Privacy Policy
This policy explains how Variant Guard processes information when a Shopify merchant installs or uses the app.
Information we process
Variant Guard receives the shop domain and Shopify shop identifier needed to associate requests with the correct store. With merchant authorization, it processes product and variant fields required for catalog checks, including Shopify resource identifiers, product title and handle, variant title, product status, vendor, SKU, barcode, price, inventory-item identifier, and Shopify update timestamp.
The app stores scan findings, issue fingerprints, fix previews, operation outcomes, subscription state, and limited review-prompt state needed to provide the service. Shopify access and refresh tokens are encrypted before database storage.
Operational logs contain limited technical data such as request path, response status, duration, correlation ID, safe error code, and exception type. They are designed not to contain access tokens, connection strings, request bodies, product titles, SKUs, or barcodes.
If a merchant contacts support, Commerce App Foundry processes the contact details and message content that the merchant chooses to provide.
Information we do not request
Variant Guard does not request access to customer or order data. It does not add storefront scripts, place cookies on shoppers' devices, collect shopper behavior, sell personal information, or use merchant catalog data for advertising.
How we use information
- Authenticate the Shopify installation and route requests to the correct shop.
- Scan the catalog, present issue evidence, and operate merchant-confirmed SKU fixes.
- Enforce plan entitlements and run scheduled scans where included.
- Secure, troubleshoot, and maintain the service.
- Respond to support and privacy requests and meet legal obligations.
Service providers and international processing
Shopify provides authentication, APIs, webhooks, and app billing. Railway hosts the application and PostgreSQL database. The current production deployment is served from Railway's US West region in California, United States. Information may therefore be processed outside a merchant's country. These providers process information under their own terms and data-protection commitments.
Retention and deletion
Active app data is retained while the app is installed and needed to provide the service. After uninstall, Variant Guard deletes stored Shopify tokens and stops pending work. When Shopify sends a verified shop/redact request, the app deletes the remaining tenant-linked live data. Backup copies, when present, expire within 30 days and are not selectively restored without reapplying completed redactions.
Operational logs are retained for no longer than 30 days. Support correspondence is retained for up to 24 months unless a longer period is required to resolve a request or comply with law. More detail is available in the Data Retention Policy.
Security
We use encrypted transport, encrypted Shopify tokens, tenant-scoped database relationships, authenticated webhooks, least-privilege access scopes, rate limiting, safe structured logging, and dependency maintenance. No security measure can guarantee absolute security.
Merchant choices and rights
Depending on location, merchants may have rights to access, correct, delete, restrict, port, or object to processing of personal information. To submit a request, email mvv890517@gmail.com. We may verify the requester's authority before acting.
Shopify sends mandatory privacy webhooks for customer data requests and redaction. Because Variant Guard does not request or store customer or order data, customer-specific requests ordinarily contain no customer record for us to return or erase.
Changes and contact
We may update this policy to reflect changes to the service, law, or operational practices. The effective date above will be updated when the policy changes.
Privacy questions and requests can be sent to Commerce App Foundry at mvv890517@gmail.com.