Privacy Policy
Last updated: 2026-09-13 · Questions: support@commercedash.io
What we collect
Public scans. When you scan a store, we fetch publicly accessible data — product feeds, sitemaps, and product pages — and store the resulting report. We log a hashed version of your IP address for rate limiting; we never store raw IPs.
Connected stores. If you connect a Shopify store, we store your shop domain and an encrypted (AES-256-GCM) OAuth access token, used solely to read catalog data and apply fixes you explicitly approve. We access only the scopes you grant.
Email addresses. If you request a report by email or enable monitoring, we store your email to send reports and monitoring alerts. That's it — no newsletters you didn't ask for.
Payments. Payments are processed by Stripe. We store the payment session ID and status — never card numbers.
What we don't do
We don't sell data. We don't run third-party trackers or ad pixels. We don't share store reports publicly — report links are unguessable but unlisted. Store names never appear in public stats; only aggregate counts and scores are shown.
Data retention & deletion
Uninstalling the app removes your access token via Shopify's mandatory uninstall webhook. To delete your data entirely — scans, fixes, leads — email us and we'll remove it. Scan reports may be retained in aggregate, anonymized form for benchmarks.
Your rights
GDPR/CCPA: you can request access, correction, or deletion of your personal data at any time via support@commercedash.io.