Privacy policy
What data Shelfready processes when a merchant installs it on a Shopify store, why we need it, how long we keep it, and how it is deleted. In short: we work with your product catalog, not with your customers.
1. Who we are
Shelfready (“Shelfready”, “we”, “us”) is a Shopify app that checks a store’s product catalog for the problems that keep products out of Shopify Catalog and AI shopping channels, and helps the merchant fix them.
For data about the merchant’s store, account, settings and billing we act as controller. Product data we read and change on the merchant’s instructions is processed on their behalf.
2. Data we process
We collect only what the app needs to scan a catalog and repair it.
From your store, through Shopify’s APIs
- Product data — titles, descriptions, handles, status, prices, images, categories, options, tags, metafields and which sales channels each product is published to.
- Order totals per product — for the last 30 days: order date, whether it was cancelled or a test, and each line item’s quantity, amount and product. This is used only to show how much revenue a problem puts at risk. We do not read customer names, email addresses, phone numbers or addresses.
About your account
- Your store’s Shopify domain and the access token Shopify issues to the app.
- Your app settings, including the email address you give us for scan notifications.
- Your plan, trial and AI-credit balance. Payment is handled entirely by Shopify; we never see card details.
- If you choose to use your own OpenAI API key, that key (stored encrypted).
What the app creates
- Scan results: the problems found on each product.
- A record of every change the app makes, including the value it replaced, so the change can be undone.
- AI drafts you requested, and a log of credit use.
From shoppers
Nothing. Shelfready adds nothing to your storefront and does not collect data from your store’s visitors or customers.
3. How and why we use it
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Scan the catalog and show what to fix | Product data, order totals per product | Performance of our contract with you |
| Make the changes you ask for, and undo them | Product data, change records | Performance of contract |
| Write AI drafts when you ask for one | The product’s own text and attributes | Performance of contract |
| Email you when a scan finishes | Notification email address | Performance of contract; you can turn it off |
| Billing, plan limits, security and support | Account data, technical logs | Contract; legitimate interests; legal obligation |
We do not sell data, do not use it for advertising, and do not use your catalog to train AI models.
4. AI processing
AI is used only when you press a button that asks for it — to draft a title or description, suggest a category, or read an attribute value from your own text. We send the AI provider that product’s own text and attributes, and nothing about your customers.
AI never writes to your store by itself. Every draft is shown to you first and is saved only when you press Save. If you use your own OpenAI key, the request is made under your OpenAI account and its terms.
AI only drafts. Nothing reaches your store until you save it.
5. Service providers
We share data only with providers that run the service for us, under contract and only for that purpose:
- Shopify — the platform the app runs on, and billing.
- Hosting and database providers — to run the app and store its data.
- OpenAI or Google (Gemini) — to generate AI drafts you request.
- Resend — to deliver scan notification emails.
We may also disclose data where the law requires it.
6. International transfers
Some of these providers process data outside the European Economic Area. Where they do, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses or an adequacy decision. You can ask us for details.
7. Retention and deletion
We keep your store’s data while the app is installed, because scan history and change records are what let you see progress and undo a change.
- When you uninstall, the app’s access to your store is revoked and the access token we held is deleted immediately.
-
48 hours later, Shopify sends us a
shop/redactrequest. We then delete your store’s data — scans, change records, drafts, settings and stored keys — within 30 days, except anything we must keep by law (such as billing records).
8. Shopify data requests
We handle Shopify’s mandatory privacy webhooks:
-
customers/data_request— we store no personal data about your customers, so there is nothing to return. We confirm receipt. -
customers/redact— likewise, there is no customer data to delete. We confirm receipt. shop/redact— we delete the store’s data as described in section 7.
9. Your rights
Under the GDPR and similar laws you can ask to access, correct, delete, restrict or object to the processing of your personal data, and to receive it in a portable format. You can also complain to your local data protection authority.
Shoppers: Shelfready holds no data about you. For anything about your orders or account, contact the store you bought from.
10. Security
All traffic is encrypted in transit (HTTPS). Shopify access tokens and any API key you give us are encrypted at rest. Access to production systems is restricted, and every change the app makes to a store is recorded. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
11. Cookies and tracking
This website sets no cookies and runs no analytics or advertising trackers. Inside Shopify admin, the app uses only the session Shopify provides to sign you in.
12. Changes and contact
We will update this policy when the app or the law changes. The date at the top shows the current version; we will tell merchants about material changes in the app.
For questions or requests about your data, contact us through the support link in the Shelfready app or on our Shopify App Store listing.