is never shared with our AI detection partner or any third party for training purposes.
When you uninstall the RealShield AI App from your SHOPLINE store, an automated deletion process is triggered:
merchants/redact webhook, issued automatically 48 hours after uninstall. This process is automated and requires no action on your part.Deletion is permanent and irreversible. If you reinstall the App after uninstalling, you will begin with no prior data. If you wish to preserve your scan history or supplier profiles before uninstalling, please export or record that information in advance. You may also request immediate manual deletion of all your data at any time, without uninstalling the App, by contacting support@realshield.ai.
In the event of a security incident affecting merchant personal information, RealShield AI will:
Notifications will be sent to the notification email address you have configured in App Settings, or to your SHOPLINE store contact email if no notification address is configured. For breaches affecting Illinois residents, we will comply with the Illinois Personal Information Protection Act (PIPA) notification requirements in addition to the above.
As a merchant using the App, you have the following rights with respect to your data. These rights apply regardless of your jurisdiction. Additional jurisdiction-specific rights are described in Sections 14 and 15.
We will respond to all rights requests within 30 days of receipt (one calendar month for GDPR-governed requests from EEA residents).
RealShield AI is based in the United States. Merchant data is processed and stored in the United States. If you are accessing the App from outside the United States, your information is transferred to, processed in, and stored in the United States, which may have different data protection laws than your country of residence.
Where required by applicable law — including the EU General Data Protection Regulation (GDPR) — we rely on Standard Contractual Clauses (SCCs) approved by the European Commission as the legal mechanism governing international transfers of personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to the United States. We do not rely solely on user consent as the transfer mechanism.
Merchants located in the EEA, the United Kingdom, or Switzerland have the right to access, correct, or delete their personal data, and the right to lodge a complaint with their local data protection supervisory authority. Contact support@realshield.ai to exercise any of these rights.
California residents have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), California Civil Code § 1798.100 et seq. These rights include:
To submit a CCPA/CPRA request, contact support@realshield.ai. We will respond within 45 days as required by law, with a possible single 45-day extension where reasonably necessary.
Merchants and individuals located in Virginia (VCDPA), Connecticut (CTDPA), Colorado (CPA), Utah (UCPA), Oregon (OCPA), Washington (MHMDA), Texas (TDPSA), and other states with comprehensive consumer privacy legislation may have additional privacy rights under those laws, including rights to access, correction, deletion, portability, and opt-out of certain processing activities. Contact support@realshield.ai and identify your state of residence to exercise any applicable state-specific right.
Effective June 1, 2026, in compliance with Colorado Senate Bill 24-205 (the Colorado Artificial Intelligence Act):
The RealShield AI App for SHOPLINE merchants does not use third-party advertising cookies or cross-site tracking technologies. Merchant session authentication is managed by SHOPLINE's platform OAuth infrastructure. We do not track merchants across third-party websites. We honor Global Privacy Control (GPC) signals in contexts where tracking would otherwise apply.
RealShield AI is a business-to-business (B2B) application designed for use by commercial merchants. It is not intended for use by individuals under the age of eighteen (18). We do not knowingly collect personal information from minors. If we learn that information has been submitted by a person under the age of 18, we will delete that information promptly. If you have reason to believe that a minor has submitted information through the App, please contact support@realshield.ai immediately.
We may update this Privacy and Data Protection Policy from time to time to reflect changes in our practices, applicable law, or the App's functionality. We will notify merchants of material changes by displaying a prominent notice within the App and updating the "Last Updated" date at the top of this document.
Continued use of the App following notification of a material change constitutes acceptance of the updated policy. We will not retroactively reduce your privacy protections for data we have already collected without your explicit consent.
For all privacy inquiries, data access requests, deletion requests, or to exercise any right described in this policy:
Email: support@realshield.ai
Website: realshieldai.com
RealShield AI, LLC — State of Incorporation: Delaware, United States
We will acknowledge all requests within 5 business days and provide a substantive response within 30 days of receipt. For CCPA/CPRA requests, we will respond within 45 days as required by California law. For GDPR requests from EEA residents, we will respond within one calendar month as required.
This Privacy and Data Protection Policy applies to the RealShield AI application distributed through the SHOPLINE App Store. For the privacy policy governing realshieldai.com and the RealShield AI consumer platform, see the separate privacy notice available at realshieldai.com/privacy.