Data Retention Policy

Effective date: September 23, 2026
Contact: mvv890517@gmail.com

DataRetentionDeletion event
Shop identity, catalog snapshots, issues, previews, and operationsWhile installed and needed to provide the serviceVerified shop redaction or an approved deletion request
Encrypted Shopify access and refresh tokensWhile installedDeleted after uninstall; also covered by shop redaction
Subscription and review-prompt stateWhile installedVerified shop redaction
Operational logsNo longer than 30 daysAutomatic expiry
Support correspondenceUp to 24 monthsScheduled deletion unless legal retention applies
Encrypted database backups, when presentNo longer than 30 daysAutomatic backup expiry

Uninstall and Shopify redaction

After uninstall, Variant Guard deletes stored Shopify tokens, cancels pending work, and stops schedules. When Shopify sends a verified shop/redact webhook, the app deletes the shop record and tenant-linked live data.

Backup deletion occurs through expiry rather than selective modification. A backup containing deleted tenant data must not be restored into production without reapplying completed redactions.

Customer privacy requests

Variant Guard does not request or store Shopify customer or order data. Verified customer data-request and redaction webhooks therefore do not start catalog processing.

Requests and legal holds

Merchants can request access or deletion by emailing mvv890517@gmail.com. We verify authority before acting. A narrowly limited record may be retained when required by law or necessary to establish, exercise, or defend legal claims, and is deleted when that obligation ends.