1. Scope
This policy explains what data the Shopify apps published by MAY Plugins process when you install them on your store, and how we handle it. It applies to every MAY Plugins app, worldwide, including the EU/EEA (GDPR/AVG) and California (CCPA).
Each app also has a short annex describing exactly what that specific app reads. The annex forms part of this policy:
2. What we collect
Across our apps, we may process:
- Store identifiers: your
myshopify.comdomain and the Shopify-issued access token used to connect to your store. - Store operational data: the specific records the app needs to do its job. See the app’s annex for the exact list.
- Settings you provide: such as alert thresholds, notification email addresses, and your plan.
- Third-party accounts you choose to connect: where an app offers an optional connection to an outside service and you connect it, we store the access credentials for that connection — encrypted at rest — together with the data that service returns to us. This is never required to use an app, nothing is stored until you connect, and disconnecting or uninstalling revokes our access and deletes what we stored. See the app’s annex for which service, exactly what is held, and how to disconnect.
- Operational logs: technical logs needed to run, secure and debug the service.
We do not collect your customers’ personal data unless an app’s annex explicitly says otherwise. Our apps never read customer names, emails, addresses, orders, or payment information.
3. Why we process it (legal basis)
- To provide the service you asked for (performance of a contract).
- To send you alerts and notifications at the address you configure (your instruction).
- To maintain and secure the service (legitimate interest).
We do not sell your data, and we do not use it for advertising. We do not use your store data to train AI models.
4. Subprocessors
We share the minimum necessary with the following providers. Each processes data only to provide their service to us, under contract — with one exception we have named in the table rather than left to a footnote: Google, which you connect yourself and which receives data from us only while a setting you control is switched on. Which company processes your data is a disclosure we keep current, not an implementation detail — this list is updated whenever a subprocessor changes; see an app’s annex for exactly which step each one performs.
| Subprocessor | Purpose | Used by |
|---|---|---|
| Shopify | The platform your store runs on, and the source of the store data our apps read. | All apps |
| Railway | Hosting and database for our applications (EU West / Amsterdam). | All apps |
| Brevo | Delivery of transactional email (alerts, notifications) and our mailing list. | Our website mailing list, and any app that sends email. ProductReady sends none. |
| OpenAI | Writes generated product copy; checks generated claims against your product data before they’re shown to you; suggests a Shopify category, product tags and type, and — if you switch it on — a shipping weight; and checks your product text for sentences that try to give our AI instructions, so that those sentences can be left out of what it is shown; adapts approved copy into your store’s other published languages; and repairs malformed AI output before it reaches you. | ProductReady only. |
| Only if you connect a Google account, and what it receives depends on a setting you control. By default the connection reads: we ask Google which Merchant Center accounts your login can see, and what Google says about the items in the one you pick. While you have sending corrections switched on, Google also receives the Google Shopping title and description you have already reviewed and applied in the app, for the products you send — one such pair per language your feed carries and your store publishes. See Services you connect yourself below. | ProductReady only, and only if you connect it yourself. |
We will update this list before adding a new subprocessor that processes your data.
Services you connect yourself
An app may offer an optional connection to an account you already hold somewhere else. That is not like the rest of the table above, and we describe it separately so the distinction is not blurred: a subprocessor is a company we send your data to so it can do a job for us, whereas here you give us permission to read your own account and we read from it. Nothing is stored until you connect, you grant us the access, and we hold a credential — which is why it is named here and not only in an app’s annex. One of these connections can also be switched, by you, into sending data back to that account; that is why Google appears in the table above as well.
Google — ProductReady only, optional, and nothing happens until you connect it. ProductReady can show you what Google Merchant Center already says about your products.
- What we read. Which Merchant Center accounts your Google login can see, and — for the one account you pick — what Google itself reports about the items in it.
- What we send, and only if you switch it on. While sending corrections is off — which is where every store starts — nothing reaches Google: no product data, no generated copy, no feed. ProductReady has one setting, “Let ProductReady send corrections to Merchant Center”, that is off until you turn it on. With it on, Google receives the Google Shopping title and description you have already reviewed and applied in the app — for a product you press Send to Google on, or, if you also switch on the second setting beside it, one you apply — together with the offer ID, feed label and content language Google itself gave us for that item. If your store publishes more than one language, that is one such pair per language — your feed can carry the same product once per language, and we send a correction for each of those languages your store itself publishes: the primary one from the copy you applied, every other one from the Shopify translation you approved for it. We never send a language your store does not publish, and outside your primary language we skip any language where either field is missing rather than send a mixture of your copy and ours. A translation you approved before later editing your primary copy is sent as you last approved it, describing that earlier version; the app names those languages on the product page and tells you that regenerating them is what brings them up to date. Nothing else about that product travels with them, nothing from the AI steps does, and no customer data ever does. We never upload or submit a feed file and never change or delete the values your own feed carries: the corrections go into a separate data source we add to your Merchant Center account and link into your feed ahead of your own values, so yours are added to rather than replaced, and every correction is reversible. The ProductReady annex sets this out in full.
- What we hold. So that we can read without asking you to sign in again, we store a Google refresh token and a short-lived access token, both encrypted at rest, together with what Google returned. That is data we hold about you, which is why it is named here and not only in the app’s annex.
- Google’s consent screen will say “manage”, and we use far less than that. Google publishes no read-only permission for this data — the single permission that reaches it is one Google describes as “Manage your product listings and accounts for Google Shopping”. So Google will ask you to grant more than we use: unless you switch sending on, the app only reads, and even switched on it uses a narrow slice of what that permission allows. The app says the same thing on the screen where you connect; we would rather you heard it from us than only from Google.
- How it ends. Disconnecting in the app’s settings, or uninstalling the app, revokes our permission at Google and deletes everything we stored from it — after any corrections we sent have been withdrawn, because once the permission is handed back we can no longer reach your account.
The full detail is in the ProductReady annex.
5. Where data is processed
Our own infrastructure — hosting and database — runs in the EU (Amsterdam, Netherlands). Processing outside the EEA is done by our AI subprocessor, OpenAI, which is US-based, and only for the specific features described in an app’s annex. Separately, if you connect a Google account (section 4), the requests we make go to Google LLC in the US and its answers come back from there: while sending corrections is off we send it no store data, and while you have that setting on, the product title and description described in section 4 are transferred to Google in the US. Where personal data is transferred outside the EEA, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses.
6. Retention and deletion
- We keep your store’s data only while the app is installed.
- When you uninstall, Shopify sends us a
shop/redactrequest (approximately 48 hours later). In response we delete all data we hold for your store. - You can request deletion at any time by uninstalling, or by emailing privacy@mayplugins.com.
- Separately from data we hold: our AI subprocessors may retain the requests we send them for a short period (typically up to 30 days) for abuse-monitoring purposes, under their own published policies, before automatic deletion. This is standard for API providers and is distinct from — and not affected by — our own deletion described above.
7. Your rights
Depending on where you live, you may have the right to access, correct, delete, or export your data, or to object to processing. To exercise any of these, email privacy@mayplugins.com.
If you are in the EU/EEA, you may also lodge a complaint with the Dutch data protection authority, the Autoriteit Persoonsgegevens.
8. Security
We authenticate through Shopify OAuth, so we never see your Shopify password. Data is transmitted over encrypted connections (HTTPS) and access is restricted. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Shopify compliance webhooks
Our apps implement Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact. Where an app stores no customer personal data, a customer data request returns no data; a shop redaction deletes your store’s data.
10. Changes to this policy
We may update this policy. Material changes will be posted here with a new “last updated” date.
11. Contact
MAY Software (MAY Plugins)
Andreas Schelfhoutstraat 50 K, 1058 HV Amsterdam, Netherlands · KVK 91578442 · BTW NL004900880B90
Privacy: privacy@mayplugins.com · Support: support@mayplugins.com