Privacy Policy
The Non-Negotiable Privacy Boundary: ShopGuard QA is built with privacy-by-design. We NEVER collect, read, store, or sell consumer personal data (PII). We do not access customer names, emails, shipping addresses, credit cards, or order histories.
1. Overview & Privacy Commitment
Prothom International (“we,” “us,” or “our”) develops ShopGuard QA (“App”). We are committed to protecting the privacy and security of merchants who install our App and the consumers who visit their stores.
This Privacy Policy explains what information we collect, why we collect it, how it is handled, and your rights under global privacy regulations including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We DO NOT Collect (Zero-PII Invariant)
Unlike marketing or analytics apps, ShopGuard QA is strictly a catalog diagnostic and store health tool. In accordance with our core engineering directives:
- No Shopper Data: We never request, read, or store customer names, phone numbers, email addresses, physical addresses, IP addresses, or payment card information.
- No Order Data: We do not request order scopes (
read_orders,write_orders) and have zero visibility into your transactions. - No Storefront Tracking: We do not inject cookies, pixels, or trackers into your theme to monitor shopper browsing behavior.
3. Information We Access & Collect (Least-Privilege Scopes)
To perform store health and catalog diagnostics, the App requests only strict least-privilege read permissions from Shopify (Strict Least-Privilege Standard):
- read_products: Used exclusively to audit product titles, handles, variant image assignments, and out-of-stock ghost variants.
- read_content: Used exclusively to parse product descriptions to detect broken outbound hyperlinks (404 errors).
- read_themes: Used exclusively to verify storefront layout paths without altering theme code.
Merchant Operational Data: We store your Shopify store domain (e.g., your-store.myshopify.com), your chosen audit settings (e.g., notification preferences), and diagnostic audit logs (counts of broken links and missing photos) in our encrypted database so you can view past audit history in your admin dashboard.
4. Mandatory Shopify Privacy Webhooks
ShopGuard QA implements and responds with immediate HTTP 200 confirmations on all mandatory Shopify privacy compliance webhooks:
- CUSTOMERS_DATA_REQUEST: Because we store zero customer personal data, requests return immediate verification that no customer records exist.
- CUSTOMERS_REDACT: Returns immediate confirmation of zero customer data to redact.
- SHOP_REDACT: When a merchant uninstalls the App, our automated purge handler cryptographically and permanently deletes all store settings, session tokens, and audit run records within 48 hours (Automated Purge Protocol).
5. Sub-Processors & Data Infrastructure
We partner with trusted, enterprise-grade cloud providers to operate the Service. All sub-processors adhere to strict security and confidentiality standards:
- Fly.io Inc.: Cloud infrastructure, container execution, and encrypted volume storage (hosted in Toronto, Canada datacenter - YYZ).
- Functional Software, Inc. (Sentry): Error logging and operational telemetry. Configured with automated PII scrubbers that recursively mask authorization tokens, emails, and credentials before transmission.
- Shopify Inc.: Authentication, session management (App Bridge v4), and recurring billing processing.
6. Security Safeguards
We maintain institutional-grade security controls (verified by our 100-point security rubric):
- In-Transit Encryption: All communications between Shopify, merchant browsers, and our servers are encrypted using TLS 1.3.
- SSRF Firewall: Outbound link health crawlers are shielded by strict SSRF perimeter validation that rejects private subnets, loopbacks, and cloud metadata IPs.
- Automated Secret Scanning: Continuous CI/CD automated gates prevent credentials or keys from entering production environments.
7. Your Rights (GDPR & CCPA)
Under applicable data protection laws, merchants have the right to:
- Access the diagnostic data we maintain for your store.
- Request correction or updates to your store configuration.
- Request permanent deletion of all store records at any time.
To exercise any of these rights, simply uninstall the App (which triggers an automatic purge) or contact us directly at support@prothom.dev.
8. Contact Information
For questions regarding this Privacy Policy or our data protection practices:
- Data Controller: Prothom International
- Data Protection Officer & Support: support@prothom.dev
- Security & Vulnerability Disclosures: security@prothom.dev
- Official Domain: prothom.dev