How We Protect Your Data

How Visibility Mesh protects your data — public surface only, encrypted, never sold

If a company is going to scan your store, you deserve a straight answer to one question: what exactly do you touch, and what do you do with it? Here it is, in plain English. We read only what is already public on your store, we store it encrypted with your name on the controls, and there are hard lines we do not cross. We do not sell your data, we do not share it for advertising, and we do not let it train AI models. No asterisks.

VMBy Visibility Meshthe measurement layer for AI visibility in ecommerce, operated by Amaretta LLC. Updated August 2026.
Key takeaways
  • We scan only your public surfacethe same pages any visitor or crawler already sees. We do not log into your store.
  • Your data is encrypted in transit and at rest, with row-level access controls and 2FA on our administrative systems.
  • We do not sell your data and do not share it for advertising. Our AI processor is contractually barred from training models on it.
  • You can request deletion at any time. Retention windows are written down in our Privacy Policy, not left vague.

The short version

Trust in this category should not require reading the fine print, so we will lead with the conclusion: we collect the minimum we need to do the job, we protect it properly, and we never monetise it behind your back. The rest of this page is just us showing our work. The binding details live in our Privacy Policy and Data Processing Agreementthis is the human-readable companion.

What we actually collect, and what we do not

To scan your store, we retrieve the publicly accessible pages you point us at, the same surface a shopper or a search crawler sees, and we generate scores and findings from them. We keep your account basics (name, email, plan) and a history of your scans, because progress tracking over time is a core feature, not a side effect. What we do not do: we do not need or take a login to your storefront, we do not collect what is not public, and payments run through Shopify, so we never store full card numbers.

Where your data lives

Your data is processed in the United States across a small set of named, vetted providers. Hosting, database, transactional email, and the AI analysis itself. We don't keep a secret roster: every sub-processor is listed in our DPA, and we give notice before that list changes. Fewer vendors, each one named, is a deliberate choice. You cannot audit a supply chain you cannot see.

How it is protected

The controls are the ordinary, boring, correct ones, and boring is the goal. Encryption in transit and at rest. Row-level security so one account's data is walled from another's. Least-privilege access, audit logging, and two-factor authentication on administrative systems, with a hardware key on the most sensitive accounts. No method is ever 100% secure, and we will not pretend otherwise; if a breach affecting your data ever occurred, we would notify you and regulators as the law requires.

The commitments, in numbers
0
Times we sell your data or share it for cross-context advertising. This is a line, not a setting.
TLS 1.2+
Encryption in transit, with encryption at rest and row-level access controls behind it.
24 mo
Free-tier scan-data retention from last activity; paid accounts plus 90 days after closure. Written down, not vague.

AI processing, stated plainly

Our scan analysis runs on a third-party large-language-model API. Currently Anthropic. That means page content from your scans is transmitted to that processor to generate the assessment. The part that matters: our processor is contractually barred from training its models on your data. We disclose this here on purpose, because “we use AI” should not be a black box you are asked to trust blindly.

VISIBILITY MESHWhat we touch, where it goes, what we never do.STEP 1 · WHAT WE READYour public surfaceThe same pages any visitoror crawler can already see.No login to your store.STEP 2 · WHERE IT LIVESEncrypted in transit & at rest. Row-level access.STEP 3 · YOUR CONTROLYou can delete itRequest deletion any time.Retention windows arewritten down, not vague.THE LINES WE DO NOT CROSSSell your dataShare it for ad targetingTrain AI models on itStore full card numbersLog into your storefrontTouch what is not public
Three steps and a hard floor: we read only your public surface, store it encrypted, hand you the controls, and never sell, share-for-ads, or train models on your data.

What we do, and what we never do

What we do What we never do
Scope Read your public pages Log into your store or take private data
Monetisation Charge a transparent price Sell or share your data for advertising
AI Use a named processor to analyse Let it train models on your data
Payments Let Shopify handle cards Store your full card numbers
Control Honour deletion requests Make you chase vague, unwritten policies

Why we wrote this down

We measure how legible your store is, and we publish our own results in the open, so it would be a strange kind of hypocrisy to be opaque about how we handle your data. Treating it well is not a feature we are selling; it is the baseline for being allowed to do this work at all. If anything here is unclear, the binding versions are one click away, and you can reach us directly.

Questions store owners actually ask

Do you sell my data?

No. We do not sell your personal information and do not share it for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA. This is a firm line, not a configurable setting.

Do you train AI on my data?

No. Our scan analysis uses a third-party AI processor (currently Anthropic), and that processor is contractually barred from training its models on your data. Page content is transmitted only to generate your assessment.

Do you log into my Shopify store?

No. Our scan reads only your publicly accessible pages, the same surface any visitor or crawler sees. We do not need, request, or take a login to your storefront to run a standard scan.

Can I delete my data?

Yes. You can request deletion at any time. We also apply written retention windows, free-tier scan data for 24 months from last activity, paid accounts for the life of the account plus 90 days after closure, detailed in our Privacy Policy.

Where is my data stored?

In the United States, across a small set of named, vetted sub-processors for hosting, database, email, and AI analysis. The full list is in our Data Processing Agreement, and we give notice before it changes.

Run a scan, see exactly what we read.

The free scan only ever touches your public pages, the same surface any crawler sees. Run it and watch precisely what we look at.

Run your free scan →

Sources

  • Visibility Mesh Privacy Policy and Data Processing Agreement (current versions on this site).
  • CCPA/CPRA definitions of “sale” and “sharing” for cross-context behavioral advertising.

Your buyers are already asking AI. This is how you make your website readable to the assistants they ask.

Everything in this article is measurable on a live storefront. The Full Assessment and Roadmap reads your website the way AI crawlers receive it and hands you every fix in plain English, in the order we would make them.

Full Assessment and Roadmap See all assessments

See whether this applies to your site

This article is about whether AI trusts you; the scan checks your entity data across your pages.

The free scan reads 5 pages of any website as AI crawlers receive them and returns a scorecard with 3 complete findings, each naming the page and the fix. No install, no call, no card.

Run the free scan