Seekmodo for Shopify — Privacy & Data Handling
Effective: 2026-07-25
This page describes what the Seekmodo for Shopify app reads, writes, and forwards between your Shopify store, the Seekmodo gateway, and downstream sub-processors. Broader Seekmodo policies: /legal/privacy, /legal/dpa, /legal/security.
1. OAuth scopes requested at install
- read_products / product metafields — catalog indexing for search and fitment projections.
- read_inventory — stock-aware ranking and out-of-stock exclusion when enabled.
- read_locales / read_markets — storefront locale and market pricing context.
- read_online_store_pages — optional pages/blogs content index (parity with Magento CMS indexing).
- read_customers / write_customers — garage vehicle preferences via app-owned customer metafields keyed by customer GID. We do not persist email, phone, or address.
- read_orders — conversion / purchase events for relevance learning (line items + monetary totals only; no payment instruments).
Scopes we never request: payment processing, customer passwords, draft order write, or theme Asset API write. Storefront injection uses Theme App Extensions only.
2. What we store about your store
- Shop identity —
shop_domain, Shopify shop id, install timestamps, pairedtenant_id, Managed Pricing subscription id/status. - Catalog projection — products, variants, collections, images, and mapped metafields indexed for search.
- Search and click telemetry — queries, result IDs, clicks; used for per-tenant relevance learning.
- Operational logs — IP, user-agent, latency, response codes; retained ~30 days.
3. What we store about shoppers
Guest shoppers: search queries plus a short-lived session id. Logged-in shoppers with a vehicle garage: app-owned metafields holding year/make/model slots keyed by Shopify customer GID — no email or address copies in Seekmodo systems.
4. What we don't store
- No payment card data or Shopify Payments credentials.
- No customer email/phone/shipping address in Seekmodo DBs.
- No theme Liquid source edits (Theme App Extensions only).
5. Mandatory GDPR / privacy webhooks
We implement Shopify's mandatory compliance webhooks:
customers/data_request— export any Seekmodo-held garage metafield data for the customer GID.customers/redact— delete garage metafield projections for that customer.shop/redact— delete the install row and catalog projection within 48 hours of uninstall.
6. Billing
App charges use Shopify Managed Pricing / Billing API only. Plan selection (Hobby / Starter / Growth) syncs to the paired Seekmodo tenant entitlements. Enhanced Native search remains available without a paid plan after install.
7. Sub-processors
- Cloudflare, Inc. — hosts
shopify-app.seekmodo.comand edge caches. - Numinix Web Development Ltd. — Seekmodo gateway, Postgres, search index (North America).
- NHTSA vPIC — optional VIN decode only; no Shopify shop data accompanies the VIN.
- Shopify Inc. — OAuth, Admin/Storefront APIs, Billing API, webhook delivery.
8. Contact
Privacy questions: [email protected]. Support: [email protected].