Privacy Policy
Last updated: September 2026
ConvertCanvas ("ConvertCanvas", "the App", "we", "us") is a Shopify application that provides a visual page builder for Shopify merchants ("Merchants"). Designs created in the App are compiled to native Online Store 2.0 theme files (JSON templates and Liquid sections) and synced to the Merchant's theme via the Shopify Admin API. This policy describes what data the App processes, why, and how it is protected.
Data we collect
Merchant account data — collected automatically at install through Shopify OAuth:
- Shop domain (e.g.
your-store.myshopify.com). - A Shopify API access token, scoped to
read_themesandwrite_themesonly. The App cannot access orders, customers, products, or any other store data. - The name and email address of the staff user who installs or opens the App, as provided by Shopify during authentication.
- Your current plan (Free, Basic, or Plus), which is read from Shopify's billing system and never set independently by the App.
Content the Merchant creates — stored so the builder can save, version, and publish your work:
- Page designs you build in the editor (titles, handles, page type, draft/published status, and the design content itself).
- Page version history, enabling rollback to earlier designs.
- Custom templates you save to your library.
- An activity log of in-app events (e.g. pages published, plan changes) shown in your dashboard.
Data we do not collect
- No end-customer personal data. The App does not access, store, or process any personal data of your store's customers. It requests no customer-related API scopes, subscribes to no order or customer webhooks, and holds no customer records of any kind.
- No payment card data. All billing is handled entirely by Shopify Billing; the App only stores the name of your current plan.
- No tracking cookies, advertising identifiers, or analytics profiles of your storefront visitors.
How we use the data
- Authenticating your store and keeping the App connected to Shopify.
- Saving your designs and publishing them as theme files to your draft theme.
- Keeping your plan and feature limits in sync with Shopify's billing state.
- Operating, securing, and improving the App.
We do not sell data, do not use merchant or store data for advertising, and do not share data with third parties except the hosting provider that runs the App's infrastructure.
GDPR compliance webhooks
The App implements Shopify's mandatory compliance webhooks:
customers/data_request— because the App stores no customer data, there is nothing to export. The request is logged and acknowledged.customers/redact— because the App stores no customer data, there is nothing to erase. The request is logged and acknowledged.shop/redact— triggers deletion of all data the App holds for the shop: sessions (including access tokens), the shop record, and everything under it (pages, page versions, custom templates, activity log).
Data retention and deletion
- Shop data is retained while the App is installed.
- On uninstall, Shopify's
app/uninstalledwebhook triggers immediate deletion of all of the shop's data in the App: sessions and access tokens, pages, page versions, custom templates, and activity history. - Theme files that were already published to your theme are not deleted — they are native theme code owned by you and keep working after uninstall. You can remove them from your theme at any time via Shopify's theme editor or code editor.
Security
- All traffic is served over HTTPS.
- All Shopify webhook payloads are verified against Shopify's HMAC signature before processing.
- Access tokens are used only for the theme operations the App was granted and are deleted on uninstall.
Changes to this policy
If we change how we handle data, we will update this page and revise the "Last updated" date above.
Contact
Privacy questions or data requests: support@convertcanvas.com