Last updated: July 23, 2026
bevdata.io ("the App", "we", "us", "our") is operated from New Zealand. This policy explains what data the App accesses and stores when a merchant installs it on their Shopify store, and how we handle it.
This policy covers data handling for merchants who install the App on their Shopify store. The App is a merchant-facing tool — it is not a customer-facing storefront app, and it has no direct interaction with your store's customers.
The App requests only the read_products and
read_inventory access scopes. Through these, we read:
We do not request or access customer personal data of
any kind — no customer names, emails, addresses, phone numbers, order
history, payment details, browsing behavior, or IP addresses. We do not
request the read_customers, read_orders, or any
write-level access scopes.
When you use the App's admin screen, you choose which of your store's existing metafields correspond to a fixed set of canonical attributes (bottle size, vintage, alcohol %, acidity, pH, residual sugar). This mapping is your own configuration choice, not personal data, and is stored so the App can apply it to future exports.
The App has no customer-facing form, widget, or checkout extension of any kind, and collects nothing directly from your store's customers.
We use the data described above solely to build a periodic export of your store's product and pricing catalog, and to give you a permanent link that only you control. You decide who you share that link with and for what purpose — if you choose to share it with a third party, that party's use of your data is governed by your agreement with them, not by us; we are not responsible for how you choose to share your data. We ourselves do not use your data for advertising, profiling, or any purpose beyond providing you this export.
Data is hosted on Amazon Web Services (AWS), in the Asia Pacific (Sydney, Australia) region. If your store operates outside Australia, this means your catalog data is processed and stored outside your home country. Access is protected by encryption in transit (TLS) and at rest; your Shopify access token is encrypted before storage and is never stored or logged in plaintext.
The only third parties involved in processing your data are AWS (hosting and storage) and Let's Encrypt (TLS certificate issuance for our domain). We do not use any analytics, advertising, or tracking services, and we do not sell, rent, or share your data with any other third party.
We do not retain any exported catalog/pricing data for longer than
30 days. Every export is automatically and permanently
deleted from our storage after 30 days, whether or not the App remains
installed on your store. If you uninstall the App, we stop syncing
immediately; your store record (including your encrypted access token)
is deleted from our database once Shopify sends us the mandatory
shop/redact notification.
As required of every app distributed through the Shopify App Store,
we subscribe to Shopify's mandatory compliance webhooks
(customers/data_request, customers/redact, and
shop/redact). Because we never access or store customer
personal data, requests under customers/data_request and
customers/redact have nothing to provide or erase on our
side — Shopify itself holds that data. We comply with applicable data
protection laws, including the GDPR and the CCPA/CPRA, to the extent
they apply to our processing activities.
If you have a question about your data or want to request its deletion ahead of the 30-day automatic expiry, contact us at the address below.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
For any privacy questions, reach us at bevdata.io@gmail.com.