Shopify Privacy Policy
Overview
This Shopify Privacy Policy explains how the Suggesto Product Advisor app (the “App”) handles personal data when a Shopify merchant installs it on their store. It supplements our general Privacy Policy with the specifics required by the Shopify Partner Program and the applicable privacy laws that govern Shopify apps (GDPR, UK GDPR, CCPA/CPRA and India's Digital Personal Data Protection Act, 2023).
The App is built by Suggesto (operated by Adhish.in). It lets merchants build on-brand Product Advisors — short quizzes that recommend the right product to a shopper — and embed them on their Shopify storefront. In the language of privacy law, the merchant is the data controller of shopper data captured through the App, and Suggesto acts as the data processor.
Data the App accesses from Shopify
Shop metadata. When a merchant installs the App, Shopify issues us an OAuth access token bound to the shop's myshopify.com domain. We store the shop domain, the granted access scopes, the app installation timestamp and, if the merchant subscribes to a paid plan, the recurring application charge id.
Merchant profile. The Shopify user email associated with the App install, used to link the Shopify store to a Suggesto account and to send transactional email about the install (welcome, billing, support responses).
Products catalogue. Read-only access to product titles, descriptions, images, options, variants, tags and inventory metadata. This is what the App recommends to shoppers. We never write back to the product catalogue.
Product Advisor content. Questions, options, weights, filter rules, themes, background images and copy the merchant authors inside the App's admin. This lives in Suggesto's database, not Shopify's.
Shopper interactions. When a shopper completes a Product Advisor on the merchant's storefront, we record the answers selected, the products recommended, the timing of the session and which recommendations the shopper clicked. Individual sessions are not linked to a Shopify customer id unless the merchant has explicitly enabled lead capture and the shopper has submitted the form.
Lead data. Email address (and any optional custom fields the merchant added to the lead-capture form) collected only after the shopper has affirmatively submitted the form. The consent text presented at capture time is stored alongside the lead.
The App does not read Shopify customer accounts, order line items or fulfilment records. We only request the Shopify scopes we actually need — currently read_products — and Shopify surfaces the exact scope list to the merchant during install.
How the App uses the data
To operate the App: authenticate the merchant, render Product Advisors on the storefront, compute product recommendations against the merchant's catalogue, deliver leads back to the admin dashboard and process billing through Shopify's Application Charge API.
To support merchants: respond to help requests, prevent abuse of the App and diagnose issues.
To improve the product: identify which features get used, debug errors and measure App performance in aggregate.
To meet legal obligations: respond to lawful requests, honour Shopify's mandatory GDPR webhooks and enforce our Terms of Service.
Shopify GDPR mandatory webhooks
The App implements the three mandatory GDPR webhooks that Shopify calls when a merchant or shopper exercises their privacy rights:
customers/data_request. When a shopper on a merchant's store submits a data-request through Shopify, we return any lead, response or shopper-interaction record the App holds that is linked to the shopper's email address. The response is delivered to the merchant so they can forward it to the shopper.
customers/redact. When Shopify instructs us to delete a shopper's data, we permanently remove any lead, response and shopper-interaction record linked to that shopper's email from the App's primary database within 30 days. Encrypted backups roll off within the standard backup retention window described below.
shop/redact. Fired by Shopify 48 hours after a merchant uninstalls the App. We delete the shop's access token, Product Advisor content, leads and shopper responses from the App's primary database within 30 days of receiving this webhook.
All three webhook payloads are verified against Shopify's HMAC signature before we act on them. We log receipts (webhook id, topic, timestamp, shop domain) for audit purposes only.
Storefront tracking and cookies
The App runs a small script on the merchant storefront only on pages where the merchant has embedded a Product Advisor. That script does not set any cross-site tracking or advertising cookies. It uses one first-party session identifier, scoped to the merchant's domain, to prevent the same shopper being counted twice in the analytics funnel within a single browsing session.
If the merchant has configured a GA4 Measurement ID on their Product Advisor, completion events are forwarded server-side via the Measurement Protocol. No client-side GA4 tag is injected by the App itself.
Data retention
Merchant account and Product Advisor content. Retained for the life of the App install. When the merchant uninstalls (Shopify fires app/uninstalled), the access token is revoked immediately. 48 hours later, Shopify fires shop/redact; we then delete the shop's Product Advisor content, leads and shopper responses from the primary database within 30 days.
Shopper responses and leads. Retained for the life of the parent Product Advisor. Merchants can delete individual leads from the App's admin at any time.
Encrypted backups. Roll off within 30 days after their creation, at which point deleted records are permanently unrecoverable.
Server and webhook logs. Retained for a limited period for security and debugging, then truncated to anonymous aggregates.
Billing and compliance records that we are legally required to keep (invoices, tax records) are retained for the period required by applicable law.
Security
The App runs on managed cloud infrastructure with TLS 1.2+ in transit, encryption at rest, principle-of-least-privilege access and regular dependency scans. Shopify access tokens are stored encrypted. Passwords for the App's standalone admin sign-in (when not signed in via Shopify) are stored as bcrypt hashes and are never visible to staff.
Webhook endpoints validate Shopify's HMAC signature before processing. Admin surfaces require an authenticated Shopify session or a signed-in Suggesto account.
No system is perfectly secure. If we become aware of a data breach that affects merchant or shopper data, we will notify the affected merchant within 72 hours of confirmation, along with the information required by Article 33 of the GDPR where applicable.
International transfers
Personal data may be processed in India and in the cloud regions of our infrastructure providers (which may include the United States and the European Union). Where we transfer personal data out of the EEA / UK, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision, as appropriate. Shopify's own data-transfer arrangements govern the shop, product and webhook data Shopify routes to us.
Merchant and shopper rights
Merchants can access, correct, export or delete their App data at any time from the App's admin, or by uninstalling the App (which triggers Shopify's shop/redact flow described above).
Shoppers should exercise their privacy rights against the merchant whose Product Advisor they used, since the merchant is the data controller. Merchants can forward requests to us at support@suggesto.me and we will action them within 30 days.
You also have the right to lodge a complaint with your local data-protection authority. We would appreciate the chance to address your concern first.
Changes to this policy
We may update this Shopify Privacy Policy from time to time. If a change is material, we will notify merchants by email or with a notice in the App admin at least fourteen days before it takes effect. The “Last updated” date above always reflects the current version.
Contact
Privacy questions, account-deletion requests or any other data-related concerns can be sent to support@suggesto.me. We aim to respond within one business day.