Skip to content

Privacy Policy

This Privacy Policy explains how data is handled when merchants install and use the app, and when visitors view pages published with it.

By installing or using the app, you acknowledge this Privacy Policy.

This policy covers data processed through app features, including:

  • page, template, and style content created in the app,
  • store data read from Shopify to power page components,
  • storefront view measurement for pages published with the app,
  • app authentication, configuration, and support communications.

This policy does not replace Shopify platform policies, your own store privacy policy, or the policies of any third-party service you choose to connect.

  • Merchant (store owner): controller for the store data and published content handled in the store context.
  • App provider: processor / service provider operating the page building and rendering service on behalf of the merchant.
  • Staff users: authorized users acting under the merchant’s Shopify account.

The app does not collect, request, or store personal data about your shoppers.

The app has no access to order data, customer records, or payment data, and does not request those permissions from Shopify.

Storefront measurement records that a published page was viewed, using a randomly generated identifier that exists only for the duration of that browsing session. It is not a cookie, is not linked to a person, is not shared for advertising, and cannot be used to identify or re-identify a visitor.

The app may process the following categories of data:

  • Merchant content: page documents, sections, component settings, saved templates, saved sections, design system style profiles, and page version history.
  • Store data read from Shopify: product, collection, blog, page, theme, and uploaded file information used to render and configure components, under the permissions you grant at installation.
  • Installation and account data: your store domain, installation and session records, subscription status, and app configuration.
  • Measurement data: page view records for published pages, consisting of the page reference, the store, a session-scoped random identifier, the page path, and a timestamp.
  • Integration data: access records for any AI assistant connections you create, including when they were created and last used.
  • Technical and service data: authentication data, diagnostics, and operational logs needed for service reliability and security.
  • Support communications: what you send us when you ask for help.

Data is processed to:

  • build, store, and version your pages, templates, and styles,
  • render published page content on your storefront,
  • read the store data your chosen components display,
  • authenticate the app and any connections you authorize,
  • report page views, sessions, and editing activity back to you,
  • create, restore, and import backups at your instruction,
  • maintain security, prevent abuse, and keep the service reliable,
  • troubleshoot issues and provide support,
  • and comply with legal obligations and platform requirements.

Data is not sold, and is not used for advertising or cross-store profiling.

Depending on jurisdiction and use case, processing may rely on:

  • contractual necessity,
  • legitimate interests,
  • legal obligations,
  • and, where required, valid consent.

Merchants are responsible for determining and documenting the lawful basis applicable to their store operations.

Data may be shared with service providers only where needed to operate the app, including:

  • Shopify platform APIs and infrastructure,
  • hosting, database, and content delivery providers,
  • operational service providers needed for reliability and security.

If you connect a third-party AI assistant, app content you make available through that connection is processed by that provider under its own terms and privacy practices. That connection is optional, is created by you, and can be revoked by you at any time.

Data may also be disclosed when required by law, legal process, or to protect rights, safety, and service integrity.

Data is retained only as long as reasonably required to operate the app, maintain security, resolve disputes, and comply with legal obligations.

Specific retention behavior:

  • Page view records are retained for 90 days and then deleted.
  • Page version history keeps a limited number of recent versions per page; older versions are superseded.
  • Backups are retained as a limited number of most recent snapshots per store; creating a new backup removes the oldest. Backups you download are stored by you, outside the app.
  • Temporary records created during uploads, authentication, and webhook handling are deleted automatically once they are no longer needed.

On uninstall, app access to your store ends and stored session credentials for that store are removed.

The app supports Shopify’s mandatory privacy webhooks:

  • Customer data request — no shopper personal data is stored by the app, so there is nothing to compile or return.
  • Customer redaction — no shopper personal data is stored by the app, so there is nothing to erase.
  • Shop redaction — on receipt, all data held for that store is erased, including pages, version history, templates, style profiles, backups, view records, assistant connections, insights, and session records.

Because erasure is final, export and download anything you want to keep before uninstalling.

Security measures are designed to reduce risk and protect data, including:

  • authenticated, store-scoped access, so one store’s content is not reachable from another,
  • encryption of stored access credentials,
  • least-privilege platform permissions — the app requests only what a page builder needs and does not request order, customer, or payment access,
  • revocable, individually managed access records for any assistant connection you create,
  • transport encryption for data in transit,
  • and automatic deletion of temporary and expired records.

No system can guarantee absolute security. Merchants should maintain their own access, policy, and operational controls, including who has admin access to the store.

Depending on applicable law, individuals may have rights such as access, correction, deletion, restriction, objection, and portability.

Requests should include sufficient identifying information to verify identity and locate relevant records. Where applicable, privacy requests can be handled through Shopify privacy and compliance mechanisms, or through the contact channel below.

Merchants are responsible for:

  • publishing a compliant store-facing privacy notice,
  • ensuring content published through the app complies with applicable law,
  • controlling which staff and which third-party assistants have access,
  • and handling privacy rights requests relating to their store in accordance with applicable law.

Data may be processed and stored by infrastructure providers in locations outside your country. Where required by law, appropriate safeguards are applied to such transfers.

The app is intended for business use by merchants and is not intended for direct use by children.

This Privacy Policy may be updated from time to time. Updated versions are effective when posted unless a different date is stated.

For privacy questions or requests related to the app, contact: rockstarui.com/contact