SHOPIFY APP PRIVACY · EFFECTIVE 11 AUGUST 2026 · VERSION 1.0

Merchant Data & Privacy Terms

Data-protection commitments for merchants using the Autonomous Commerce Factory Shopify applications.

Current baseline. The Shopify apps are configured without a request for Shopify Protected Customer Data. Any future feature that needs protected customer data must not be enabled until access, disclosures, security controls, agreements, and Shopify review requirements are updated.

1. Parties and scope

These Merchant Data & Privacy Terms apply between a merchant using Factory Traditional Automation or Factory Hybrid Automation ("Merchant") and Autonomous Commerce Factory ("Operator").

2. Instructions and purpose limitation

The Operator processes merchant data only for documented service purposes such as catalog/merchandising operations, content/publishing workflows, security, support, troubleshooting, and legal compliance. Protected customer data will not intentionally be used for unrelated advertising, profiling, or sale.

3. Current data categories

CategoryTreatment
Catalog/content/store operational dataMay be accessed or modified when required for enabled app functions.
Merchant business/support informationProcessed when voluntarily provided or required for support/administration.
Technical/security metadataMinimized processing for security, reliability and auditability.
Shopify Protected Customer DataNot requested for current normal app functionality.
Mandatory privacy-webhook bodiesAuthenticated and processed for compliance; public edge receiver designed not to retain raw body.

4. Privacy-law roles

Where personal data is processed solely on Merchant instructions, the parties intend the Operator to act as processor/service provider to the extent required by law. For the Operator's own business-contact, security, fraud-prevention, legal-compliance and relationship-management activities, the Operator may act as an independent controller/business as applicable.

5. Confidentiality and security

Access is limited to authorized persons and service identities with a need to know. Controls include minimized scopes, encrypted secrets, HMAC privacy-webhook verification, restricted network exposure, encrypted backup handling where configured, audit/security metadata, and incident-response procedures.

6. Subprocessors and AI

Subprocessors may include Shopify, Cloudflare, Resend, infrastructure/hosting providers, and AI providers for permitted non-protected operational processing. The current policy is not to intentionally transmit Shopify Protected Customer Data to AI providers.

7. Privacy requests

The Operator supports Shopify's mandatory data-request, customer-redaction, and shop-redaction topics and will reasonably assist Merchants with applicable privacy requests to the extent relevant information is held.

8. Retention, deletion, transfers

Information is retained only for a reasonably necessary period. On termination or valid deletion/redaction, applicable Merchant-linked personal data is deleted or de-identified unless lawful retention is required. International transfers use appropriate safeguards where required by law.

9. Incidents and evidence

The Operator maintains an incident-response process and may keep technical evidence of privacy controls, scope minimization, webhook configuration/delivery, backup protection, and access controls. Reasonable compliance information may be provided subject to confidentiality and security restrictions.

10. No sale; changes

The Operator does not sell Shopify Protected Customer Data. A separately signed data-processing agreement controls over conflicting provisions. Material updates will change the effective date or version.