Merchant data protection terms
Effective August 17, 2026
By installing or using Shopcast, the merchant instructs the app provider identified in the Shopify App Store listing to process data under these terms.
Merchant instructions
Shopcast processes Shopify data only to provide and secure the dashboard features selected by the merchant, comply with law and respond to documented security incidents.
Data minimization
Shopcast intentionally excludes customer names, contact details, street addresses, postal codes and Shopify order identifiers from Apple TV payloads. Protected location data is reduced to the city, region, country and coarse coordinates required for the globe visualization.
Confidentiality and access
Production access is limited to authorized personnel who need it to operate or secure the service. Access to protected data is logged without copying protected values into the log.
Security controls
Shopcast uses HTTPS, tenant isolation, server-side Shopify tokens encrypted with AES-256-GCM, revocable device credentials, request validation, webhook HMAC verification, rate limiting, bounded request bodies and retention enforcement.
Deletion and return
Uninstalling revokes Shopify and device access and removes uploaded logo overrides and short-lived sales events. Valid Shopify redaction webhooks delete remaining store records. Legal or security retention exceptions are limited, documented and de-identified where feasible.
Incidents and subprocessors
The operator maintains an incident-response process covering containment, investigation, remediation and required notifications. Infrastructure providers are limited to those needed to operate Shopcast and are subject to applicable contractual safeguards.
Contact
Questions about these terms: shopcast@shopify.com.