Privacy Policy
This Privacy Policy explains how GMC Margin Tagger (“the App”), developed by Astro Labs, accesses, processes, and protects merchant information when installed on or used in connection with Shopify stores.
1. Information We Collect
To compute gross product margins and automate Google Merchant Center classification tags, the App accesses the following store data via official Shopify APIs:
- Product Catalog Data: Product IDs, variant IDs, product titles, retail prices, cost per item (COGS), inventory policy, and existing product tags.
- Merchant Identifiers: Store domain name (myshopify.com) and cryptographically signed session tokens required for OAuth and App Bridge v4 authentication.
- Subscription Status: Billing metadata retrieved through Shopify Recurring Application Charges API to verify active plan status (Free vs. Pro).
2. Information We Never Collect
Under no circumstances does GMC Margin Tagger access or handle:
- Customer names, email addresses, phone numbers, or delivery addresses.
- Customer order histories, cart sessions, or browsing behavior.
- Credit card numbers, bank accounts, or payment processing details (all recurring subscription fees are processed directly and securely by Shopify Billing).
- Storefront tracking pixels or behavioral telemetry on your public online store.
3. Purpose and Use of Collected Data
Access to product information is limited strictly to delivering core app functions:
- Calculating unit profit margins based on retail price and recorded unit cost.
- Updating standardized Google Merchant Center classification tags (gmc_high_margin, gmc_mid_margin, gmc_low_margin, gmc_unknown_margin).
- Applying merchant-configured threshold preferences and multi-variant calculation criteria.
- Enforcing fair-usage catalog boundaries under the Free Tier and authorizing Pro features.
4. Mandatory GDPR & Privacy Compliance Webhooks
In strict adherence to Shopify App Store Partner requirements and international data protection laws (GDPR, CCPA/CPRA), the App operates dedicated automated webhook endpoints to service data requests and deletions:
- Customer Data Request (/api/webhooks/customers/data_request): Acknowledged immediately. Because no customer data is retained, no consumer records exist to disclose.
- Customer Data Erasure (/api/webhooks/customers/redact): Confirmed immediately upon receipt.
- Shop Data Erasure (/api/webhooks/shop/redact): Triggered automatically 48 hours following an app uninstallation. Upon receipt, all stored shop tokens, cached catalog references, and threshold preferences are permanently purged from database records.
5. Data Security and Storage
All communication between Shopify, the merchant browser, and our backend services takes place exclusively over TLS/HTTPS encryption. Authentication relies on time-limited, JSON Web Tokens (JWT) signed by Shopify. Backend infrastructure and non-sensitive shop preferences are hosted within enterprise-grade Google Cloud / Firebase data centers with strict role-based access control.
6. Third-Party Sharing
We do not sell, rent, monetize, or trade merchant catalog data to third parties, advertising brokers, or data aggregators. Catalog metadata is transmitted solely between your Shopify store and our application backends to execute tagging actions initiated by you.
7. Merchant Rights & Uninstallation
You retain full ownership and control of your store data at all times. You may terminate data processing immediately by uninstalling GMC Margin Tagger from your Shopify Admin. Uninstallation automatically revokes all API access tokens and queues the store record for permanent removal via our deletion webhooks.
8. Contact & Privacy Inquiries
For inquiries regarding this Privacy Policy, data handling practices, or compliance verification, contact our developer team:
Astro Labs — Data Protection Office
Email: support@astrolabs.io
Support Window: Monday – Friday, 9:00 AM – 6:00 PM UTC