Data Retention Policy
| Data | Retention | Deletion event |
|---|---|---|
| Shop identity, catalog snapshots, issues, previews, and operations | While installed and needed to provide the service | Verified shop redaction or an approved deletion request |
| Encrypted Shopify access and refresh tokens | While installed | Deleted after uninstall; also covered by shop redaction |
| Subscription and review-prompt state | While installed | Verified shop redaction |
| Operational logs | No longer than 30 days | Automatic expiry |
| Support correspondence | Up to 24 months | Scheduled deletion unless legal retention applies |
| Encrypted database backups, when present | No longer than 30 days | Automatic backup expiry |
Uninstall and Shopify redaction
After uninstall, Variant Guard deletes stored Shopify tokens, cancels pending work, and stops schedules. When Shopify sends a verified shop/redact webhook, the app deletes the shop record and tenant-linked live data.
Backup deletion occurs through expiry rather than selective modification. A backup containing deleted tenant data must not be restored into production without reapplying completed redactions.
Customer privacy requests
Variant Guard does not request or store Shopify customer or order data. Verified customer data-request and redaction webhooks therefore do not start catalog processing.
Requests and legal holds
Merchants can request access or deletion by emailing mvv890517@gmail.com. We verify authority before acting. A narrowly limited record may be retained when required by law or necessary to establish, exercise, or defend legal claims, and is deleted when that obligation ends.