StoreFix

Privacy Policy

Last updated 7 August 2026.

What StoreFix accesses

When you install StoreFix, Shopify grants read and write access to products, collections, online store pages and theme content, plus read access to your shop profile. StoreFix uses these scopes only to audit and repair store content.

StoreFix never reads or writes orders, customers, payment details, discounts, prices or inventory quantities.

What StoreFix stores

We store your shop domain, shop name, plan, an encrypted Shopify access token, audit results (issue codes, affected resource identifiers, and the values we read or wrote) and a record of every change we make so it can be undone.

Access tokens are encrypted with AES-256-GCM before they are written to the database and are never exposed to the browser.

AI processing

Product and collection text is sent to our AI provider only to generate SEO titles, meta descriptions and image alt text. Prompts contain nothing beyond the product content required for the task, and outputs are not used to train third-party models.

Data retention and deletion

Uninstalling the app revokes our access immediately and triggers Shopify's app/uninstalled webhook, after which the encrypted token is destroyed.

StoreFix implements Shopify's mandatory GDPR webhooks: customers/data_request, customers/redact and shop/redact. Shop data is deleted within 30 days of a redaction request.

You can request export or deletion at any time by emailing privacy@storefix.app.

Free audits of public URLs

The free audit tool fetches publicly available pages exactly as a search engine would. Results are returned to your browser and are not attached to any account.

Subprocessors

Application hosting and database (managed cloud infrastructure), and an AI model gateway for text generation. All connections use TLS.