Privacy Policy — bevdata.io

Last updated: July 23, 2026

bevdata.io ("the App", "we", "us", "our") is operated from New Zealand. This policy explains what data the App accesses and stores when a merchant installs it on their Shopify store, and how we handle it.

Who this applies to

This policy covers data handling for merchants who install the App on their Shopify store. The App is a merchant-facing tool — it is not a customer-facing storefront app, and it has no direct interaction with your store's customers.

What we access via Shopify's API

The App requests only the read_products and read_inventory access scopes. Through these, we read:

We do not request or access customer personal data of any kind — no customer names, emails, addresses, phone numbers, order history, payment details, browsing behavior, or IP addresses. We do not request the read_customers, read_orders, or any write-level access scopes.

What we collect directly (not via the API)

When you use the App's admin screen, you choose which of your store's existing metafields correspond to a fixed set of canonical attributes (bottle size, vintage, alcohol %, acidity, pH, residual sugar). This mapping is your own configuration choice, not personal data, and is stored so the App can apply it to future exports.

The App has no customer-facing form, widget, or checkout extension of any kind, and collects nothing directly from your store's customers.

How we use this data

We use the data described above solely to build a periodic export of your store's product and pricing catalog, and to give you a permanent link that only you control. You decide who you share that link with and for what purpose — if you choose to share it with a third party, that party's use of your data is governed by your agreement with them, not by us; we are not responsible for how you choose to share your data. We ourselves do not use your data for advertising, profiling, or any purpose beyond providing you this export.

Where data is stored, and who else touches it

Data is hosted on Amazon Web Services (AWS), in the Asia Pacific (Sydney, Australia) region. If your store operates outside Australia, this means your catalog data is processed and stored outside your home country. Access is protected by encryption in transit (TLS) and at rest; your Shopify access token is encrypted before storage and is never stored or logged in plaintext.

The only third parties involved in processing your data are AWS (hosting and storage) and Let's Encrypt (TLS certificate issuance for our domain). We do not use any analytics, advertising, or tracking services, and we do not sell, rent, or share your data with any other third party.

How long we keep data

We do not retain any exported catalog/pricing data for longer than 30 days. Every export is automatically and permanently deleted from our storage after 30 days, whether or not the App remains installed on your store. If you uninstall the App, we stop syncing immediately; your store record (including your encrypted access token) is deleted from our database once Shopify sends us the mandatory shop/redact notification.

Your rights and mandatory compliance

As required of every app distributed through the Shopify App Store, we subscribe to Shopify's mandatory compliance webhooks (customers/data_request, customers/redact, and shop/redact). Because we never access or store customer personal data, requests under customers/data_request and customers/redact have nothing to provide or erase on our side — Shopify itself holds that data. We comply with applicable data protection laws, including the GDPR and the CCPA/CPRA, to the extent they apply to our processing activities.

If you have a question about your data or want to request its deletion ahead of the 30-day automatic expiry, contact us at the address below.

Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

Contact

For any privacy questions, reach us at bevdata.io@gmail.com.