meridian
SupportContactExplore the demo
LEGAL

Privacy policy

This policy explains what Meridian collects when a Shopify merchant installs or uses the app, why we use it, and the choices available to merchants and individuals.

Last updated 15 July 2026
ScopeInformation collectedHow we use itService providersRetentionSecurityYour rightsContact
This policy describes Meridian’s current product implementation. We do not sell personal information or use store data for advertising.

1. Scope

This policy applies to the Meridian Shopify app, the Meridian website, product demonstrations, and support communications. “Merchant” means the Shopify store owner or authorised team member who installs or uses Meridian.

2. Information we collect

Information from Shopify

When authorised by a merchant, Meridian reads only the store information needed to provide the service:

  • Shop identity and configuration: store name, myshopify.com domain, currency, timezone, installation session, granted scopes, and an access token protected in the production datastore.
  • Product catalogue information: product and variant identifiers, titles, descriptions, handles, status, vendor, product type, tags, options, prices, inventory, media metadata, and update dates.
  • Level 1 order information from the previous 60 days: order identifiers and dates, currency, store totals, quantities, discounts, and product and variant identifiers attached to line items. Meridian compares the latest 30 days with the previous 30 days and aggregates this evidence by product and store before persistence.
  • Anonymous product-funnel events after analytics consent: product viewed, added to cart, checkout started, and checkout completed, with an opaque session ID, event time, product and variant IDs, quantity, shop-currency amount where relevant, and the actual analytics-consent state. We do not use IP addresses, device fingerprints, arbitrary URLs, checkout tokens, or identity stitching for this funnel.

Meridian does not request or store Shopify customer IDs, customer names, postal or billing addresses, phone numbers, email addresses, payment information, or shipping and billing records. It does not create advertising audiences or sell data.

Information you provide

We may collect a merchant or authorised team member’s name, work email, store domain, support messages, structured action feedback, product facts, brand voice, and other information deliberately supplied through the app or support. Do not include customer personal information in these fields.

Technical information

We process Shopify and operator session records, bounded application events, timestamps, job and error categories, and security audit data needed to authenticate users, prevent abuse, diagnose faults, and operate the service. Infrastructure providers may process request IP addresses and basic request metadata for transport security; Meridian does not persist these in its product analytics or anonymous funnel tables. Raw webhook bodies, rejected funnel bodies, access tokens, and pixel tokens are not written to application logs.

3. How we use information

  • Authenticate the merchant and maintain the installed Shopify app.
  • Scan the catalogue and calculate deterministic catalogue, commercial, and product-funnel findings.
  • Prioritise and prepare reviewable, catalogue-grounded merchandising actions.
  • Compare merchant-approved interventions with later store performance.
  • Enforce consent, retention, rate limits, access controls, and uninstall revocation.
  • Respond to support, prevent abuse, investigate incidents, maintain reliability, meet legal obligations, and enforce our terms.

AI processing boundary

When optional AI reasoning is available, Meridian sends OpenAI a minimised structured commercial summary: aggregate 30-day comparison metrics, bounded catalogue findings, product IDs and titles, product-level aggregate order and funnel evidence, confirmed product facts, and explicit missing-evidence labels. Meridian does not send customer identity, raw orders, raw funnel events, anonymous session IDs, access tokens, pixel tokens, payment data, addresses, or merchant support messages. AI requests use a one-way safety identifier and are submitted with API storage disabled. AI output can recommend a reviewable investigation; it cannot autonomously change Shopify data.

4. Service providers and disclosure

We disclose information only as needed to operate Meridian, comply with law, protect rights and security, or complete a business transaction with appropriate safeguards. Current core subprocessors are:

  • Shopify, for the commerce platform, merchant authentication, APIs, mandatory privacy webhooks, and consent-controlled Web Pixels runtime.
  • Render, for application hosting, managed PostgreSQL, scheduled retention and observation jobs, and operational logs. Meridian’s application and primary database are deployed in Singapore.
  • OpenAI, for optional structured AI reasoning on the minimised inputs described above.
  • Clerk, for authentication of Meridian’s restricted internal operator surface. Shopify merchant authentication remains separate.
  • Vercel, for the public Meridian website; merchant store datasets are not hosted in the website deployment.

Providers may process information in Singapore, Australia, the United States, or other countries where they and their subprocessors operate. We use provider data-processing terms and security safeguards for international transfers where required. We do not sell personal information, share store data with data brokers, or use it for third-party targeted advertising.

5. Retention and deletion

  • Raw accepted anonymous funnel events and opaque session IDs are hard-deleted 30 days after the event time.
  • Daily product-funnel aggregates and reconciliation records are hard-deleted after 25 months.
  • Compliance delivery receipts are retained for no more than 25 months and contain only a delivery ID, topic, bounded outcome, and processing time—never the webhook body, customer identity, shop domain, Shopify shop ID, or another reversible store identifier.
  • Catalogue scans, action records, product profiles, measurements, schedules, jobs, alerts, store-level analytics, and Shopify sessions are kept while the app is installed and are deleted for that store when Shopify sends the mandatory shop-redaction webhook.

When an uninstall webhook arrives, Meridian immediately deactivates scheduled collection, revokes the installation generation used by the pixel, and deletes Shopify sessions and access tokens. Shopify normally sends shop redaction 48 hours after uninstall; Meridian’s handler permanently deletes every remaining store-scoped application record when received and is designed to complete well inside Shopify’s 30-day limit. Customer data-access and redaction webhooks are recorded as no-ops because Meridian holds no customer-identifiable record to export, reconstruct, or delete.

Render-managed recovery backups can retain a deleted database state for up to seven days. Meridian does not maintain independent long-term database exports. A deleted record is not returned to the live service from a backup except when strictly necessary for incident recovery; if a recovery restores deleted data, the deletion procedure is rerun before normal processing resumes.

Merchants may request export or deletion of Meridian data by emailing info@meridiancommerce.io from an address associated with the store and including the myshopify.com domain. We verify authority, respond directly to the merchant, and explain any legally required retention.

6. Security and incident response

Connections to Meridian use HTTPS/TLS. Production data is stored in Render’s managed PostgreSQL service with provider-managed encryption at rest. Shopify and pixel tokens remain server-side or in the Shopify pixel setting required for authenticated delivery; Meridian never places secrets in public documentation or analytics. Access scopes are minimised, writes require merchant review, and production operator access is isolated from merchant sessions by a dedicated hostname, separate identity provider, exact email allowlist, no-store responses, and audited fail-closed authorisation.

Production access is limited to authorised operators who need it for deployment, support, security, or incident response. Access is revoked when no longer needed and sensitive values are kept in provider secret stores. We review application and provider logs without intentionally logging raw webhooks, funnel payloads, customer personal information, access tokens, or pixel tokens.

For a suspected incident we contain access, revoke sessions and credentials, preserve bounded evidence, assess affected data and stores, correct the cause, restore safely, rerun required deletions and retention, and notify affected merchants and regulators when required. Security reports can be sent to info@meridiancommerce.io. No internet service can guarantee absolute security.

7. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing of your personal information, or receive a portable copy. You may also complain to your local privacy regulator. To make a request, contact us using the details below. We may need to verify your identity and authority over the relevant store.

8. Changes to this policy

We may update this policy as Meridian changes. The current version and effective date will always appear on this page. Material changes will be communicated through the app or by email where appropriate.

9. Contact

Meridian Privacy

For privacy questions, complaints, access requests, or deletion requests:

info@meridiancommerce.io

Australia

© 2026 Meridian
PrivacyTermsSupportContact