Privacy Policy
Effective Date: September 20, 2026
At Attahir Labs, we are committed to protecting the privacy of the merchants who use our Shopify applications. This Privacy Policy describes how we collect, use, share, and retain information when you visit our website or install or use our Shopify apps. The app-specific sections below describe StockClearance, TariffShield, ShelfLife, and pre-release StoreChronicle; existing AccessShield disclosures also remain below.
1. Information We Collect
When you install one of our apps, we are automatically able to access certain types of information from your Shopify account via the Shopify API. Specifically, we may collect:
- Shop and Account Information: Your .myshopify.com domain, Shopify session and authorization records, and account or staff details supplied through the authorized session, such as user ID, name, and email. We use these to identify your store, secure access, and manage your subscription.
- Product and Inventory Data: Information about your products and inventory, including titles, prices, variants, stock levels, unit costs where available, and related product attributes needed to provide analysis (e.g., TariffShield, StockClearance).
- Order Records for Inventory Analytics: For StockClearance, we may access Shopify order records when the merchant grants the app order access. We use order dates, order IDs, line items, product IDs, quantities, cancellation status, and line-item revenue only to calculate product-level inventory signals such as last sale timing, units sold, sales velocity, seasonal history, and clearance-action results.
- Accessibility and Theme Data: For AccessShield, we may access store pages, product titles, product vendors, product image URLs, existing image alt text, page HTML content, and theme file content needed to detect WCAG-oriented accessibility issues, missing alt text, and cookie/consent script patterns. We may store accessibility issue records, WCAG rule identifiers, severity levels, page URLs, HTML snippets, fix suggestions, generated alt-text suggestions, applied/ignored/fixed statuses, compliance score snapshots, badge status, and certificate/progress-report data.
- Image-Aware Alt-Text Generation Data: For AccessShield, when AI-assisted alt-text suggestions are enabled, we may send product image URLs and limited product metadata such as product title, vendor, product type, tags, image position, and existing alt text to an AI service provider solely to generate reviewable alt-text suggestions.
- Usage and Operational Measurement: App activity, operation outcomes, timestamps, plan changes, and traffic classifications help us understand useful workflows and service reliability. Measurement can use hashed or keyed store identifiers; these are pseudonymous identifiers, not a claim that the data is anonymous. Test and development activity is classified separately where supported.
- Billing Status: Subscription plan and status supplied by Shopify, including trial duration and end date, subscription observations, and test/development indicators where available. Subscription observations do not themselves establish that a payment was collected.
- Support and Notifications: Contact addresses, notification preferences, delivery records, and the feedback or support messages you choose to send us.
StockClearance does not need customer names, email addresses, phone numbers, shipping addresses, billing addresses, or payment details for these inventory analytics. We do not use order data for customer profiling, advertising, or resale. Service providers process information as described in section 3.
AccessShield does not request access to Shopify orders, customers, customer addresses, payment details, or customer profiles. AccessShield uses product, page, theme, audit, and configuration data only to provide accessibility audits, AI-assisted alt-text review, guided remediation, cookie/consent checks, optional badge display, and progress documentation. AccessShield does not send order data, customer data, addresses, payment details, or customer profiles to AI service providers.
StockClearance
StockClearance uses product and variant identifiers, titles, images, vendor and product type, inventory quantities, prices, and available unit costs. With authorized order access, order dates, IDs, line items, quantities, cancellation status, and line-item revenue support inventory analytics. Available order history depends on Shopify access.
Stored records include inventory analysis, scan history, dead/slow/seasonal classifications, clearance rules, discount and collection references, price snapshots, action status, and reporting figures. Configured scans, optional weekly digests, and merchant-selected clearance actions use these records. Operational measurement records successful actions and usage using protected store identifiers and operation references.
TariffShield
TariffShield uses product and variant identifiers, inventory, prices, available costs, country of origin, HS/HTS classifications, target margins, destination assumptions, and custom rates. Stored records can include product tariff analysis, margin snapshots, proposed and applied price changes, notification settings, feedback, and operational measurement.
When you use an Exact Duty workflow, the service processes the classification, origin, rate, value, entry-time, and additional tariff facts you provide to calculate supported scenarios. It may retain an operation receipt and measurement metadata to record the outcome. TariffShield does not require shopper names, addresses, or payment-card details for tariff analysis.
ShelfLife
ShelfLife stores product and variant references, batch and lot identifiers, titles and SKUs, supplier information, locations, quantities, unit costs and currency, manufacture and expiry dates, status, and notes you enter or import. These support expiry checks, waste and activity reports, FEFO picking guidance, supplier reporting, and traceability workflows. Merchants maintain batch quantities.
We also store alert preferences and recipients, expiry and delivery records, import receipts, app settings, feedback, and account/session information. Expiry emails and weekly digests are opt-in. Measurement records can include activity timestamps, operation and import counts, protected store and subscription identifiers, trial and plan observations, and test/development classifications. The first-party measurement ledger is separate from optional Google Analytics delivery.
Where you enable supported Shopify sync or app-owned actions, ShelfLife may write expiry, location, and quantity summaries to app-owned Shopify variant metafields or use app-owned product markers. Configuration and effect records support verification, retry, and reversal of those actions. ShelfLife remains the batch database of record.
ShelfLife does not require Shopify shopper order or customer-profile data for these batch workflows. This does not exclude merchant account details, alert addresses, or information you choose to put into a batch record or support message.
StoreChronicle — pre-release testing
StoreChronicle is in pre-release testing and is not yet available for general installation. This section applies only to StoreChronicle and describes its current processing, including development-store testing; it does not change another app’s retention settings.
Recorded information. With the relevant plan, permissions, and enabled observations, StoreChronicle stores supported product and variant changes, prices, collection metadata and membership observations, inventory item/location quantities, theme metadata and observed file content, and page titles, handles, and HTML. Order records are limited to identifiers, name, currency, payment and fulfillment status, current total, and cancellation time. They are not complete order records. Merchant-entered content and free-text fields can contain personal information even when order projections exclude customer contact details.
We also process shop and authentication records, plan status, timezone and notification preferences, private API credential hashes and usage allowances, feedback, incoming update payloads, webhook receipts, privacy requests, and operational records. Optional activity collection stores Shopify-reported labels, resource references, and event times. Labels are not verified staff identities or proof that an activity caused a specific change. Restoration records include selected fields, before-and-after evidence, permission checks, execution status, and readback results. These support access control, investigation, review rules, exports, reliability, and deletion handling. Recorded events and periodic observations do not guarantee a complete account of every store action. StoreChronicle’s Google Analytics delivery is currently disabled.
History and operational retention. Ordinary recorded change history expires after 7 days on Free and 90 days on Standard. Pro has no automatic age-based expiry while installed, subject to continued necessity, any shorter store setting, and applicable deletion requirements. Activity and restoration evidence have a separate limit: up to 7 days on Free, 90 days on Standard, and 120 days on Pro. Monthly and annual billing have the same retention limits within each paid plan. Evidence expiry can make an older history entry ineligible for restoration. Scheduled cleanup removes expired records. Current state, authentication, configuration, privacy-request, support, and operational records have separate purposes and may remain while needed to operate the installed service or handle a request. Token expiry alone is not deletion of a session record.
Downgrade export grace. A confirmed downgrade provides a seven-day read-only ordinary-history export grace. This gives the merchant time to download history covered by the grace without continuing higher-plan functionality. It does not extend activity or restoration evidence, saved-membership exports, restoration actions, alerts, or other higher-plan features. Uninstall, erasure requests, and other applicable deletion requirements take precedence over the grace period.
Incoming updates and recovery. Incoming store updates are held in a durable processing inbox. Successful processing removes the payload. Retry authority ends after 24 hours; unresolved updates enter quarantine for investigation. Remaining payloads have a deletion deadline of at most seven days from receipt, shortened by a lower store-history limit. Scheduled maintenance removes due payloads; downtime or contention can delay physical removal and is monitored as an overdue-cleanup condition. A minimized unresolved-gap record can remain to explain incomplete processing; it is not proof that a store change was missed. Current-state checks can establish a new observation but cannot reconstruct unknown intermediate changes. Privacy erasure also covers queued and quarantined data and takes precedence over these operational periods.
Optional notifications. Notifications require an eligible plan, an explicit opt-in and a configured recipient or destination. Email uses Resend; chat uses the Slack or Discord workspace destination you authorize. Saving preferences is not proof of delivery. StoreChronicle prepares generic review notices and aggregate weekly summaries rather than copying captured product or customer values into those notices. Recipient addresses, message contents, delivery metadata, and destination secrets still require protection and separate provider handling. Notification processing records are retained for up to 30 days, with scheduled cleanup targeting day 29 and earlier local removal where required by a privacy request. This limit does not describe provider and recipient copies; turning notifications off cannot recall a message already accepted or posted.
Provider and recipient copies. Resend’s published retention terms describe 30-day email/log retention on Free, Pro and Scale, configurable Enterprise retention, and separate 7-day backups. Resend stores data in the United States and provides a support route for earlier message removal. These terms are not a guarantee that every copy disappears within 30 days. Messages held by email recipients or a Slack or Discord workspace are not automatically removed by StoreChronicle’s local deletion controls; those copies require recipient, workspace administrator or provider handling.
Uninstall and privacy requests. Authenticated Shopify uninstall and shop-deletion notifications trigger removal of store-specific records, preferences, and sessions from the active database, with retries on failure. Shopify documents a separate shop-deletion notification approximately 48 hours after uninstall; this is not a promise to retain history for reinstallation. Minimal identifiers and deletion records can remain to block stale writes and prevent erased data returning through recovery. These records are not anonymous data or retained store history. Selected-order access and erasure controls are not proof that an entire privacy request is complete: other content, support records, downloaded exports, and provider copies require separate review. Shopify privacy requests require action within 30 days of receipt unless applicable law requires retention; an acknowledgement, download or partial local erasure does not complete that action. Contact support@attahirlabs.com for access, correction, export, or deletion assistance. Include the request identifier if available, not customer records or credentials in the initial email. We coordinate any additional identity verification and provider handling separately.
Recovery copies. Railway hosts the app, its database, and a separate independent deletion log. Configured app-database recovery schedules retain daily backups for up to 6 days and weekly backups for up to 27 days after creation. Any manual recovery points or externally retained copies require separate inventory and deletion handling; the scheduled-backup limit is not a promise about all copies. Deleting active-database records does not itself erase recovery or provider copies. Backup retention does not extend a privacy-deletion deadline.
Deletion-safe recovery and record minimization. The independent deletion log holds the necessary shop or request identifiers, deletion scope, timing, and verification or external-copy case status separately from the app’s restorable database. Access is restricted. These records are retained until related recoverable copies are gone and external-copy cases are resolved, then minimized or removed under the operating policy. They are not held to preserve deleted merchant history. Recovery starts in quarantine: app access and workers remain blocked until recorded deletions are reapplied and independently checked. If deletion coverage cannot be established, recovery remains blocked. External-copy cases require evidence of resolution; local cleanup alone is not completion.
2. How We Use Your Information
We use the information we collect from you and your store to provide the service and to operate our apps. This includes:
- Providing the core functionality of the app, such as inventory analysis, clearance workflow tracking, tariff-impact calculations, expiry and batch tracking, picking guidance, supplier and traceability reporting, accessibility audits, alt-text review, cookie/consent checks, and other app-specific operational tools.
- Processing billing and payments through the Shopify platform.
- Communicating with you regarding technical support, app updates, and account-related notices.
- Monitoring and analyzing usage trends to improve our application performance.
3. Data Sharing and Disclosure
We do not sell, rent, or trade your personal information to third parties. We only share information in the following circumstances:
- Shopify: We share data with Shopify as required to provide the service, process billing, and comply with Shopify's Partner Program requirements.
- Shopify Billing: App subscription billing is handled through Shopify Billing. We receive subscription information and do not store your credit card details.
- Resend (Email): Resend processes recipient and sender addresses, subject lines, and message contents to deliver transactional emails and support notifications. Depending on the app and message, contents can include your shop, product names, inventory or margin summaries, batch identifiers, expiry dates, and the feedback you submit. Delivery identifiers and status may be retained to manage notifications and avoid duplicate sends.
- Hosting and Delivery: Infrastructure providers, including Railway for app hosting and Cloudflare for website delivery, process the records or request metadata needed to host, secure, and deliver our services.
- Google Analytics: When enabled, Google Analytics processes website activity and configured app events. App events can use hashed store identifiers and limited route, activity, and classification metadata. This is separate from our first-party operational records. See section 5 for website choices.
- AI Service Providers: For AccessShield image-aware alt-text suggestions, we may send product image URLs and limited product metadata to an AI provider such as OpenAI solely to generate alt-text suggestions for merchant review.
- Legal Compliance: We may disclose information if required by law or to respond to valid legal requests by public authorities.
4. Merchant Rights (GDPR & CCPA)
Regardless of your location, we believe you should have control over your data. You have the right to:
- Access: Request a copy of the data we hold about your store.
- Deletion: Request deletion of your data. Uninstalling also starts the account cleanup described below.
- Correction: Request that we correct any inaccurate information.
- Export: Request your data in a machine-readable format.
To exercise these rights, please contact us at support@attahirlabs.com.
Retention and deletion
We retain app records while needed to provide the installed service. Authenticated Shopify uninstall and erasure notifications trigger cleanup of the live apps’ store-specific business records, settings, sessions, and first-party measurement records. Cleanup can require retries; we do not promise that every record disappears at the instant you click uninstall.
For ShelfLife and StockClearance, limited protected identifiers and deletion-state markers can remain after cleanup to prevent delayed requests from recreating erased records. These markers are not retained batch, product, or subscription histories. Information required to resolve a support request or meet an applicable legal obligation may need separate handling.
ShelfLife also uses limited webhook delivery receipts for replay protection and deduplication. These have configured expiry and scheduled cleanup; processing retries or maintenance delays can postpone physical removal. While the app is installed and authorized, use its available cleanup controls to remove app-owned Shopify copies or reverse supported effects. After uninstall, the app no longer has Shopify Admin access and cannot promise removal of Shopify-hosted data or state.
Deleting app records does not delete Shopify’s own billing records or automatically remove records already held by email or analytics providers. Requests involving those records are handled separately. Contact us for access, export, correction, or deletion assistance, including questions about retained identifiers.
5. Cookies and Analytics
Our apps use session and authentication mechanisms to maintain access and provide functionality. Configured app analytics may be sent from our servers without placing a third-party tracking cookie in the app interface. First-party operational measurement and third-party analytics are distinct forms of processing.
For this website, Google Analytics can measure page views, App Store outbound clicks, and tool interactions, along with limited browser/device and referral information. You can turn website analytics on or off in your analytics preferences. The choice applies to this browser and site address; it does not change app-server measurement or Shopify’s own processing.
6. Security
We implement industry-standard security measures to protect your data. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
7. Contact Us
If you have any questions about this Privacy Policy or our treatment of your data, please reach out to us:
Attahir Labs
Email: support@attahirlabs.com