Privacy Policy
Store Audit — Last updated August 2026
Who we are
Store Audit is a Shopify app that audits your store's products and collections for AI-search readiness, schema correctness, meta tags, and image alt text. It is operated as a sole proprietorship based in California, USA. Questions about this policy can be sent to mattmcallistermarketing@gmail.com.
What data the app accesses
When you install Store Audit, you grant the following Shopify API access scopes:
- read_products — reads your product titles, descriptions, images, meta tags, and JSON-LD structured data so the app can score and audit them.
- write_products — applies one-click fixes (meta title rewrites, alt-text additions, metafield updates) back to your store on your explicit request.
- read_content — reads collection titles, descriptions, and SEO fields for collection-level audits.
All API calls go through Shopify's Admin GraphQL API. Store Audit does not scrape your storefront, does not access customer orders, customer personal data, financial data, or any other Shopify resource outside the scopes listed above.
What data the app stores
Store Audit stores the following data in its own database:
- Scan results and scores — the audit output for each scan you run: overall score, per-category scores, and the issue list. Stored and scoped to your shop domain (*.myshopify.com).
- Fix history — a record of each one-click fix you applied (issue type, timestamp, shop domain), used to enforce the free-plan fix limit and to track your store's improvement over time.
- Shopify session tokens — the OAuth session data Shopify issues when you install the app, used solely to authenticate subsequent API calls on your behalf. No session data is shared with third parties.
- Shop owner email — the account-owner email address associated with your Shopify store, used exclusively to deliver the Pro plan's weekly re-scan digest email. It is never used for marketing without your consent and is never sold or shared.
All stored data is scoped to your shop domain. No data from one merchant's store is visible to or accessible by any other merchant.
What the app does NOT do
- Does not sell, rent, or share your store data or personal information with any third party for their own purposes.
- Does not collect customer personal data (names, emails, addresses, payment information) from your shoppers.
- Does not use your product or collection data to train machine learning models.
- Does not send marketing email to your shop owner email without explicit opt-in.
Third-party services
Store Audit uses the following third-party services to operate:
- Shopify — the platform API. Your data is accessed through Shopify's infrastructure and subject to Shopify's Privacy Policy.
- Vercel — hosts the app's server infrastructure. Data in transit is encrypted via TLS.
- Resend — used to send the Pro plan's weekly re-scan digest emails. Only the recipient email address and digest content (your store's score and issue summary) are transmitted.
Data retention
Scan results and fix history are retained for as long as your store has the app installed, and for up to 90 days after uninstallation, to allow you to reinstall and recover your history. After 90 days, retained data is deleted on a rolling basis.
Session tokens are deleted immediately upon app uninstallation via the app/uninstalled webhook.
GDPR compliance webhooks
Store Audit implements all three mandatory Shopify GDPR compliance webhooks:
- customers/data_request — when Shopify sends a customer data request on behalf of a merchant, we return a summary of any data we hold that is associated with that customer. Because Store Audit does not collect customer personal data, the typical response confirms no customer-level data is held.
- customers/redact — when Shopify requests erasure of a customer's data, we delete any records associated with that customer identifier from our database.
- shop/redact — when a merchant uninstalls the app and Shopify triggers the shop redact webhook (48 hours after uninstallation), we permanently delete all scan results, fix history, and session data associated with that shop domain.
Your rights
You may request a copy of the data Store Audit holds for your shop, or request its deletion at any time, by emailing mattmcallistermarketing@gmail.com. We will respond within 30 days. Uninstalling the app from your Shopify admin immediately revokes our access to your store, and triggers the data-deletion process described above.
Changes to this policy
If we make material changes to this policy, we will update the “Last updated” date at the top of this page. Continued use of Store Audit after changes are posted constitutes acceptance of the revised policy.
Contact
Questions, data requests, or deletion requests: mattmcallistermarketing@gmail.com