SHOPIFY APP PRIVACY · EFFECTIVE 11 AUGUST 2026 · VERSION 1.0
Privacy Policy
How Autonomous Commerce Factory handles information for its Shopify apps, public website, support, and operational systems.
1. Scope and operator
This policy applies to Factory Traditional Automation, Factory Hybrid Automation, the related Autonomous Commerce Factory website, and support functions. Privacy contact: support@echeualdiu.resend.app.
2. Information processed
Shopify operational data. The apps may access or modify products, publications, content, files, metaobjects and definitions, online-store navigation, translations, markets, inventory, and locations as needed for merchant-enabled functionality.
Merchant-provided information. We may process business contact details, support requests, configuration instructions, and operational communications voluntarily provided by merchants or authorized representatives.
Technical/security metadata. We may process minimized timestamps, routes, status codes, pseudonymous audit identifiers, deployment data, and security events. Raw payloads are avoided when unnecessary.
Customer data. Current normal app functionality does not request Shopify Protected Customer Data. Shopify privacy-webhook bodies are authenticated and the public edge receiver is designed not to persist the raw body.
3. Purposes
Information is used only to provide, secure, maintain, troubleshoot, improve, and support the service; perform merchant-requested catalog, merchandising, publishing and automation functions; comply with legal/platform duties; and prevent fraud or abuse.
4. AI-assisted processing
AI systems may support catalog analysis, content, merchandising, opportunity analysis, and workflow orchestration. The current policy is not to intentionally provide Shopify Protected Customer Data to AI providers. Sensitive actions remain subject to deterministic policy controls and merchant/owner authorization rules.
5. Privacy requests
The apps implement Shopify's mandatory customers/data_request, customers/redact, and shop/redact topics. Requests are verified using Shopify HMAC authentication. Where no responsive customer data is held, the request can be acknowledged without creating a persistent copy of the raw request body.
6. Retention and deletion
Information is retained only as long as reasonably necessary for service delivery, security, support, auditability, or legal obligations. Raw compliance-webhook bodies are not intended to be retained by the public edge receiver. Merchant-linked data is deleted or de-identified when a valid redaction/deletion requirement applies, subject to lawful retention duties.
7. Service providers
Service providers may include Shopify, Cloudflare, Resend, infrastructure/hosting providers, and AI providers for permitted non-protected operational processing. Providers receive only information reasonably necessary for the function performed and are subject to applicable contractual and security controls.
8. International processing
Providers may process information in different countries. Where law requires safeguards for international transfers, appropriate contractual, organizational, or legal transfer mechanisms are used.
9. Sale, advertising, automated decisions
We do not sell Shopify Protected Customer Data or use it for cross-context behavioral advertising. The current apps are not designed to make legal or similarly significant decisions about individual customers using Shopify Protected Customer Data.
10. Security
Controls include least-privilege Shopify scopes, encrypted secrets, HMAC validation, restricted service exposure, encrypted backup handling where configured, audit metadata, and incident-response procedures. See the Security Statement.
11. Rights and contact
Depending on applicable law, individuals may have rights to access, correct, erase, restrict, port, or object to processing of personal data. Contact support@echeualdiu.resend.app. We may need to verify the request and coordinate with the relevant Shopify merchant.
12. Changes
We may update this policy when services, data practices, laws, or platform requirements change. Material changes will update the effective date or version.