Skip to main content
Privacy

Customer PII
Removed immediately
Personal data is redacted right away; only non-PII operational data is kept temporarily.
Retention lens
Billing-period restore
Operational data is retained only until the end of the current billing period.
Compliance
Shopify aligned
Supports Shopify billing, uninstall, and privacy webhook obligations.
What we collectHow we use itAI processingRetentionComplianceSecurityRightsContact
Last updated: June 27, 2026 · Applies to Margin Optimizer (sparande.co.uk)

1. What Data We Collect

Margin Optimizer processes merchant, store, and operational commerce data from Shopify, plus the settings merchants add inside the app. This includes:

  • Store and account information: shop domain, plan and billing status, timezone and currency settings, and store contact details made available through Shopify.
  • Merchant authentication and audit data: Shopify session records and app authentication data, which may include the merchant or staff user ID, name, email address, account-owner flag, locale, and encrypted access tokens. We use this for secure access, operational notices, and to understand who triggered certain actions in the app.
  • Product, inventory, and location data: product titles, variant titles, SKUs, barcodes, pricing, compare-at pricing, unit cost, inventory quantities, inventory item IDs, tags, product type, vendor, product images, and location-level inventory facts. Among the product-pricing data we transmit, current price and cost-per-item affect today's margin recommendations. Compare-at price is transported as pricing context but does not currently affect them.
  • Order and performance data: recent order-line facts and recommendation-performance records used to estimate demand, margin, and the measured outcome of applied pricing changes. This can include order IDs, product or variant IDs, quantities, prices, order timestamps, source channel, and shipping country code (a two-letter country code only — we do not read customer names, emails, phone numbers, or addresses from orders).
  • Connected marketplace credentials: when a merchant connects an external sales channel (for example Amazon, eBay, Faire, Mable, or RangeMe), we store the OAuth authorization for that channel — encrypted access and refresh tokens, the external account or seller ID, and the granted scopes — so the app can read pricing signals and publish approved pricing on the merchant's behalf. These are retained only while the connection is active and are deleted when the merchant disconnects the channel or uninstalls the app.
  • Merchant-provided inputs: pricing rules and exclusions, AI context notes, approval choices, and other configuration data entered in the app.

Margin Optimizer's core operational workflows are designed to avoid storing customer names, email addresses, phone numbers, street addresses, or payment details unless a specific privacy, audit, or support workflow requires them. When a merchant uninstalls, we promptly delete the Shopify session records and the stored Shopify access token from our systems, and we preserve only the minimum non-PII operational data needed for the billing-period restore window. Personal data is removed or redacted as part of the uninstall and privacy workflows.

2. How We Use Information

We use the information described above solely to provide and improve Margin Optimizer’s services.

  • Analyze product movement, demand, and margin across Shopify and connected channels over time.
  • Generate explainable pricing and margin recommendations for your catalogue, with the expected impact and a confidence signal.
  • Generate AI-assisted recommendations and the plain-language explanations shown with them.
  • Apply approved pricing changes to Shopify and connected marketplaces, and measure their outcome.
  • Record merchant approvals, overrides, state transitions, sync attempts, and applied-change outcomes for support, rollback, and audit purposes.
  • Send operational reminders, audit notices, and privacy-response emails when needed.
  • Process billing and subscription management through Shopify.
  • Maintain service reliability, troubleshoot issues, and improve store-specific recommendations.
  • Use infrastructure and application telemetry for security, fraud prevention, cost control, and service monitoring.
  • Record GDPR webhook handling and operational access events so privacy requests and security incidents can be audited.

We never sell, rent, or share your store data with third parties for marketing or advertising purposes.

The embedded app is designed without third-party advertising trackers. If we introduce product analytics tooling in the future, we will update this policy before using it for merchant-facing behaviour analysis.

3. AI Processing

Margin Optimizer sends selected store-operational data to the Microsoft Azure OpenAI Service to generate pricing and margin recommendations and the plain-language explanations shown with them. Azure OpenAI processes this input within Microsoft Azure under Microsoft's enterprise terms; inputs are not used to train the underlying foundation models. The input may include product titles, variant titles, SKUs, prices, unit costs, inventory levels, demand and margin metrics, and the merchant notes or preferences relevant to the recommendation.

This AI input is not fully anonymised because product and SKU data can identify items in a merchant's catalogue. It is intentionally limited to business and operational data. We do not send customer names, payment details, or customer contact records to the AI service as part of the normal recommendation pipeline.

We may also use store-level operational outcomes, such as which recommendations were accepted and the measured result of applied pricing changes, to improve future recommendations for that merchant.

4. Data Retention and Deletion

  • Margin Optimizer uses recent order history, typically the last 90 days, to power demand and margin analysis. Records older than that are not needed for the core analysis workflow and may be pruned or rolled up into aggregate reporting.
  • We retain merchant, store, and operational data only for as long as it is needed to provide the service, maintain auditability, support rollback and billing workflows, and comply with Shopify or legal obligations. Where a shorter retention period is possible, we use it.
  • If the app is uninstalled, we promptly delete the Shopify session records and the stored Shopify access token from our systems, and we delete the stored credentials for any connected marketplaces. (Deleting our stored copy stops our access; a merchant can also revoke the app from their Shopify admin at any time.) When Shopify later sends the mandatory shop/redact webhook, we delete the shop record and related app data unless a longer retention period is required by law. If the merchant reinstalls during the billing-period restore window, only the minimum non-PII operational data needed to restore paid-for settings is retained until that window ends.
  • Some raw attribution records may be pruned after they have been rolled up into longer-term reporting records, but audit and operational history needed to run and support the app may remain while the merchant uses the service.

5. GDPR & CCPA Compliance

Margin Optimizer is designed with privacy by default. We comply with Shopify's mandatory GDPR webhooks:

  • customers/data_request: we review what Margin Optimizer holds that relates to the request and process the request through our privacy workflow, including the merchant data export endpoint where appropriate.
  • customers/redact: when Shopify provides order IDs to redact, we delete matching order-line records from our database.
  • shop/redact: we delete the shop record and related operational app data from our database after Shopify sends this webhook, unless a legal retention obligation applies.

6. Security & Infrastructure

  • We implement reasonable administrative, technical, and organizational safeguards to protect merchant data against unauthorized access, disclosure, alteration, or destruction.
  • Admin access to the systems we use for the service requires strong, unique passwords and MFA on the core control planes we rely on, including GitHub, Microsoft Azure, Shopify Partner access, and shared mail or password-manager accounts.
  • Customer and merchant data is separated from development data where possible, and production secrets are stored in Azure Key Vault rather than in source code.
  • We use authenticated Shopify app sessions and protect access tokens and API credentials as sensitive data. Marketplace OAuth tokens are encrypted at rest.
  • Our structured application logs redact sensitive fields such as tokens, API keys, and email addresses; we do not rely on logs as a source of customer-facing personal data.
  • We maintain a documented security incident response process for containment, investigation, recovery, and required notifications.

Sub-processors

We rely on a small set of sub-processors to run the service. Data is shared with them only as needed to operate Margin Optimizer:

  • Microsoft Azure — cloud hosting, managed PostgreSQL database, secret storage (Azure Key Vault), and message queues.
  • Microsoft Azure OpenAI Service — generates pricing/margin recommendations and their explanations from store-operational data (see “AI Processing” above).
  • Resend — delivery of operational, audit, and privacy-response emails. This may include the recipient's email address and the message contents.
  • Shopify — the platform the app runs on; source of catalog, order, and billing data and the mandatory privacy webhooks.
  • Connected marketplaces you enable (e.g. Amazon, eBay, Faire, Mable, RangeMe) — when a merchant connects a channel, product and pricing data is shared with that channel to read signals and publish approved pricing.

7. Privacy Rights

  • Merchants and customers may have rights under applicable privacy laws, including rights to request access to or deletion of personal data where applicable.
  • Merchants can contact us directly about app data. Customers should usually submit privacy requests through the merchant or Shopify, and we respond to Shopify's mandatory privacy webhooks where applicable.
  • Uninstall and reinstall are self-serve: restore previous settings if you reinstall during the billing period you already paid for, or choose Start Fresh to permanently delete the preserved data.

8. Contact Us

For privacy-related requests, data deletion, or questions about this policy: