MerchGrid: Catalog Audit — Privacy Policy
Last updated: August 2, 2026
What MerchGrid does
MerchGrid: Catalog Audit is a read-only Shopify app. It reads your product catalog to identify pricing, inventory, and merchandising issues, and displays that report to you inside Shopify admin. It never modifies your store's products, inventory, or any other data.
Data we collect and why
| Data | Why we store it | Retention |
|---|---|---|
| Shopify access token | Authenticate API requests to read your catalog. Encrypted at rest. | Until uninstall |
| Shop domain and install status | Identify your store and its scan configuration | Until uninstall + GDPR deletion window |
| Scan settings (margin threshold, variant limit) | Apply your chosen thresholds to each scan | Until uninstall |
| Scan results and findings | Show and export your catalog audit report | Until uninstall + GDPR deletion window |
What we do not collect
We do not request access to, and do not store, your customers, orders, checkout data, or any personally identifiable information about your shoppers. Our app requests only read-only product and inventory access.
Data deletion
When you uninstall MerchGrid, your access token is deactivated immediately. In compliance with Shopify's mandatory data-protection requirements, we permanently delete your shop's stored data (settings, scans, findings) when Shopify sends the shop-redact request, typically within 48 hours of uninstall. You may also request deletion sooner by contacting us (see Support below).
Security
Your Shopify access token is encrypted at rest (AES-256-GCM). All traffic to and from the app is encrypted in transit (TLS). We request only the minimum Shopify API scopes required to read your product catalog — no write access of any kind.
Third parties
We do not sell or share your data with third parties.
Contact
Questions about this policy: buffrstudio@gmail.com