Reference
Data and permissions
What HI Engine reads, what it can write, where credentials are stored, and how to revoke access.
What HI Engine reads
| Source | Read access |
|---|---|
| Shopify | Products, variants, collections, orders, inventory, locations, themes, translations |
| Google Analytics 4 | Sessions, users, page paths, funnel events, conversions, revenue |
| Click Context | Anonymous behavioural events on your storefront |
| Klaviyo | Campaigns, flows, metrics, list and segment sizes |
What HI Engine can write
Exactly two things, and only after you approve them:
- A draft theme in Shopify. A copy of your live theme with the approved change applied. Customers never see a draft theme.
- Translations for a change you approved, when your store is multi-language.
That is the whole write surface.
What HI Engine never does
- It never publishes a theme to your storefront.
- It never reads or stores payment details.
- It never charges, refunds, cancels or edits an order.
- It never deletes a product, a collection or a theme.
- It never writes to your GA4 property.
- It never sends an email or a campaign from Klaviyo.
- It never sells or shares your data with a third party.
Where credentials live
Access tokens and OAuth refresh tokens are encrypted at rest in a dedicated secrets store. They are never sent to a browser and never appear in a log.
Each store's data is isolated at the database level. A user can only read the stores they belong to.
Personal data
HI Engine analyses aggregate behaviour: how many sessions did what, on which device, from which channel. Its findings are about pages and segments, not about individuals.
Order data is read for volume and value. Customer records are not part of any analysis or any output.
Revoking access
| Source | How |
|---|---|
| Shopify | Shopify admin → Settings → Apps and sales channels → Develop apps → uninstall the HI Engine app |
| Shopify collaborator | Shopify admin → Settings → Users → Collaborators → remove |
| GA4, viewer access | Analytics → Admin → Property access management → remove brancoyoy@gmail.com |
| GA4, OAuth | Google third-party access → remove HI Engine |
| Klaviyo | Klaviyo → Settings → Account → API keys → delete the key |
| Slack | Remove the bot from the channel, or ask HI Engine to unbind it |
Revoking a source stops HI Engine reading it immediately. Work already published to your theme is yours and stays where it is.
Data retention
Insights, ideas and change logs stay for the life of your account, so you keep the record of what was tried and what it did.
Ask your HI Engine contact for export or deletion at any time.