Privacy Policy — SKU Surf
Effective date: 2026-04-18
Last updated: 2026-09-07
SKU Surf ("the App," "we," "our," or "us"), operated by Raj Patel (a sole proprietor based in Minneapolis, Minnesota, USA), respects your privacy and is committed to minimum-necessary data collection. This Privacy Policy explains what we collect, how we use it, and your rights. It applies to merchants who install the App from the Shopify App Store and visitors to the public SKU Surf website.
1. What We Collect
Shop data (collected via Shopify OAuth):
- Your shop domain (e.g.,
yourshop.myshopify.com) - Your product catalog: product titles, handles, prices, vendors, product types, status, and associated identifiers (SKU, barcode where available)
- Access token issued by Shopify for our read-only catalog access
Shopify account and store-owner information:
- Shopify makes store-owner contact and location information available to installed apps, including name, email address, phone number, and physical addresses
- On installation, SKU Surf saves the shop email supplied by Shopify as the initial price-alert recipient. An authorized merchant can change that recipient in the App.
- We do not routinely persist the other contact fields as part of product monitoring, although they can be processed transiently during authentication or an authorized support diagnostic.
Merchant-provided data (collected when you use the App):
- Competitor URLs you add to the App for tracking
- Preferences you configure (alert-recipient email, alert thresholds, MAP rules, monitoring cadence)
Scraped data (collected from third-party public sites on your behalf):
- Competitor product prices, availability, and titles from publicly accessible URLs that you have added to the App
- Historical price data for Amazon ASINs via Keepa API (where applicable)
Operational data:
- Timestamps of your activity in the App
- Error logs and diagnostic information needed to operate the service
- Per-shop crawl-request counts and reserved-cost totals used to enforce your
usage safeguards, plus a non-identifying monthly global count/cost aggregate
used to enforce the service-wide safety cap
- Pseudonymous HMAC identifiers, trial status, usage reservations, and deletion
receipts used to prevent reinstalling from resetting a consumed trial or paid
usage limits and to prevent deleted backup data from being restored
Optional public-website analytics:
- The public SKU Surf website asks before loading Google Analytics
- If you allow analytics, Google Analytics can process page location, referring
page, device/browser information, interaction events, and approximate
geographic information derived from the network request
- This website measurement is kept separate from Shopify catalog, billing, and
store-owner data by purpose and reporting dimensions
- Your choice is stored locally in your browser and can be cleared through your
browser's site-data controls
Coverage requests before installation:
- When you request a coverage check, we collect the email address, store URL,
product URLs, and competitor URLs you submit so we can evaluate coverage and
reply about that request. This does not enroll you in marketing emails.
- Requests are delivered to the operator's email inbox using our email
transport. Do not include passwords, access tokens, customer information,
or confidential information in the form or URLs.
- Short-lived necessary cookies protect the form and show a receipt. They
expire after two hours. The application logs a request reference and
delivery status, without logging the submitted form fields.
- If you arrive through a recognized campaign link, the form displays that
campaign label and includes it with your submitted request. We do not store
it in a tracking cookie or include advertising click IDs or arbitrary URL
parameters in the request email. A campaign label is not verified click attribution.
- Optional analytics can record that a request was accepted, without the
submitted email address, store URL, product URLs, or competitor URLs.
- Coverage correspondence is retained in the operator's mailbox to handle
the request and related support. You can request deletion through
support@skusurf.com. Shopify uninstall webhooks do not delete correspondence
sent before installation.
2. What We Do NOT Collect
We explicitly do not collect the following, because we do not need it for the App to function:
- Your end customers' personal data. We do not access
read_customers,read_orders, or any other scope that exposes customer PII from your Shopify store. - Payment card information. All billing flows through Shopify's Billing API. We never see or store your payment information.
- Competitor customer data. We scrape publicly displayed product pricing, not customer-facing account or transaction data.
- Unrelated Shopify store resources. Beyond the baseline Shopify account and store-owner information described above, we request only the
read_productsOAuth scope. We do not request customer, order, fulfillment, theme, or write access.
3. How We Use Your Data
- Operate the App: to display competitor pricing alongside your product catalog, generate alerts when competitor prices change, and power competitor URL discovery. Discovery queries sent to Perplexity can contain product-title terms, vendor/brand, product type, and a strong product identifier such as SKU, barcode, GTIN, model, or style code when available.
- Service operation and troubleshooting: to monitor the scraper's health, debug errors, and ensure the App works correctly.
- Billing: Shopify Billing handles charges; we only reference your shop domain to link billing state to your account.
- Optional website measurement: if you consent, to understand which public
SKU Surf pages are visited and whether visitors continue to the Shopify App
Store. The website does not load Google Analytics if you choose "Only
necessary."
We do NOT:
- Sell your data to third parties
- Pool your catalog data across merchants to create aggregate datasets we sell or redistribute
- Use your data to train or improve AI models (Shopify's February 27, 2026 Partner Program Agreement update explicitly requires written consent for this; we do not have or seek such consent)
- Share your data with advertisers or marketing partners
4. Lawful Bases for EEA and UK Processing
If EU or UK data-protection law applies, we rely on the following lawful bases
for the purposes described in this Policy:
- Performance of a contract: where necessary to provide the App, authenticate
an installation, monitor the products and URLs you select, deliver requested
alerts, and administer the subscription. Where the merchant contract is with
an organization rather than the individual whose data is processed, we rely
on legitimate interests instead where appropriate.
- Legitimate interests: to secure and troubleshoot the service; prevent
fraud, repeated-trial abuse, and unauthorized usage or cost-limit resets;
enforce proportionate service-wide and per-shop safeguards; and maintain
reliable deletion and backup controls. We minimize the data used for these
purposes and retain pseudonymous controls only for the periods described
below. You may object to this processing, and we will assess the request
against our compelling grounds and legal duties.
- Legal obligation: where processing is necessary to comply with applicable
privacy, security, tax, accounting, or other legal requirements, including
handling legally required data-access or deletion requests delivered through
Shopify compliance webhooks.
- Consent: only when we specifically ask for consent for an optional purpose.
Consent is not the catch-all basis for providing the core service, security
controls, or routine international transfers, and it may be withdrawn for the
future at any time.
5. Third-Party Processors
To operate the App, we share limited data with the following service providers:
| Provider | What they process | Purpose |
|---|---|---|
| Shopify Inc. | OAuth token, shop domain, store-owner/account information, billing | Platform integration, authentication, billing |
| Supabase | Shop catalog, competitor URLs, settings, encrypted access tokens, and pseudonymous entitlement/deletion controls | Database storage |
| Render | Application requests and responses, shop domain, product/competitor data processed by the App, and operational logs retained for no more than 30 days | Application hosting |
| Proton Mail / configured SMTP provider | Alert-recipient addresses, merchant price-alert messages, and signed pseudonymous deletion receipts | Alert delivery and off-database deletion evidence |
| Hetzner Cloud | Scraping requests (competitor URLs only — no Shopify data) | Scraper infrastructure in the United States |
| Smartproxy/Decodo or Bright Data | Competitor URLs passed to proxy | Scraping proxy infrastructure |
| Keepa | Amazon ASINs (public identifiers, no Shopify data) | Historical price data |
| Perplexity | Product-title terms, vendor/brand, product type, and strong product identifiers such as SKU, barcode, GTIN, model, or style code when available | Competitor URL discovery |
| Google Analytics | Public website page, referrer, device/browser, interaction, and approximate-location data after opt-in | Optional public website measurement |
Perplexity requests do not intentionally include the Shopify shop domain,
store-owner contact information, or end-customer data. Vendor/brand terms can,
however, identify the merchant or product source, so these queries are not
described as anonymized.
Provider handling is governed by the applicable service terms and data-processing terms available for each service. We configure each provider to receive only the data needed for its function.
6. Data Retention and Deletion
During your subscription: We retain your data as long as you're actively using the App.
Upon uninstall: Shopify fires the shop/redact webhook 48 hours after uninstall. Within 30 days of receiving this webhook, we delete:
- All rows in our database associated with your shop domain
- Any cached scraping results for competitor URLs you monitored
- Authentication tokens and session information
- Your shop-scoped crawl-budget ledger
Deletion is performed transactionally across the shop-scoped records. A purge
is not acknowledged as complete unless its pseudonymous deletion receipt has
first been accepted by our off-database mail channel and recorded for
idempotent retries.
Encrypted disaster-recovery archives are isolated from the live service and
kept for no more than 30 days. A separate pseudonymous, authenticated deletion
ledger prevents deleted shop data from being reintroduced during any restore.
At the archive deadline we remove all retained copies and destroy the relevant
backup-encryption key after its last archive expires. Backup archives are not
used for analytics, marketing, or ordinary account access.
We retain a monthly service-wide crawl count and reserved-cost total that
contains no shop domain, URL, product, payload, or other merchant identifier.
It exists only to prevent deletion from reopening the service-wide spend cap
and cannot be used to identify your shop.
To prevent repeated free trials, paid-provider budget resets, and accidental
reintroduction of deleted backups, we retain HMAC-pseudonymous entitlement,
monthly usage, and deletion-receipt records for up to 24 months after the most
recent relevant event. These records contain no raw shop domain, catalog,
competitor URL, contact detail, access token, or message payload and are not
used for marketing or cross-merchant analytics.
Render application logs can contain request metadata and shop identifiers and
are retained for no more than 30 days. Database diagnostic runs are removed on
shop deletion and are separately subject to bounded operational retention.
Authentication identities are deleted only when they are explicitly classified
as merchant-owned and have no remaining shop links. Operator, shared, and
unclassified administrative identities are retained for manual review rather
than being deleted based only on an email-domain guess.
Customer data: Not applicable — we do not collect end-customer PII, so we have nothing to delete when Shopify fires customers/data_request or customers/redact webhooks. We still acknowledge those webhooks with a 200 OK response and log the receipt.
7. Data Location and International Transfers
- Shopify data: Hosted wherever Shopify's infrastructure dictates (typically multiple regions globally).
- Our database (Supabase): Primary region is in the United States (subject to Supabase's infrastructure).
- Application hosting (Render): United States.
- Scraper infrastructure (Hetzner): United States (the live server reported Hetzner availability zone
ash-dc1, Ashburn, on 2026-07-10). - Scraping proxy providers: Global (traffic routed through proxy IPs in multiple regions for scraping effectiveness).
When an international transfer safeguard is required, we use an applicable
legal transfer mechanism available for the relevant provider and transfer,
such as an adequacy decision, the European Commission's Standard Contractual
Clauses, or the applicable UK transfer addendum/agreement, together with
supplementary measures where required. We do not treat ordinary installation or
use of the App as blanket consent to international transfers. Contact us for
information about the safeguard applicable to a particular provider.
8. Your Rights (GDPR / CCPA / Similar)
If you are in a jurisdiction with data-protection laws (GDPR, CCPA, etc.), you have the following rights:
- Access: Request a copy of the data we hold about your shop
- Correction: Request correction of inaccurate data
- Deletion: Request deletion of your data (this happens automatically on uninstall via
shop/redact) - Portability: Request an export of your data in a machine-readable format
- Objection: Object to specific processing activities
To exercise any of these rights, email us at the address below. We respond within 30 days.
9. Security
We use industry-standard security practices:
- All connections use TLS/HTTPS
- Shopify access and refresh tokens are encrypted at rest and protected by row-level security
- Scraper service is protected by a bearer-token authentication header
- Regular security patching of underlying infrastructure
No system is perfectly secure. If you believe there has been a security incident affecting your data, contact us immediately at the email below.
10. Children
The App is not directed at children under 16 and we do not knowingly collect data from them. If you believe we have collected data from a child, contact us and we will delete it.
11. Changes to This Policy
We may update this Privacy Policy as the App evolves or as regulations change. Material changes will be announced via the App's dashboard and/or by email to the contact on file at Shopify. The "Last updated" date at the top reflects the most recent material change.
12. Contact
For privacy questions, data requests, or to exercise your rights:
- Privacy email: support@skusurf.com
- Operator: Raj Patel, sole proprietor (Minneapolis, Minnesota, USA)
13. Private SKU Surf Operations Monitor
SKU Surf Operations Monitor is a separate, owner-only operations tool. It is not
offered as a Gmail integration to Shopify merchants, and installing the Shopify
app does not grant it access to a merchant's Gmail account.
With the operator's explicit Google authorization, this tool uses the Gmail
read-only scope to read messages and metadata in the operator's authorized
mailbox. Its purpose is to identify SKU Surf vendor incidents, support requests,
security notices, billing obligations, and deadlines. Gmail push notifications
are delivered through Google Cloud Pub/Sub to the operator's local OpenClaw
runtime. Relevant email content may be processed by the configured OpenAI
assistant service for operational analysis. Email content is untrusted evidence,
not authorization to send messages, make purchases, or change account security.
The Gmail integration cannot send, delete, archive, label, or mark messages read.
Operational evidence, message identifiers, incident records, and runtime logs may
be retained on the operator's workstation until the operator removes them.
Credentials are stored in restricted local credential storage and are not
included in public reports. Access can be revoked through the Google Account's
third-party connections settings; locally retained records must be removed
separately if deletion is wanted.
SKU Surf does not sell Google user data, use it for advertising, or use it to
develop or train generalized AI models. SKU Surf Operations Monitor's use and
transfer of information received from Google APIs will adhere to the
Google API Services User Data Policy,
including the Limited Use requirements. Contact support@skusurf.com about this
private integration or its locally retained operational records.
By installing SKU Surf on your Shopify store, you acknowledge that you have read, understood, and agreed to this Privacy Policy.