Privacy Policy
Effective September 15, 2026. MerchUndo is operated by MangoAnvil. This policy describes how the app processes information when you use its catalog editing, import, verification, scheduling, and undo features.
Information processed by the app
- Store and authorization information: your Shopify store domain and identity, installation status, granted permissions, authorization expiry and lifecycle events. Shopify access and refresh tokens are stored encrypted so authorized background work can run without keeping your browser open.
- Catalog and content: the products, variants, collections, fields, metafields, translations, market content, redirects, file metadata, and language settings needed for the tools you use. This can include resource identifiers, titles, prices, descriptions, SKUs, tags, and other selected values.
- Task records: task names, original and proposed field values, observed values, execution and verification results, errors, timestamps, and schedules. Creating a preview stores a task and its proposed changes even if you never run it.
- Imports: the spreadsheet data or public file URL you submit is processed to inspect columns, match resources, and build changes. Imported values included in a saved task become part of its history. The app does not provide an archive of your original uploaded files. Do not include unrelated personal information in imports or task names.
- Operations and support: request metadata such as API path, status, duration, and request identifier helps diagnose failures. Hosting services may also process connection information. When you contact support, your contact details, message, and any attachments are used to handle your request.
Why we use this information
We use it to authenticate your store, load the resources you select, create and execute changes, check results, detect conflicting edits, retry failures, restore original values, run saved schedules, and provide audit downloads and support. Store-level usage summaries are calculated from retained tasks to show activity and verification outcomes. These summaries are not a billing meter.
Customers and tracking
The current app does not request Shopify customer or order permissions and does not install a storefront tracking pixel. It is not a customer or order management tool. Personal information entered into catalog fields, spreadsheets, task names, or support messages can nevertheless be included in the records described above. Shopify's admin and App Store have their own authentication, platform measurement, and privacy practices.
Services involved
MerchUndo communicates with Shopify to read and update your store. Its hosting and database infrastructure processes app records. When you choose a link import, our server requests the file from the URL you supply; that provider can receive the request and connection metadata. Google Sheets imports use a publicly exportable sheet, not access to your private Google account. Support messages may be handled through Shopify and our support email provider.
When you choose Generate with MerchUndo, our server sends the selected source fields, resource identifiers and target language to our third-party AI service provider to generate translation drafts. Shopify access tokens and AI service credentials are not included in the translation content. Draft generation does not update your store; you review the text and confirm a separate execution. Manual translation remains available without sending content to an AI service provider. The provider processes these requests under its own service terms and privacy practices. Contact us for current service-provider information.
The app runs on infrastructure separate from your Shopify store. It does not offer a merchant-selected data region or a guarantee that processing remains in your country. Contact us for current processing-location and service-provider information before submitting data subject to a particular location requirement.
Retention and deletion
Current task history has no automatic fixed-day expiry. Original values and task records are retained to support verification, undo, and audit while the store's app records remain. Undo restores eligible Shopify values; it does not erase the task history. You can export audit records before removing the app.
When Shopify notifies us that the app was uninstalled, the app removes the stored access and refresh tokens. Uninstallation does not itself immediately erase task history or undo changes already made in Shopify. When we process Shopify's shop data-redaction notification, the installation and associated tasks, changes, and schedules are deleted from the application database.
A separate compliance receipt retains the store domain, notification identifier, notification type, and processing timestamps; the current implementation has no automatic expiry for these receipts. Application-record deletion is separate from the handling of support correspondence, operational logs, and infrastructure backups. We do not promise that deleting a task's underlying store records immediately removes every operational copy. Contact us about the scope and status of a data-deletion request.
Your requests and choices
Contact [email protected] or use the support page to request information, access, correction, deletion, or restriction of processing. Include your store domain and describe the records involved. We may need to verify your authority to act for that store. Do not send passwords or access tokens. Deleting original-value records can make undo unavailable. Changes to the store itself remain under your control in Shopify.
Security and updates
The app uses HTTPS, validates Shopify session tokens and webhook signatures, and encrypts stored Shopify credentials. These safeguards do not guarantee that every security risk can be eliminated. We will update this page when the practices described here change; the effective date identifies the current version.