SHOPIFY APP PRIVACY · EFFECTIVE 11 AUGUST 2026 · VERSION 1.0

Privacy Policy

How Autonomous Commerce Factory handles information for its Shopify apps, public website, support, and operational systems.

Data-minimization baseline. The current Shopify applications are designed to operate without requesting Shopify Protected Customer Data. Mandatory privacy-compliance webhooks are implemented even though normal app functionality does not depend on protected customer data.

1. Scope and operator

This policy applies to Factory Traditional Automation, Factory Hybrid Automation, the related Autonomous Commerce Factory website, and support functions. Privacy contact: support@echeualdiu.resend.app.

2. Information processed

Shopify operational data. The apps may access or modify products, publications, content, files, metaobjects and definitions, online-store navigation, translations, markets, inventory, and locations as needed for merchant-enabled functionality.

Merchant-provided information. We may process business contact details, support requests, configuration instructions, and operational communications voluntarily provided by merchants or authorized representatives.

Technical/security metadata. We may process minimized timestamps, routes, status codes, pseudonymous audit identifiers, deployment data, and security events. Raw payloads are avoided when unnecessary.

Customer data. Current normal app functionality does not request Shopify Protected Customer Data. Shopify privacy-webhook bodies are authenticated and the public edge receiver is designed not to persist the raw body.

3. Purposes

Information is used only to provide, secure, maintain, troubleshoot, improve, and support the service; perform merchant-requested catalog, merchandising, publishing and automation functions; comply with legal/platform duties; and prevent fraud or abuse.

4. AI-assisted processing

AI systems may support catalog analysis, content, merchandising, opportunity analysis, and workflow orchestration. The current policy is not to intentionally provide Shopify Protected Customer Data to AI providers. Sensitive actions remain subject to deterministic policy controls and merchant/owner authorization rules.

5. Privacy requests

The apps implement Shopify's mandatory customers/data_request, customers/redact, and shop/redact topics. Requests are verified using Shopify HMAC authentication. Where no responsive customer data is held, the request can be acknowledged without creating a persistent copy of the raw request body.

6. Retention and deletion

Information is retained only as long as reasonably necessary for service delivery, security, support, auditability, or legal obligations. Raw compliance-webhook bodies are not intended to be retained by the public edge receiver. Merchant-linked data is deleted or de-identified when a valid redaction/deletion requirement applies, subject to lawful retention duties.

7. Service providers

Service providers may include Shopify, Cloudflare, Resend, infrastructure/hosting providers, and AI providers for permitted non-protected operational processing. Providers receive only information reasonably necessary for the function performed and are subject to applicable contractual and security controls.

8. International processing

Providers may process information in different countries. Where law requires safeguards for international transfers, appropriate contractual, organizational, or legal transfer mechanisms are used.

9. Sale, advertising, automated decisions

We do not sell Shopify Protected Customer Data or use it for cross-context behavioral advertising. The current apps are not designed to make legal or similarly significant decisions about individual customers using Shopify Protected Customer Data.

10. Security

Controls include least-privilege Shopify scopes, encrypted secrets, HMAC validation, restricted service exposure, encrypted backup handling where configured, audit metadata, and incident-response procedures. See the Security Statement.

11. Rights and contact

Depending on applicable law, individuals may have rights to access, correct, erase, restrict, port, or object to processing of personal data. Contact support@echeualdiu.resend.app. We may need to verify the request and coordinate with the relevant Shopify merchant.

12. Changes

We may update this policy when services, data practices, laws, or platform requirements change. Material changes will update the effective date or version.