Merchant data protection terms

Effective August 17, 2026

By installing or using Shopcast, the merchant instructs the app provider identified in the Shopify App Store listing to process data under these terms.

Merchant instructions

Shopcast processes Shopify data only to provide and secure the dashboard features selected by the merchant, comply with law and respond to documented security incidents.

Data minimization

Shopcast intentionally excludes customer names, contact details, street addresses, postal codes and Shopify order identifiers from Apple TV payloads. Protected location data is reduced to the city, region, country and coarse coordinates required for the globe visualization.

Confidentiality and access

Production access is limited to authorized personnel who need it to operate or secure the service. Access to protected data is logged without copying protected values into the log.

Security controls

Shopcast uses HTTPS, tenant isolation, server-side Shopify tokens encrypted with AES-256-GCM, revocable device credentials, request validation, webhook HMAC verification, rate limiting, bounded request bodies and retention enforcement.

Deletion and return

Uninstalling revokes Shopify and device access and removes uploaded logo overrides and short-lived sales events. Valid Shopify redaction webhooks delete remaining store records. Legal or security retention exceptions are limited, documented and de-identified where feasible.

Incidents and subprocessors

The operator maintains an incident-response process covering containment, investigation, remediation and required notifications. Infrastructure providers are limited to those needed to operate Shopcast and are subject to applicable contractual safeguards.

Contact

Questions about these terms: shopcast@shopify.com.

Privacy · Data protection terms