Privacy Policy
Spotly
Last updated: July 19, 2026
Introduction
Spotly (“we,” “our,” or “us”) is a Shopify application that scans your product catalog to identify data quality issues and generate a store health score. This privacy policy explains what data we collect, how we use it, and how we protect it.
What data we collect
When you install and use Spotly, we access and process the following data through the Shopify API:
- Store information: Your shop domain, shop name, and Shopify access token (required for authentication and API access).
- Product catalog data: Product titles, descriptions, images, image alt text, SKUs, barcodes/GTINs, variant details, and collection assignments. This data is read during a catalog scan to identify issues.
- Scan results: The health score, issue counts, and references to affected products generated by each scan.
- App settings: Your per-store check preferences (which checks are enabled or disabled).
What data we do not collect
- We do not collect customer personal data (names, emails, addresses, payment information).
- We do not collect order or transaction data.
- We do not track merchants or their customers across other websites or services.
How we use your data
We use the data listed above solely to:
- Run catalog health scans and generate your store health score.
- Display scan results and link to affected products in your Shopify admin.
- Remember your check preferences between sessions.
We do not sell, rent, or share your data with any third parties. We do not use your data for advertising, profiling, or any purpose unrelated to the functionality of Spotly.
Data storage and security
- Your Shopify access token is stored securely and used only to authenticate API requests on your behalf.
- Product catalog data is processed during scans. Scan results (issue counts and product references) are stored to display your dashboard.
- All data is transmitted over HTTPS.
Data retention and deletion
- On uninstall: When you uninstall Spotly, we immediately invalidate your access token and cease all API access.
- 48 hours after uninstall: In response to Shopify’s
shop/redact webhook, we permanently delete all data associated with your store, including scan history, settings, and stored shop information.
- Customer data requests: If a customer submits a data access or deletion request through your store, we respond to Shopify’s
customers/data_request and customers/redact webhooks. Since Spotly does not collect or store customer personal data, these requests typically require no action on our part beyond confirming compliance.
Your rights
You may request access to, correction of, or deletion of your data at any time by contacting us. You may also uninstall the app at any time, which triggers automatic data deletion as described above.
Changes to this policy
We may update this privacy policy from time to time. If we make material changes, we will notify you through the app or via the email associated with your Shopify account.
If you have any questions about this privacy policy or how your data is handled, please contact us at:
Email: georgehadjisavvas12@gmail.com