Privacy
Draft, last updated 2026-09-01. Plain description of what this service stores and why.
What we store
- Account data: name, email, password hash (or the Shopify identity used to sign in), workspace membership and role.
- Store connections: the store domain and a Theme Access password or OAuth token you enter in the browser. Credentials are encrypted at rest with keys held outside the database and are only decrypted inside a request that needs them.
- Theme data: copies of theme files for the change requests you open (baseline snapshot and working copy), validation results, before/after screenshots and visual-diff summaries of your storefront.
- Audit log: who did what and when: change created, files pushed, approved, published, rolled back. This log is append-only.
- Agent access: API keys (stored hashed) and OAuth grants for the coding agents you connect.
What we do not do
- We do not read or store your customers' personal data. Theme access only covers theme files.
- We do not send your credentials, theme files or screenshots to any AI model. Your own coding agent runs under your account with its provider; this service only executes the tool calls it makes.
- We do not sell or share data with third parties. Infrastructure providers (hosting, database, object storage, email) process data on our behalf.
Retention and deletion
Screenshots and theme snapshots for closed change requests are kept for review history and can be deleted on request. Disconnecting a store deletes its stored credential. Deleting your account removes your personal data; audit rows are kept in anonymised form.
Contact
Questions or deletion requests: open an issue at github.com/tmill313/shopbuddy.