Privacy Policy

Last updated: 2026-09-13 · Questions: support@commercedash.io

What we collect

Public scans. When you scan a store, we fetch publicly accessible data — product feeds, sitemaps, and product pages — and store the resulting report. We log a hashed version of your IP address for rate limiting; we never store raw IPs.

Connected stores. If you connect a Shopify store, we store your shop domain and an encrypted (AES-256-GCM) OAuth access token, used solely to read catalog data and apply fixes you explicitly approve. We access only the scopes you grant.

Email addresses. If you request a report by email or enable monitoring, we store your email to send reports and monitoring alerts. That's it — no newsletters you didn't ask for.

Payments. Payments are processed by Stripe. We store the payment session ID and status — never card numbers.

What we don't do

We don't sell data. We don't run third-party trackers or ad pixels. We don't share store reports publicly — report links are unguessable but unlisted. Store names never appear in public stats; only aggregate counts and scores are shown.

Data retention & deletion

Uninstalling the app removes your access token via Shopify's mandatory uninstall webhook. To delete your data entirely — scans, fixes, leads — email us and we'll remove it. Scan reports may be retained in aggregate, anonymized form for benchmarks.

Your rights

GDPR/CCPA: you can request access, correction, or deletion of your personal data at any time via support@commercedash.io.

Terms of Service · Contact · Home