Privacy Policy

Privacy Policy

Last updated: March 2026

1. Introduction

Welcome to Rain ("we," "us," or "our"). We are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at https://heyrain.xyz and use our AI-powered Shopify theme editing service.

By using our services, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

Information You Provide

  • Account Information: Name, email address, and password when you create an account.
  • Payment Information: Billing details processed securely through Stripe. We do not store your full credit card number.
  • Shopify Store Data: When you connect your Shopify store, we access your theme files (Liquid templates, CSS, JavaScript, JSON configuration) to provide our editing service. We do not access your customer data, orders, or financial information.
  • Chat Messages: The editing instructions you provide through our chat interface.
  • Newsletter Subscription: Name and email address when you subscribe to our newsletter.
  • Support Communications: Any information you provide when contacting our support team.

Information Collected Automatically

  • Usage Data: Pages visited, features used, and interactions with our service, collected via PostHog analytics.
  • Device Information: Browser type, operating system, device type, and screen resolution.
  • IP Address: Used for security purposes and approximate geographic location.
  • Cookies: See our Cookie Policy for details.

3. How We Use Your Information

We use your information to:

  • Provide, maintain, and improve our Shopify theme editing service
  • Process your theme editing requests using AI models
  • Process transactions and send related information
  • Send you newsletters, marketing communications, and promotional offers (with your consent)
  • Respond to your comments, questions, and support requests
  • Monitor and analyze usage trends to improve user experience
  • Detect, prevent, and address technical issues and fraud
  • Comply with legal obligations

4. AI Processing

When you submit a theme editing request:

  • Your instructions and relevant theme files are sent to third-party AI providers (OpenAI and Anthropic) for processing.
  • AI providers process this data to generate code changes for your theme.
  • We do not use your data to train AI models. Our AI providers process data under data processing agreements that prohibit training on customer data.

5. Legal Basis for Processing (GDPR)

If you are in the European Economic Area (EEA), we process your data based on:

  • Consent: When you subscribe to our newsletter or accept cookies.
  • Contract: When processing is necessary to provide our services, including connecting to your Shopify store and editing your theme.
  • Legitimate Interest: For analytics, security, and service improvement.
  • Legal Obligation: When required by law.

6. Data Sharing and Third Parties

We share your data with the following categories of service providers:

Service Purpose Data Shared
Shopify Store integration Theme files via Shopify API
OpenAI AI processing (file selection) Theme file names, your editing instructions
Anthropic AI processing (code generation) Theme file contents, your editing instructions
Stripe Payment processing Payment and billing information
Neon Database Account data
PostHog Product analytics Usage data, anonymized identifiers
Resend Transactional emails Email address, name
Vercel Hosting IP address, request data

We do not sell your personal data to third parties.

7. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. If you delete your account, we will delete your data within 30 days, except where retention is required by law.

Theme files are temporarily stored during editing sessions and deleted after changes are applied to your store.

8. Your Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of your personal data.
  • Rectification: Correct inaccurate or incomplete data.
  • Erasure: Request deletion of your data ("right to be forgotten").
  • Portability: Receive your data in a machine-readable format.
  • Objection: Object to processing based on legitimate interest.
  • Withdraw Consent: Withdraw consent at any time (e.g., unsubscribe from emails).

To exercise these rights, contact us at support@heyrain.xyz.

9. Data Security

We implement appropriate technical and organizational measures to protect your data, including encryption in transit (TLS/SSL), secure data storage, and access controls. Shopify store connections use OAuth 2.0 for secure authorization.

10. International Data Transfers

Your data may be transferred to and processed in countries outside your jurisdiction. We ensure appropriate safeguards are in place, including Standard Contractual Clauses where required.

11. Children's Privacy

Our services are not directed to individuals under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the updated policy on our website and updating the "Last updated" date.

13. Contact Us

If you have questions about this Privacy Policy, please contact us: