Privacy Policy

Last updated: September 2026

Welcome to Torziva Catalog. This Privacy Policy explains how we collect, use, and protect your data when you install and use our Shopify embedded app ("the App"). We believe in being fully transparent about how your data is handled.

1. Information We Collect and How We Use It

When you install Torziva Catalog on your Shopify store, we collect and process the following information:

  • Store Installation Data: We store your shop domain and an encrypted Shopify access token via Shopify OAuth to authenticate your store and grant us permission to interact with your catalog.
  • Product Catalog Data: We read your product data via Shopify's GraphQL Admin API (including titles, descriptions, images, variants, SKUs, barcodes, vendor, and product type). We use this data strictly to run catalog-quality checks and generate completeness scores.
  • Scan Results: We store the results of our scans, including detected issues and completeness scores, in our secure database to power your dashboard.
  • Contact Information: We fetch your store's contact email from Shopify to send transactional emails when scheduled scans find new issues. You can opt out of these emails at any time via a settings toggle or an unsubscribe link.

Note: Our App is built for merchants, not your end customers. We do not process direct customer data (PII). However, product data we process (like descriptions or images) could incidentally include end-customer-facing content.

2. Third-Party Data Processors

We do not sell or share your data with anyone. We only share data with the following trusted third-party processors required to operate the App:

  • Supabase: We use Supabase to securely store your shop credentials, scan results, detected issues, and completeness scores.
  • OpenAI: If you are on an eligible plan and manually opt-in to generate an AI suggestion, we transmit specific product data (including text and images) to OpenAI's API (gpt-5.6-luna) to generate the suggested fix. Data is only sent to OpenAI when you explicitly request a suggestion.
  • Resend: We use Resend to deliver transactional email notifications about your scheduled scans.
  • Shopify: We interact with Shopify to read your catalog and, only with your explicit permission, write suggested fixes back to your store via mutations. All billing is handled entirely by Shopify's Billing API—we never see or store your payment or credit card details.

3. Data Retention and Deletion

We retain your store data and scan history for as long as the App is installed on your store.

If you choose to uninstall the App, your data will be permanently deleted. Torziva Catalog fully implements Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact, and shop/redact). When Shopify notifies us that you have uninstalled the App (via shop/redact), all data associated with your store—including scans, issues, suggestions, and scores—is automatically and permanently wiped from our database.

4. Your Rights

You have the right to access, correct, or request the deletion of your data at any time. Because we adhere to Shopify's strict webhook compliance, any data deletion requests made through your Shopify admin panel will be automatically processed by our systems.

Legal Review Recommended

You should have a legal professional review Sections 2 and 3 to ensure they meet the specific compliance requirements (like GDPR/CCPA) for your jurisdiction, especially regarding the transmission of data to OpenAI.

5. Contact Us

If you have any questions about this Privacy Policy or how your data is handled, please contact us at:
Email: support@torziva.site