Privacy policy

Effective July 19, 2026

App operator

DELVIN AS
Norwegian organization number 932 564 645
c/o Lasse Sviland, Sørhalla 16A, 1344 Haslum, Norway

What the app processes

The app reads the Shopify product and variant identifiers, titles, handles, descriptions, vendor and product-type labels, publication and lifecycle status, tags, creation and update times, product SEO title and description fields, taxonomy categories, prices and compare-at prices, SKUs and barcodes, option names and values, inventory quantities and policies, sale availability, shipping and inventory-tracking flags, weight measurements, and media type, status, alt text, dimensions, and preview URL needed to synchronize and audit the catalog. Core catalog auditing does not require customer names, addresses, email addresses, phone numbers, orders, payment data, or media files themselves.

The app also stores the shop domain and Shopify shop identifier, granted access scopes, subscription and entitlement status, catalog run state, merchant-approved settings, bounded usage records, and audit events needed to secure and operate the service. It does not request access to Shopify customer or order records.

Why data is processed

Catalog data is used to create deterministic quality checks, issue evidence, readiness test results, merchant-approved catalog changes and descriptions, job history and exports. Shopify remains the catalog source of truth.

Storage and security

Operational records are stored in Cloudflare D1. Versioned private snapshots and exports are stored in Cloudflare R2. Shopify access and refresh tokens are encrypted with AES-GCM before storage; encryption keys are held as Worker secrets and support rotation.

Service logs and network data

The application does not intentionally copy IP addresses, browser user-agent strings, or device identifiers into its D1 or R2 app-data stores. Cloudflare and Shopify can process transient network, request, security, and diagnostic information when they deliver and protect the service. Their processing and infrastructure-log retention are governed by their own privacy and security terms.

Sharing and model use

Core catalog auditing uses deterministic software rules and does not send catalog or customer data to an LLM. If a merchant explicitly chooses Refine using AI, the current description draft and the product title, vendor, and product type are sent to Google AI Studio for text generation. The app does not send the product image, tags, or customer data for this action, and the generated text remains a draft until the merchant saves it. Data is not sold. Cloudflare, Shopify, and Google act as infrastructure or service providers required for the features a merchant chooses to use.

Retention

Current catalog projections, settings, encrypted sessions, and operational records are kept while the app remains installed and while they are needed to provide synchronization, evidence, rollback, security, and support. The history period presented by the app is determined by the active plan: 90 days on Essential, 180 days on Growth, 365 days on Pro, and 730 days on Scale. Generated exports carry plan-based expiration periods of 7, 30, 90, or 180 days. A merchant can request deletion at any time instead of waiting for those periods.

Export and deletion

Merchants can export the current catalog audit and request complete app-data deletion from Settings. Uninstall and Shopify privacy webhooks queue the same software-only deletion pipeline immediately, and privacy requests are completed within 30 days. Deletion covers sessions, projections, evidence, snapshots, exports, operational telemetry, and audit records held by the app; it never deletes Shopify products.

International processing

The operator is established in Norway. Shopify, Cloudflare, and, only when a merchant requests AI refinement, Google can process data in the European Economic Area and in other countries where they operate infrastructure. Where personal data is transferred outside the EEA, the operator relies on the applicable contractual and legal transfer safeguards offered by those providers.

Your data rights

Depending on applicable law, a merchant can request access, correction, portability, restriction, objection, or deletion of personal data controlled by the operator. Catalog-source corrections should be made in Shopify, which remains the source of truth. The operator will verify the request and respond within the period required by law. Merchants can also complain to their local data protection authority; in Norway this is Datatilsynet.

Contact

Email privacy questions, access requests, or deletion concerns to lasse@sviland.net. Product-support requests can be sent to lasse@sviland.net.