Privacy Policy
This policy explains what the Commerce Observability app accesses when you install it on your Shopify store and connect your Google Merchant Center account, and how you can revoke access at any time.
Data we access from Shopify
- Product catalog data — products, variants, prices, availability, and publication status. The app requests only the read-only
read_productspermission. - Store information — your shop domain, needed to identify your store and receive Shopify app events (for example product-change and app-uninstall notifications).
The app does not request access to customer, order, or payout data.
Data we access from Google Merchant Center
- Account information — the Merchant Center accounts your Google login can access (account IDs, names, and statuses), so you can choose which account to monitor.
- Product and status data — the items Merchant Center holds for the selected account and their item-level processing and approval statuses, so they can be compared against your Shopify catalog.
Google access uses OAuth 2.0 with your own Google account. Google may show the app's requested permission scope; the app restricts itself to read-only operations (see below).
Read-only by design
Commerce Observability is a monitoring tool. It never creates, edits, deletes, or re-prices products, and it never changes settings, in either Shopify or Google Merchant Center. It reads data from both platforms and reports differences to you.
OAuth tokens and security
- Authorization happens server-side; tokens are exchanged and stored on the server, never in your browser.
- Stored Shopify and Google access and refresh tokens are encrypted at rest using authenticated AES-256-GCM encryption.
- The service runs on cloud hosting infrastructure (Railway) with a managed PostgreSQL database.
- These public pages and the app contain no advertising, analytics, or third-party tracking scripts, and your data is not sold or used for advertising.
Disconnecting Google
You can disconnect Google at any time from the app's Google Merchant Center settings page in Shopify. Disconnecting revokes the app's authorization with Google and deletes the stored Google tokens from our database immediately. Shopify app access is removed by uninstalling the app from your Shopify admin.
Uninstall and data deletion
- When you uninstall the app, Shopify processing for your store stops and your stored Shopify session tokens are deleted.
- We receive and record Shopify's mandatory compliance notifications (customer data requests and data-erasure events). These records may contain customer identifiers supplied by Shopify and are kept as processing evidence.
- The app does not run time-based automated deletion jobs today; data is removed through the disconnect and uninstall actions described above.
To request deletion of data associated with your store, contact us at messikazi2121@gmail.com.
Contact
Questions about this policy or your data: messikazi2121@gmail.com.