Legal

Privacy Policy

Last updated: 23 July 2026  ·  Effective: 23 July 2026

This policy explains what information Shopify Store Auditor collects, how we use it, who we share it with, and the rights and choices you have — including our commitments for data received from Google APIs.

Shopify Store Auditor ("the Service", "we", "us", "our") is operated by Liquid Web Developers and available at shopifystoreauditor.liquidwebdevelopers.com. The Service is an AI-powered web application that analyzes public Shopify storefronts and produces an audit report covering performance, SEO, accessibility, conversion optimization, Core Web Vitals, security and technical best practices. By using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.

1. Information we collect

Account information

When you create an account or sign in — including Sign in with Google — we collect your name, email address and a Google account identifier. If you register with a password, we store only a salted cryptographic hash of it, never the password in plain text.

Audit data

When you run an audit you submit a store URL. Our server-side crawler then fetches publicly available pages of that storefront — HTML, HTTP response headers, status codes and rendered screenshots — to analyze them. We store the resulting audit report, its scores and screenshots so you can revisit and export them.

Google account data

If you connect Google Analytics, we access read-only Google Analytics (GA4) data. See Section 2 for the specific scopes and our Limited Use commitment.

Shopify store data

If you connect a Shopify store, we access store, product, theme and order data. See Section 3.

Usage & device information

To operate the Service, secure it, and enforce fair-usage limits on free audits, we log request metadata such as IP address, approximate geographic location derived from it (country, region, city), browser user-agent, referring URL and timestamps.

2. Google user data & Limited Use

Signing in with Google and connecting Google Analytics use Google OAuth. Depending on what you authorize, we may request the following scopes:

Scope Why we request it
.../auth/userinfo.email, .../auth/userinfo.profile, openid To authenticate you and create your account (your name and email).
.../auth/analytics.readonly Read-only access to your Google Analytics (GA4) data, to enrich your audit report with real traffic and conversion insights (sessions, channels, landing pages, key events). We access only the properties you select, and only while your connection is active.
Google API Services — Limited Use

Shopify Store Auditor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, for all data obtained through Google APIs we affirm that we:

You can revoke our access to your Google data at any time from your Google Account permissions page, or by disconnecting the integration inside the Service.

3. Shopify store data

If you connect a Shopify store, we use Shopify OAuth to access store profile, product, theme and order data (including read access to orders) so we can produce revenue-aware analysis and benchmarks. We access only the stores you authorize, use the data solely to generate your reports, and never sell it. You can revoke access at any time by uninstalling the app from your Shopify admin or disconnecting it in the Service. Your use of Shopify remains subject to Shopify's own terms and privacy policy.

4. How we use information

6. Cookies & similar technologies

We use strictly necessary cookies and similar local-storage technologies to keep you signed in, remember your session, and enforce free-usage limits. We do not use third-party advertising cookies. Because these technologies are essential to the Service's core functionality, they are set when you use the Service; you can clear them through your browser settings, though doing so may affect functionality.

7. How we share information

We do not sell your personal information. We disclose data only in these circumstances:

8. Service providers

We use a small set of trusted providers to run the Service. Categories and purposes:

Category Purpose
Cloud hosting & database Running the application and storing accounts and audit reports.
Object storage Storing rendered storefront screenshots used in your reports.
Email delivery Sending transactional and support email you request (e.g. contact form).
Google PageSpeed Insights Retrieving Core Web Vitals for the audited public URL.

A current list of the specific providers we use is available on request at the contact address below.

9. International data transfers

We and our service providers may process your information in countries other than your own. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (or equivalent mechanisms) to protect your data.

10. Data retention

We retain account and audit data for as long as your account is active or as needed to provide the Service and for legitimate business or legal purposes. Public share links expire automatically 30 days after creation. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where retention is required by law. Disconnecting Google Analytics or a Shopify store revokes our ongoing access to that platform's data.

11. Security

We protect data in transit with HTTPS/TLS, restrict access to production systems on a need-to-know basis, and store OAuth access tokens so they are used only to maintain your own connections and are never exposed to other users. No method of transmission or storage is completely secure, but we work continuously to protect your information and will notify you and the relevant authorities of a breach where required by law.

12. Your rights & choices

Depending on where you live, you may have the right to:

EEA/UK residents (GDPR): you may lodge a complaint with your local data-protection authority.

California residents (CCPA/CPRA): you have the right to know what personal information we collect and how we use it, to request deletion, and to opt out of "sale" or "sharing" of personal information. We do not sell or share your personal information as those terms are defined under California law, and we will not discriminate against you for exercising your rights.

To exercise any right, contact us at support@liquidwebdevelopers.com. We will verify and respond within the time required by applicable law.

13. Children

The Service is intended for businesses and is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after an update takes effect constitutes acceptance of the revised policy.

15. Contact us

For any privacy question, or to exercise your rights, contact the data controller:
Liquid Web Developers · support@liquidwebdevelopers.com
Website: www.liquidwebdevelopers.com