Who we are

This Privacy Policy applies to the Shopify apps built and operated by Philip Biedermann ("PB", "we", "us"), an independent Shopify app developer established in the European Union. You can reach us at hello@themachinedream.com.

It covers every app we publish through the Shopify App Store, together with the developer websites and support channels we operate. Apps that are still in development are covered from the moment they are installed on any store.

In data-protection terms, the merchant who installs one of our apps is the controller of the personal data in their store. We act as a processor on that merchant's behalf and process the data only to provide the app. For data about the merchant's own account and their use of our service, we act as controller.

What data we collect

Data we receive through the Shopify APIs when you install an app:

  • Your Shopify store URL, shop ID and basic shop information provided by Shopify at install time
  • An OAuth access token that lets the app call the Shopify Admin API on your behalf
  • Store data covered by the access scopes the app requested and you approved when installing — for our current apps this is shop, product, collection, inventory and pricing data

Data we collect directly from you as a merchant:

  • Your shop owner email address, used only for service-related communications
  • App configuration and settings you choose within the app
  • The content of any support request you send us, including the email address you send it from

Data relating to your storefront visitors:

  • Where an app renders a storefront widget, it records anonymous interaction events — for example, that a button was clicked — for app functionality and aggregate usage counts
  • These events are not linked to a named individual, a customer account or a persistent advertising identifier, and we do not use them to build profiles
  • Our storefront widgets do not set advertising or cross-site tracking cookies on visitor devices

Automated logs: our servers keep standard application and error logs, which can include IP addresses, request paths and timestamps. These exist for security and debugging, not for analytics.

We never collect or store payment card data of any kind. All payment processing is handled entirely by Shopify.

Why we collect it

  • To operate the app and deliver its core functionality to your store
  • To authenticate your store against the Shopify API and keep your settings available between sessions
  • To send you service-related emails — for example, billing issues, app updates that require action, or deprecation notices
  • To answer support requests and investigate faults
  • To keep the service secure and detect abuse

We limit our processing to these purposes. We do not use the data for any other purpose, we do not sell it, and we do not send marketing emails without your explicit consent.

Legal basis for processing

Where the GDPR applies, we rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — processing your store and account data in order to provide the app you installed
  • Legitimate interests (Art. 6(1)(f) GDPR) — keeping the service secure, debugging faults and preventing abuse
  • Consent (Art. 6(1)(a) GDPR) — optional communications you have opted into, which you can withdraw at any time
  • Legal obligation (Art. 6(1)(c) GDPR) — retaining records where law requires it

Where we process personal data on a merchant's behalf as a processor, the merchant determines the legal basis and we act on their documented instructions.

Who we share it with

We do not sell your data, and we do not share it with advertising networks or data brokers. We do not use third-party analytics services that track individual users. Where applicable law gives individuals the right to opt out of a "sale" or "sharing" of personal data, there is nothing for us to opt out of, because we do neither.

The following subprocessors may access data as part of operating the service:

  • Shopify — the platform through which our apps operate. Their practices are governed by the Shopify Privacy Policy.
  • Hetzner Online GmbH — hosting infrastructure. Hetzner processes data on our behalf to run the app servers and does not receive your data for its own purposes. See the Hetzner Privacy Policy.

Each subprocessor is bound by a data processing agreement. We will update this list before adding a new subprocessor.

We may also disclose data where we are legally required to do so, for example in response to a valid order from a competent authority.

Where we store and process data

We are established in the European Union. Our apps and this website run on servers operated by Hetzner Online GmbH in their Helsinki, Finland datacenter — inside the European Union and the European Economic Area.

Data stays within the European Economic Area in normal operation. Should a subprocessor ever process data outside the EEA, that transfer is covered by the European Commission's Standard Contractual Clauses or by an adequacy decision.

Data retention

  • App settings and configuration data are retained for as long as the app is installed on your store
  • When you uninstall an app, Shopify sends us a shop/redact request 48 hours later, and we delete all data associated with your store on receipt
  • Anonymous interaction counters are retained in aggregate form only and cannot be traced back to an individual
  • Application and error logs are retained for up to 30 days, then deleted
  • Support correspondence is retained for up to 24 months so we can follow up on recurring issues
  • We do not retain personal data for longer than is necessary for the purposes described above, except where law requires us to keep it

Data subject requests and Shopify compliance webhooks

Every app distributed through the Shopify App Store must respond to data subject requests, whether or not it collects personal data. Our apps subscribe to the three mandatory Shopify compliance webhooks and handle them as follows:

  • customers/data_request — a customer has asked a merchant for a copy of their data. We acknowledge the request and provide any data we hold for the referenced customer to the store owner, who passes it on to the customer.
  • customers/redact — a merchant has asked us to delete a customer's data. We delete or irreversibly redact any data we hold for that customer in that store.
  • shop/redact — sent 48 hours after a merchant uninstalls the app. We delete all data associated with that store.

We confirm receipt of each request immediately and complete the action within 30 days, unless we are legally required to retain the data. Shopify controls the timing of these requests: a redaction request for a customer with no order in the past six months is delivered after 10 days, otherwise it is withheld until six months have passed.

Your rights as a merchant

You have the right to:

  • Request a copy of all data we hold about your store at any time
  • Request correction of inaccurate data
  • Request deletion of all your data at any time, including before the automatic post-uninstall deletion
  • Object to or request a restriction of processing based on our legitimate interests
  • Receive the data you provided in a structured, commonly used, machine-readable format
  • Withdraw any consent you have given, without affecting processing that already took place

To exercise any of these rights, email us at hello@themachinedream.com. We will respond within 5 business days and complete the request within 30 days.

If you are a storefront customer rather than a merchant, please direct your request to the store you shopped with. The merchant is the controller of that data, and Shopify will route the request to us through the compliance webhooks described above. You also have the right to lodge a complaint with your local data protection supervisory authority.

Protected customer data

Shopify classifies data that relates to an identified or identifiable customer as protected customer data, and requires apps to process only the minimum needed to deliver their functionality.

Our current apps operate on shop, product, catalog and configuration data and do not request access to customer names, addresses, phone numbers or email addresses of your storefront customers. Where an app does require protected customer data, we request only the fields needed for the stated functionality, use them only for that functionality, and say so in the app listing and in this policy before the app is released.

Where a customer's consent or opt-out decision applies to processing carried out through our apps, we respect and apply that decision.

Security

  • Data is encrypted in transit using TLS, and encrypted at rest by our hosting and database providers
  • Access tokens and secrets are stored as encrypted configuration and are never written to logs
  • Access to production systems and to any personal data is limited to the people who need it, protected by strong, unique credentials and multi-factor authentication where the provider supports it
  • Test and production data are kept in separate environments
  • We keep an incident response process. If a breach affects your data and is likely to result in a risk to affected individuals, we will notify you without undue delay and support you in meeting your own notification obligations

Cookies

  • We do not use tracking cookies or advertising cookies
  • If you access an authenticated admin session for an app, a session cookie or session token may be set to keep you signed in. It expires when you sign out or close your browser
  • Our storefront widgets may use local browser storage strictly to remember a dismissed state within a session. This is required for the feature to work and is not used to identify or track a visitor

Changes to this policy

If we make significant changes to this policy, we will notify you by email at the address associated with your store. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

For any questions about this privacy policy or how your data is handled, contact us at hello@themachinedream.com.