Privacy Policy
Last updated: July 1, 2026
This Privacy Policy describes how ShopBeat ("we", "us", or "our") collects, uses, stores, and shares information when you install and use the ShopBeat application ("App") on your Shopify store.
By installing or using ShopBeat, you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not install or use the App.
1. Who this policy applies to
This policy applies to merchants (store owners and staff) who install and use ShopBeat. ShopBeat is an internal admin tool — it is not visible to your store's customers or website visitors.
2. Information we collect through Shopify
When you install ShopBeat, we access data from your Shopify store through Shopify's APIs, limited to the scopes you approve at installation:
- Products — titles, images, and identifiers, when you attach a product to a post
- Collections — titles, images, and identifiers, when you attach a collection to a post
- Orders — order identifiers and related metadata, when you attach an order to a post
- Customers — names and identifiers, when you attach a customer to a post
- Files — images you upload or attach to posts
- Product listings — as needed to display attached product information
We cache titles and image URLs on posts so your team feed loads quickly. We do not use this data for purposes unrelated to providing the App.
3. Information we collect from merchants and staff
When staff members use ShopBeat, we store:
- Shopify staff ID, first name, last name, and email (from your Shopify admin session)
- Staff avatar URL, if available from Shopify
- Posts, comments, likes, reposts, @mentions, and image tag coordinates created in the App
- In-app notifications generated by team activity
- Your shop's myshopify.com domain
- OAuth session tokens required to authenticate with Shopify (stored securely and deleted on uninstall)
4. Information we do not collect
- We do not place cookies or tracking technologies on your online storefront
- We do not collect data directly from your store's customers or website visitors
- We do not sell, rent, or trade merchant or customer data to third parties
- We do not use your data for advertising or profiling
Customer or order information may appear in posts only when a merchant voluntarily attaches that asset to a feed post. ShopBeat does not independently harvest customer PII beyond what Shopify's APIs return for attached resources.
5. How we use information
We use collected information solely to:
- Provide, operate, and maintain the ShopBeat team feed
- Display posts, comments, likes, tags, mentions, and notifications to your authorized staff
- Authenticate your store with Shopify
- Process subscription billing through Shopify's Billing API
- Respond to support requests and comply with legal obligations
- Improve the reliability and security of the App
6. Data sharing
We do not sell your data. We may share information only in these limited circumstances:
- Shopify — as required to operate the App on the Shopify platform
- Service providers — hosting and infrastructure providers that process data on our behalf under confidentiality obligations (e.g. cloud hosting where the App is deployed)
- Legal requirements — when required by law, regulation, or valid legal process
7. Data retention
We retain your shop's data for as long as the App is installed on your store. When you uninstall ShopBeat, we delete your shop's data from our systems, including posts, comments, staff profiles, notifications, and session tokens.
We may retain minimal logs for security and legal compliance for a limited period, after which they are deleted or anonymized.
8. GDPR and data subject rights
ShopBeat subscribes to Shopify's mandatory compliance webhooks:
- customers/data_request — we acknowledge requests; ShopBeat does not independently store customer PII beyond cached asset metadata in merchant-created posts
- customers/redact — we acknowledge redaction requests; customer data in posts is removed when the shop uninstalls the App or upon specific merchant request
- shop/redact — we delete all shop data from our systems
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your data. To exercise these rights, contact us at support@shopbeat.app.
9. Security
We use industry-standard measures to protect data, including encrypted connections (HTTPS), secure session storage, and access controls. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.
10. International data transfers
Your data may be processed and stored in the United States or other countries where our service providers operate. By using ShopBeat, you consent to this transfer where permitted by applicable law.
11. Children's privacy
ShopBeat is a business tool for Shopify merchants and is not directed at children under 16. We do not knowingly collect information from children.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the "Last updated" date. Continued use of the App after changes constitutes acceptance of the updated policy.
13. Contact us
If you have questions about this Privacy Policy or our data practices, contact us:
- Email: support@shopbeat.app
- Support page: shopbeat.app/support