1. Scope and provider

Craig Technology Services LLC (“CTS,” “we,” “us,” or “our”) provides Product Change Guard. This policy explains the Shopify store data the app processes, why it is used, how long supported history is retained, how deletion works, and how to contact us. Shopify separately controls Shopify Admin, authentication, APIs, webhook delivery, and its platform under Shopify's terms and privacy notices.

2. Data the app processes

Product Change Guard processes the minimum store and product information needed to provide read-only product activity history:

  • The installed shop's Shopify identifier or domain and the authentication session information needed to operate the embedded app.
  • Shopify product identifiers and supported product fields needed to establish product state and identify supported create, update, and delete activity.
  • Product-change event time, event type, and supported before-and-after information used in the app's history and CSV export.
  • A one-way digest of a product description when needed to detect a supported description change. The readable product description body is not retained in change history.

The app requests only Shopify's read_products permission. It does not request customer, order, or product-write access and does not intentionally collect customer records, payment information, or storefront visitor activity.

3. How data is used

The data is used only to establish the product state needed for monitoring, receive and verify supported Shopify product webhooks, display retained product activity to the installed shop, create a merchant-requested CSV export, authenticate the installation, maintain service security, troubleshoot failures, and satisfy Shopify's mandatory privacy workflows.

Product Change Guard does not edit or restore products. CTS does not sell app data or use it for advertising.

4. Webhook verification and service providers

The app verifies Shopify webhook authenticity before accepting supported product or privacy events. Shopify provides the store platform, authentication, APIs, and webhook delivery. Hosting and security service providers used by CTS process app data only as needed to operate and protect the service, subject to their applicable terms.

Access to app data is limited to the installed shop and authorized CTS administration or support activity needed to operate, secure, or troubleshoot the service. No transmission or storage system can be guaranteed completely secure.

5. Retention and deletion

  • Supported product-change history is retained for 90 days, after which it is removed from active app history.
  • The current product state needed for monitoring is retained while the app is installed and the corresponding product remains monitored.
  • Shop data associated with Product Change Guard is deleted when the app is uninstalled.
  • Shopify's mandatory shop/redact webhook is supported and triggers shop-data deletion.
  • Shopify's mandatory customer data request and customer redaction webhooks are supported. Because the app does not request or store Shopify customer records, there are no customer records for the app to return or delete.

Shopify may retry webhook delivery; repeated deletion requests are handled without intentionally recreating deleted shop data.

6. CSV exports

An authorized merchant can export the installed shop's retained product-change history as CSV. Once downloaded, the export is controlled by the merchant and is no longer governed by the app's automatic 90-day retention. Merchants should protect and delete exported files according to their own requirements.

7. Merchant choices and requests

A merchant can stop future app processing by uninstalling Product Change Guard. Privacy, access, correction, or deletion questions may be sent to [email protected]. Identify the Shopify shop domain and the nature of the request, but do not send passwords, access tokens, API secrets, customer records, payment information, or unnecessary sensitive data.

8. Changes to this policy

Material changes will be posted at this URL with an updated effective date. Additional notice will be provided when required by applicable law or Shopify's requirements.

9. Contact

Questions about this policy or suspected security issues can be sent privately to [email protected].