GuardNest ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that monitors a merchant's own store: it probes the storefront the way a shopper would, watches for a flat-line in orders, and records changes to products, collections and themes so the merchant is told when something breaks. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
Contact / Data Protection: support@appnest.studio
1. Who the data belongs to
The App acts as a data processor on behalf of the installing merchant (the data controller). We process the merchant's Shopify store data solely to provide the monitoring the merchant configured.
2. What we access and why
| Scope | Why |
|---|---|
read_products |
Product and collection change events (title, status, published state, prices) for the change history and bulk-change alerts; product handles for storefront probes |
read_themes |
Theme create / update / publish / delete events, and a probe right after a theme is published |
read_inventory |
Negative-inventory alerts |
read_orders |
Flat-line detection only. The orders/create webhook is reduced to an hourly count the moment it arrives. No order ids, amounts, names, addresses, emails or any other field are read, logged or stored. |
Storefront probes request public storefront pages of the merchant's own store (home, a product page, add-to-cart, the checkout page). They add one item to a cart and clear it; they never place an order or enter payment details.
3. What we store
| Data | Stored? | Notes |
|---|---|---|
| Shopify session / access token | Yes | Required to call the Admin API |
| Checks (kind, product handle) and their results (pass/fail, latency, failing step) | Yes | Results kept 7 days |
| Incidents (what broke, when, when it recovered) | Yes | Your monitoring history |
| Change history of products, collections and themes, with the change payload | Yes | 30 / 90 / 365 days by plan. Contains no customer data |
| Orders per hour (a number) | Yes | 35 days. Aggregate only, no order or customer fields |
| Storefront password (password-protected stores only) | Yes | So probes can reach the storefront. Encrypted at rest (AES-256-GCM) with a rotatable key; masked in the UI; deleted on uninstall |
| Alert email / Slack webhook URL | Yes | Where to notify you |
| Order details, customer or payment data | No | Never read beyond the count above |
4. Data retention & deletion
- Configuration and history are retained while the App is installed, within the retention periods above.
- On app uninstall and on the Shopify
shop/redactcompliance webhook, we delete all data for that store. - We honour
customers/redactandcustomers/data_request. Because we hold no customer data, there is nothing to return or erase.
5. Subprocessors / third parties
| Provider | Purpose | Data shared |
|---|---|---|
| Hosting (Railway) + Postgres/Redis | Run the App | Stored data listed in §3 |
| Resend | Alert emails (if configured) | Your alert email + incident summary |
| Slack | Alert messages (if configured) | Your webhook + incident summary |
| Sentry | Error tracking (if configured) | Diagnostic error data |
| Shopify status page (public) | Platform incident notices | Nothing of yours is sent |
We do not sell personal data or use it for advertising.
6. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
7. Security
- All API traffic is over HTTPS. Probes only ever request your store's own primary domain, as reported by Shopify, never a URL typed into a form.
- We store the minimum necessary and no customer data.
8. Your rights
Merchants can export or delete their data by uninstalling the App (triggers full deletion) or by contacting us at the address above. Data subjects should contact the merchant (controller) for GDPR/CCPA requests; we assist the merchant in fulfilling them.
9. Changes
We will update this policy as the App evolves and revise the "Last updated" date above.
GuardNest by AppNest Studio · support@appnest.studio