This policy describes how the Practical Automation Lab Shopify catalog-readiness app handles data when installed on a Shopify store.
The app requests the Shopify read_products scope. It uses Shopify's GraphQL Admin API to read product, variant, image, price, identifier, vendor, and publication fields needed to generate catalog-readiness scans. The app does not request customer or order access and does not use Shopify's legacy REST Admin API for its core catalog scan.
Free catalog data is processed by the app runtime to generate the current scan. Free scans do not create a saved catalog-history record in the PAL Catalog Check application database.
When Pro monitoring is enabled, the app stores bounded scan-result snapshots, scan scores and issue summaries, monitoring preferences, health alerts, and scheduled report summaries. This storage is required to provide saved history, change detection, recurring scans, image-readiness monitoring, and downloadable reports. Pro storage is scoped to the installed shop and is not used to build an advertising profile or a separate merchant-data marketplace.
To remain installed and authenticate requests, the app stores Shopify session data in a dedicated persistent database. This can include the shop domain, granted scopes, access-token and refresh-token material supplied through Shopify's authentication flow, and token-expiration metadata. Access to that database is restricted to the app runtime and authorized infrastructure.
The app records limited operational events such as app opens, scan starts, scan completions, product counts, readiness scores, and compliance-webhook topic names. Application access logs are configured to record request paths without Shopify's signed query string. Infrastructure providers can also process standard technical metadata such as IP addresses, timing information, and server diagnostics as part of hosting and security.
The app does not request Shopify customer or order scopes. It therefore does not intentionally collect or maintain customer or order records as part of its catalog-readiness functionality.
The app implements Shopify's mandatory privacy-compliance webhooks for customers/data_request, customers/redact, and shop/redact. Customer privacy requests are acknowledged even though the app does not maintain customer or order records. On uninstall and Shopify shop-redaction processing, PAL deletes stored installation sessions together with saved Pro scan history, monitoring preferences, alerts, and scheduled report summaries for that shop.
The Shopify app does not use merchant catalog data for advertising and does not sell merchant catalog data, saved scan results, reports, or Shopify authentication data.
The app currently relies on infrastructure providers for application hosting, operational logging, and persistent database storage. Those providers process technical data only as needed to operate those services under their own terms and privacy commitments.
For support or privacy questions, use the Shopify app's support channel or visit the PAL Catalog Check support page. Do not send store passwords, Shopify access tokens, recovery codes, customer data, or confidential catalog exports in a support request.
Last updated: September 18, 2026.