Privacy policy

Effective 15 September 2026

Channelmirror is operated by [Company legal name] ("we", "us"). This policy explains what the app reads from your Shopify store, what it keeps, where it goes and for how long. It is written for the merchant who installs the app. The short version: we store configuration state about products, markets and channels; we never access customers, orders or payments; and we delete everything when you uninstall.

1. Who we process data for

When you install Channelmirror we act as a processor of your store's product configuration data on your behalf, and as a controller of the small amount of account data we need to run the service and bill you (your store domain, the alert email address and your plan).

2. What we access in your store

DataWhy
Products and variants: title, handle, status, vendor, type, collections, whether a product has an image, whether it is hidden from search, prices, compare-at prices, unit costsTo compare configuration across markets and channels and to name the product in an issue
Publish state: which products are published to which sales channel and catalog, and channel feedback messages about a productTo detect products missing from a channel, catalog leaks, and channel-reported problems
Markets, catalogs and price lists: names, countries, currencies, percentage adjustments and fixed pricesTo compute the price configured for each market and channel
Store name, store email, base currency and timezoneTo prefill the alert email address and to run checks and send emails at the right local time

We never request or access customers, orders, checkouts, payments, inventory quantities, discounts, themes or content. The app's access scopes are limited to products, publications and markets, and you can see them on the app's page in your Shopify admin.

3. What we store

  • Configuration state, not product copies: for each product, variant and market or channel, the configured price, compare-at price, publish state and a hash of those values, so we can tell what changed.
  • Product metadata needed to write a sentence: title, handle, status, vendor, type, collection ids, unit cost and whether the product has an image.
  • Issues: the sentence, the expected and actual values, when the issue was first and last seen, and when it was resolved.
  • Account data: store domain, alert email, plan, timezone, settings you change, and scan history (counts and timestamps).
  • Shopify session tokens required to call the Shopify API on your behalf, stored encrypted at rest.

4. What we send

  • Email alerts and summaries to the alert address you set, sent through Resend. Each email contains issue sentences, product titles and market or channel names from your store.
  • Shopify Flow trigger events, if you use them, containing the product id, product title, market or channel name, issue kind, severity and sentence. These stay inside your Shopify account.

We do not sell data, share it with advertisers, or use it to train any model. Channelmirror has no AI features.

5. Sub-processors

ProviderPurposeLocation
[Fly.io]Application hosting and database[Region, e.g. Amsterdam (ams)]
[Upstash]Job queue (Redis)[Region]
ResendTransactional email deliveryUnited States / EU per Resend's settings
Shopify Inc.The platform the app runs inside; billingCanada / global

6. Retention and deletion

  • While the app is installed, we keep current state and open issues. Resolved issues are kept for the history period of your plan (30 days, 90 days or one year) and then deleted.
  • When you uninstall, checks stop immediately and the store is marked as uninstalled.
  • Shopify sends us a mandatory store redaction request 48 hours after uninstall. We delete all data for the store within 48 hours of receiving it, and in any case no later than 30 days after uninstall.
  • Customer data requests and customer redaction requests from Shopify are acknowledged as required. Because we hold no customer data, there is nothing to return or erase, and we reply saying so.
  • Backups are rotated within 30 days.

7. Security

Data is encrypted in transit (TLS) and at rest. Access tokens are stored server-side only and are never sent to the browser or to the admin block extension. Access to production systems is limited to named staff with two-factor authentication. We keep audit logs of fixes applied through the app.

8. Your rights

Depending on where you are, you may have rights under the GDPR, the UK GDPR, the CCPA/CPRA and similar laws to access, correct, export or delete the personal data we hold about you (in practice: your store email and alert address), to object to or restrict processing, and to complain to a supervisory authority. Write to us at the address below and we will respond within 30 days. Uninstalling the app deletes your data as described above without needing a request.

9. International transfers

Where data leaves the European Economic Area or the United Kingdom, we rely on the sub-processor's standard contractual clauses or an adequacy decision. Details are available on request.

10. Changes

We will announce material changes to this policy inside the app or by email at least 14 days before they take effect. The effective date at the top tells you when it last changed.

11. Contact

[Company legal name], [Registered address]. Privacy contact: support@channelmirror.com. See also our terms of service.