Effective August 20, 2026
CatalogFix AI processes the shop domain, Shopify product catalog fields, product scan results, detected issues, generated suggestions, applied-change audit records, app usage, billing identifiers, merchant preferences, and limited technical logs needed to operate and secure the service. The app does not request customer, order, or payment scopes.
We use this information only to scan product catalogs, generate and apply merchant-approved improvements, enforce plan limits, provide reports, maintain security, troubleshoot failures, and support merchants.
Product context selected for suggestion generation can be processed by OpenAI. Hosting, database, logging, and monitoring providers process data only to operate CatalogFix AI. We do not sell merchant or catalog data.
Catalog records are retained while the app is installed so merchants can review scan history and changes. When Shopify sends a validated shop redaction request, CatalogFix AI deletes the shop record and its associated scans, issues, suggestions, usage, settings, billing references, and audit records. Production operational logs are retained for no longer than 30 days unless a longer period is required for security or legal compliance.
Shopify credentials are encrypted at rest, access is authenticated with Shopify session tokens, and webhook requests are verified using Shopify HMAC signatures. No method of storage or transmission is completely secure.
Merchants can request access, correction, or deletion of applicable information by contacting info@madinamicrosystems.com. Uninstalling the app revokes Shopify access and starts Shopify's standard data-redaction lifecycle.