Seekmodo for Shopify — Privacy & Data Handling

Effective: 2026-07-25

This page describes what the Seekmodo for Shopify app reads, writes, and forwards between your Shopify store, the Seekmodo gateway, and downstream sub-processors. Broader Seekmodo policies: /legal/privacy, /legal/dpa, /legal/security.

1. OAuth scopes requested at install

  • read_products / product metafields — catalog indexing for search and fitment projections.
  • read_inventory — stock-aware ranking and out-of-stock exclusion when enabled.
  • read_locales / read_markets — storefront locale and market pricing context.
  • read_online_store_pages — optional pages/blogs content index (parity with Magento CMS indexing).
  • read_customers / write_customers — garage vehicle preferences via app-owned customer metafields keyed by customer GID. We do not persist email, phone, or address.
  • read_orders — conversion / purchase events for relevance learning (line items + monetary totals only; no payment instruments).

Scopes we never request: payment processing, customer passwords, draft order write, or theme Asset API write. Storefront injection uses Theme App Extensions only.

2. What we store about your store

  • Shop identityshop_domain, Shopify shop id, install timestamps, paired tenant_id, Managed Pricing subscription id/status.
  • Catalog projection — products, variants, collections, images, and mapped metafields indexed for search.
  • Search and click telemetry — queries, result IDs, clicks; used for per-tenant relevance learning.
  • Operational logs — IP, user-agent, latency, response codes; retained ~30 days.

3. What we store about shoppers

Guest shoppers: search queries plus a short-lived session id. Logged-in shoppers with a vehicle garage: app-owned metafields holding year/make/model slots keyed by Shopify customer GID — no email or address copies in Seekmodo systems.

4. What we don't store

  • No payment card data or Shopify Payments credentials.
  • No customer email/phone/shipping address in Seekmodo DBs.
  • No theme Liquid source edits (Theme App Extensions only).

5. Mandatory GDPR / privacy webhooks

We implement Shopify's mandatory compliance webhooks:

  • customers/data_request — export any Seekmodo-held garage metafield data for the customer GID.
  • customers/redact — delete garage metafield projections for that customer.
  • shop/redact — delete the install row and catalog projection within 48 hours of uninstall.

6. Billing

App charges use Shopify Managed Pricing / Billing API only. Plan selection (Hobby / Starter / Growth) syncs to the paired Seekmodo tenant entitlements. Enhanced Native search remains available without a paid plan after install.

7. Sub-processors

  • Cloudflare, Inc. — hosts shopify-app.seekmodo.com and edge caches.
  • Numinix Web Development Ltd. — Seekmodo gateway, Postgres, search index (North America).
  • NHTSA vPIC — optional VIN decode only; no Shopify shop data accompanies the VIN.
  • Shopify Inc. — OAuth, Admin/Storefront APIs, Billing API, webhook delivery.

8. Contact

Privacy questions: [email protected]. Support: [email protected].