This Privacy Policy describes how Jarlix ("we", "us", "our") collects, uses, and protects information when you install or use any of our Shopify apps, collectively referred to as "the App":
- Jarlix Importer — bulk product import from Excel, ODS, CSV, XML files with AI column mapping.
- Jarlix Price Rounder — psychological price rounding across the catalog with bulk modes, scheduler, and rollback.
- Jarlix Improver — AI-driven SEO optimization for Shopify products (meta-title, description, alt-text).
The App provides services to merchants who use Shopify to power their stores ("the Service"). By installing or using any Jarlix app, you agree to the practices described in this policy.
1. Information We Collect
1.1 Information accessed via Shopify APIs
When you install one of our apps, we are granted access only to the data necessary for that app to function. Each app uses the minimum scopes required by its features:
-
Jarlix Importer —
write_products,read_products,write_inventory,read_inventory. We read and write product titles, SKUs, prices, descriptions, variants, images, and inventory levels. - Jarlix Price Rounder — write_products, read_products. We read and write product prices and compare-at prices, and access collection/product associations.
- Jarlix Improver — write_products, read_products, and access to product translations where applicable. We read and write meta-titles, meta-descriptions, and image alt-text.
We also access basic store metadata: shop domain, shop name, currency, timezone, primary locale, and the email address registered with the Shopify account, in order to authenticate your session and send transactional emails.
1.2 Information you provide directly
- Account information (your name, email, store URL) when you sign up or contact us.
- Configuration data you enter into the App (e.g., rounding rules, import field mappings, SEO templates).
- Communications you send us via email or support channels.
1.3 Information collected automatically
- Session cookies provided by Shopify's authentication framework, used to keep you signed in to the App.
- Operational logs: timestamps, error traces, feature usage events. These help us debug issues and improve performance.
- Basic technical metadata: IP address, user agent, request headers, used solely for security and abuse prevention.
We do not use third-party advertising cookies, tracking pixels, fingerprinting, or cross-site tracking technologies.
1.4 Information about your customers (buyers)
Our apps operate on product, pricing, and catalog data. They do not require access
to customers, orders, or checkouts scopes, and we do not
collect personal data of your end customers in the normal course of operation.
If a Shopify GDPR webhook delivers customer-related identifiers to us (e.g.,
customers/data_request), we process them strictly to comply with the request and
delete them afterwards.
2. How We Use Your Information
- To provide and operate the Service — performing the actions you initiate (imports, price changes, SEO generation).
- To bill you for usage of paid plans via Shopify Billing (we do not store credit card numbers ourselves).
- To communicate with you — service updates, support replies, security notices.
- To improve the App — diagnose bugs, measure feature usage, plan new functionality.
- To comply with legal obligations and respond to lawful requests from authorities.
We do not sell your personal information. We do not use your data for behavioural advertising or share it with advertisers.
3. Sharing Your Information
We share data only with the limited set of processors required to operate the App:
- Shopify — as the platform on which the App runs.
- Cloud hosting and infrastructure providers — used to run the App's servers, databases, and background queues. Operational data and logs are processed in line with industry-standard security practices.
- AI service providers — for Jarlix Importer's AI column mapping and Jarlix Improver's content generation, anonymized product data (column headers, product titles, descriptions) may be sent to third-party AI providers (e.g., OpenAI). No customer or buyer personal data is sent to AI providers under any circumstance.
- Email and support tools — to send you transactional and support emails.
We may also disclose information to comply with applicable laws, respond to a subpoena, search warrant, or other lawful request, or to protect our rights and the rights of merchants using the App.
4. Shopify GDPR Compliance
All Jarlix apps implement the three mandatory Shopify GDPR webhooks:
-
customers/data_request— when a buyer requests their data, we respond within 30 days with the data we hold (in practice, this is usually empty because we do not collect buyer data). -
customers/redact— we delete any customer-related identifiers we may hold. -
shop/redact— within 48 hours of an app uninstall, we automatically delete all shop-scoped data. Encrypted backups are purged within 90 days.
5. Data Retention
We retain merchant account and operational data while the App is installed on your store.
Within 48 hours of uninstall, all shop-scoped data is automatically deleted via the
shop/redact webhook. Encrypted backups containing this data are purged within 90 days.
Aggregated and anonymized analytics (which cannot be linked back to a specific store) may be retained indefinitely for product improvement.
6. Your Rights
If you are a resident of the European Economic Area, the United Kingdom, California, or any jurisdiction with similar data protection laws, you have the right to:
- Access the personal information we hold about you;
- Request correction or deletion of your personal information;
- Object to or restrict processing;
- Withdraw consent at any time;
- Lodge a complaint with a supervisory authority.
To exercise any of these rights, contact us at the email below.
7. International Data Transfers
Our hosting and AI providers may process data outside the European Economic Area, including in the United States. Where this happens, we rely on appropriate safeguards, such as Standard Contractual Clauses or equivalent mechanisms, to protect your information.
8. Security
We use industry-standard practices to protect your information: encryption in transit (TLS), encryption at rest where supported, role-based access control, and the principle of least privilege. Shopify access tokens are stored encrypted in our session database. We do not store credit card data — all billing is handled by Shopify Billing.
9. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations, or for other operational reasons. The updated policy will be posted on this page with a revised "Last updated" date. Material changes will be communicated to active merchants by email.
10. Contact Us
For questions about this Privacy Policy, to exercise your data rights, or to file a complaint, contact us at: