SHOPIFY APP PRIVACY · EFFECTIVE 11 AUGUST 2026 · VERSION 1.0
Merchant Data & Privacy Terms
Data-protection commitments for merchants using the Autonomous Commerce Factory Shopify applications.
1. Parties and scope
These Merchant Data & Privacy Terms apply between a merchant using Factory Traditional Automation or Factory Hybrid Automation ("Merchant") and Autonomous Commerce Factory ("Operator").
2. Instructions and purpose limitation
The Operator processes merchant data only for documented service purposes such as catalog/merchandising operations, content/publishing workflows, security, support, troubleshooting, and legal compliance. Protected customer data will not intentionally be used for unrelated advertising, profiling, or sale.
3. Current data categories
| Category | Treatment |
|---|---|
| Catalog/content/store operational data | May be accessed or modified when required for enabled app functions. |
| Merchant business/support information | Processed when voluntarily provided or required for support/administration. |
| Technical/security metadata | Minimized processing for security, reliability and auditability. |
| Shopify Protected Customer Data | Not requested for current normal app functionality. |
| Mandatory privacy-webhook bodies | Authenticated and processed for compliance; public edge receiver designed not to retain raw body. |
4. Privacy-law roles
Where personal data is processed solely on Merchant instructions, the parties intend the Operator to act as processor/service provider to the extent required by law. For the Operator's own business-contact, security, fraud-prevention, legal-compliance and relationship-management activities, the Operator may act as an independent controller/business as applicable.
5. Confidentiality and security
Access is limited to authorized persons and service identities with a need to know. Controls include minimized scopes, encrypted secrets, HMAC privacy-webhook verification, restricted network exposure, encrypted backup handling where configured, audit/security metadata, and incident-response procedures.
6. Subprocessors and AI
Subprocessors may include Shopify, Cloudflare, Resend, infrastructure/hosting providers, and AI providers for permitted non-protected operational processing. The current policy is not to intentionally transmit Shopify Protected Customer Data to AI providers.
7. Privacy requests
The Operator supports Shopify's mandatory data-request, customer-redaction, and shop-redaction topics and will reasonably assist Merchants with applicable privacy requests to the extent relevant information is held.
8. Retention, deletion, transfers
Information is retained only for a reasonably necessary period. On termination or valid deletion/redaction, applicable Merchant-linked personal data is deleted or de-identified unless lawful retention is required. International transfers use appropriate safeguards where required by law.
9. Incidents and evidence
The Operator maintains an incident-response process and may keep technical evidence of privacy controls, scope minimization, webhook configuration/delivery, backup protection, and access controls. Reasonable compliance information may be provided subject to confidentiality and security restrictions.
10. No sale; changes
The Operator does not sell Shopify Protected Customer Data. A separately signed data-processing agreement controls over conflicting provisions. Material updates will change the effective date or version.