Privacy Policy (Shopify Apps)
Last Updated: July 2026
This Privacy Policy applies specifically to Shopify Apps developed by Elie Labs (including “Auto Sync & Agent” and future releases).
1. Our “Stateless Passthrough” Philosophy
Section titled “1. Our “Stateless Passthrough” Philosophy”We do not sell your merchant data. We do not build databases of your store’s information.
Our Shopify Apps are engineered with a strict Stateless Passthrough architecture. When our servers act as a bridge (e.g., routing Shopify webhooks to your designated workspace), the e-commerce data is processed in-memory to trigger your configured automations and is immediately discarded after successful transmission.
2. What Data We Collect & How We Handle It
Section titled “2. What Data We Collect & How We Handle It”- Store Data (Orders, Customers, Inventory): We DO NOT store your e-commerce data on our servers. Data such as orders or inventory levels is strictly routed from Shopify webhooks directly to your connected third-party tools. Temporary server logs used for debugging are automatically expunged and do not contain Personally Identifiable Information (PII).
- App Configurations & Authentication: To make the automation work, we securely store your specific configuration rules (e.g., alert thresholds) and encrypted authentication tokens (e.g., for Notion or Telegram). These are used exclusively to facilitate your automated workflows via official APIs.
- Usage Data: We collect anonymous, aggregated installation and error metrics provided by the Shopify Partner Dashboard and our internal monitoring tools to maintain app health.
- Payment Information: All billing is handled directly through the Shopify Billing API. Elie Labs does not collect, process, or have access to your credit card information.
3. Third-Party Integrations
Section titled “3. Third-Party Integrations”Our apps act as a conduit between Shopify and third-party services you explicitly authorize (such as Notion, Telegram, or other productivity tools). Data is only sent to these platforms based on your active configurations. We encourage you to review the privacy policies of any third-party service you choose to connect with our apps.
4. Permissions & Scopes Usage
Section titled “4. Permissions & Scopes Usage”Our apps request the absolute minimum read-only permissions (e.g., read_orders, read_products) strictly necessary to monitor the thresholds and triggers you configure. We do not request modification rights to your store data unless it is explicitly required for a specific feature you actively enable.
5. Data Retention, Deletion, and GDPR Compliance
Section titled “5. Data Retention, Deletion, and GDPR Compliance”We fully comply with Shopify’s mandatory data privacy webhooks for GDPR/CCPA requirements:
- Customer Data Requests (
customers/data_request): If a customer requests their data, we have no PII to provide, as we do not store customer records. - Customer Redact (
customers/redact): If a customer requests data deletion, no action is required on our end as no PII is retained on our servers. - Shop Redact (
shop/redact): When you uninstall our app or request store deletion, we automatically purge all your stored configurations, webhook subscriptions, and encrypted API tokens from our database within 30 days.
6. Contact Us
Section titled “6. Contact Us”Have questions? please reach out via our Contact Form or email us at: [email protected]