← Practical Automation Lab

PAL Catalog Check privacy policy

This policy describes how the Practical Automation Lab Shopify catalog-readiness app handles data when installed on a Shopify store.

Shopify access

The app requests the Shopify read_products scope. It uses Shopify's GraphQL Admin API to read product, variant, image, price, identifier, vendor, and publication fields needed to generate catalog-readiness scans. The app does not request customer or order access and does not use Shopify's legacy REST Admin API for its core catalog scan.

Free scan data

Free catalog data is processed by the app runtime to generate the current scan. Free scans do not create a saved catalog-history record in the PAL Catalog Check application database.

Pro monitoring data

When Pro monitoring is enabled, the app stores bounded scan-result snapshots, scan scores and issue summaries, monitoring preferences, health alerts, and scheduled report summaries. This storage is required to provide saved history, change detection, recurring scans, image-readiness monitoring, and downloadable reports. Pro storage is scoped to the installed shop and is not used to build an advertising profile or a separate merchant-data marketplace.

Installation and authentication data

To remain installed and authenticate requests, the app stores Shopify session data in a dedicated persistent database. This can include the shop domain, granted scopes, access-token and refresh-token material supplied through Shopify's authentication flow, and token-expiration metadata. Access to that database is restricted to the app runtime and authorized infrastructure.

Operational logs

The app records limited operational events such as app opens, scan starts, scan completions, product counts, readiness scores, and compliance-webhook topic names. Application access logs are configured to record request paths without Shopify's signed query string. Infrastructure providers can also process standard technical metadata such as IP addresses, timing information, and server diagnostics as part of hosting and security.

Customer and order data

The app does not request Shopify customer or order scopes. It therefore does not intentionally collect or maintain customer or order records as part of its catalog-readiness functionality.

Privacy requests and deletion

The app implements Shopify's mandatory privacy-compliance webhooks for customers/data_request, customers/redact, and shop/redact. Customer privacy requests are acknowledged even though the app does not maintain customer or order records. On uninstall and Shopify shop-redaction processing, PAL deletes stored installation sessions together with saved Pro scan history, monitoring preferences, alerts, and scheduled report summaries for that shop.

Advertising and sale of data

The Shopify app does not use merchant catalog data for advertising and does not sell merchant catalog data, saved scan results, reports, or Shopify authentication data.

Service providers

The app currently relies on infrastructure providers for application hosting, operational logging, and persistent database storage. Those providers process technical data only as needed to operate those services under their own terms and privacy commitments.

Support and contact

For support or privacy questions, use the Shopify app's support channel or visit the PAL Catalog Check support page. Do not send store passwords, Shopify access tokens, recovery codes, customer data, or confidential catalog exports in a support request.

Last updated: September 18, 2026.