Legal
Privacy Policy
Last updated: July 21, 2026
At TagStorm, we take your privacy seriously. This Privacy Policy explains how we collect, use, and protect information when you use our Shopify app and this website. TagStorm is developed by Techra doo (the same company behind AdsLink Offline).
Information we collect
Shop and account data
When you install TagStorm we process:
- Shop domain and installation metadata
- Billing / plan state (Free or Pro) and usage meters
- Job history metadata (status, counts, timestamps, tag names)
- Shopify authentication tokens required to call Admin APIs on your behalf (stored as secrets; see Data security)
Operational tagging data
To filter, preview, mutate, audit, and undo jobs we process Shopify resource identifiers and tag values. Pre-change snapshots store {id, tags} only — not customer name, email, phone, or address. Audit CSVs list resource IDs, tags before/after, status, and error messages.
Protected customer data (PCD)
When merchants configure filters that need them, and only after Shopify approves the relevant Protected Customer Data access, we may read fields such as name, email, phone, or address through authenticated Shopify APIs. Core tagging works on Level 1 scopes alone; Level 2 fields are requested with per-field justification. We do not sell PCD or use it for advertising.
Usage and diagnostics
- App installation and feature usage patterns
- Error logs and performance metrics
- Standard website server logs (IP, user agent, path) for security and reliability — no advertising trackers on marketing pages
How we use information
We use this information solely to:
- Operate bulk tagging, dry-run preview, undo, and audit download
- Meter billing and enforce plan allowances / ceilings
- Improve reliability and diagnose failures
- Provide technical support
- Meet Shopify mandatory compliance obligations (GDPR webhooks)
We do not use this information for third-party advertising or sell it to marketers.
Data security
All interactions use encrypted HTTPS. Data is encrypted in transit (TLS). Production databases use encryption at rest at the infrastructure level. Shopify access and refresh tokens are treated as secrets: they are not written to application logs, and we apply industry-standard controls to limit who and what can read them. Test and production environments are separated.
Shopify integration
When you use TagStorm:
- Catalog and customer records remain in Shopify; we access them only through authenticated Admin API / Bulk Operations calls
- We store only the operational artifacts needed to run jobs (session tokens, job rows, snapshots, audits, usage charges)
- We do not share your Shopify data with advertisers or unrelated third parties — only subprocessors required to host and operate the service (for example cloud hosting and database providers)
Data retention
- Job snapshots, audit files, and related artifacts are retained for a bounded window (approximately 30 days) to support undo and support requests, then purged
- Shop and billing records are kept while the app is installed and as needed for accounting / compliance after uninstall
- You can request deletion of retained operational data via support; we also honor Shopify's mandatory GDPR webhooks (below)
GDPR and Shopify mandatory webhooks
We implement Shopify's mandatory compliance webhooks with HMAC verification (invalid signatures receive HTTP 401):
- customers/data_request — summarize personal data we hold for the requested customer
- customers/redact — purge that customer's data, including snapshot/error rows that reference them, within the required SLA (up to 30 days)
- shop/redact — purge shop data after uninstall within the required SLA (within 48 hours)
Your rights
Depending on your jurisdiction, you may have the right to:
- Request access to or deletion of data we hold about you
- Ask questions about our processing
Contact support@tagstorm.app or use Support. Merchants should also use Shopify Admin privacy tools for store-level customer requests.
Changes to this policy
We may update this Privacy Policy from time to time. Material changes may be communicated via in-app notice, email, and/or this page. Continued use after changes constitutes acceptance of the updated policy.
Contact us
Questions about this Privacy Policy or our data practices:
This privacy policy applies to TagStorm for Shopify. By using our app, you agree to the collection and use of information in accordance with this policy.