Legal
Privacy Policy
Last updated: March 13, 2025
1. Overview
2. Data we collect
We collect the minimum data necessary to provide the App's functionality:
| Data | Purpose |
|---|---|
| Shop domain | Identifies which Shopify store the data belongs to. Collected automatically on installation. |
| Brand records | Name, description, and image URL that the merchant enters when creating a brand. |
| Product associations | Shopify product IDs and titles that the merchant assigns to each brand. |
| Access token | The Shopify OAuth access token required to make API calls on behalf of the store. |
We do not collect personal data about your customers. The storefront blocks fetch brand data directly from our API without any customer information being transmitted or stored.
3. How we use your data
- To create, store, update, and delete brands you manage in the App.
- To serve brand and product data to your storefront via the proxy API (
/apps/brands). - To authenticate API requests using the Shopify access token.
- To associate your data with the correct store using the shop domain.
We do not use your data for advertising, profiling, or any purpose beyond operating the App.
4. Data storage and security
All data is stored in a managed database hosted on secure infrastructure. Access to the database is restricted to the App's backend services only. Data is encrypted at rest and in transit using industry-standard TLS.
Access tokens are stored securely and are never exposed in client-side code or logs.
5. Data sharing
We do not sell, rent, or share your data with third parties, except:
- Shopify — as required to operate as a Shopify App (API calls, OAuth).
- Infrastructure providers — hosting and database services that process data solely on our behalf under strict confidentiality obligations.
- Legal requirement — if we are required by law, court order, or government authority to disclose data.
6. Data retention
We retain your data for as long as the App is installed on your store. When you uninstall the App, Shopify sends an uninstall webhook and we permanently delete all data associated with your store within 48 hours.
You may also request immediate deletion at any time by contacting us (see Section 9).
7. Cookies and tracking
The App itself does not set cookies or use any tracking technologies on your storefront or in the admin interface. The Shopify admin iframe may use cookies as part of Shopify's own platform — please refer to Shopify's Privacy Policy for details.
8. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict certain processing.
- Data portability (receive your data in a structured format).
To exercise any of these rights, contact us using the details in Section 9.
9. Contact
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us through the Get support link on the Shopify App Store listing for Easy Shop by Brand.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the App after changes are posted constitutes acceptance of the revised policy.