
Last updated:
Privacy policy
This policy explains how Tdev Scripts ("we", "us") processes information when you use Audit Rise, our Shopify product auditing and AI editing app, or contact us for support.
Privacy contact: tardif.92320@gmail.com
1. Information we process
- Store and account information. Store domain and identifiers, installation status, access permissions, encrypted Shopify session information, subscription details, and usage counters. Shopify sessions may include information about the authorized staff member.
- Catalog information. Product and collection titles, descriptions, tags, SEO fields, image URLs and alt text, variants, prices, inventory, and store website information.
- Performance information. Order line-item information is used to calculate product-level sales and revenue totals. We also use aggregate checkout counts when available. These audit queries do not request customer names, email addresses, shipping addresses, or payment-card details.
- Audit and AI information. Findings, scores, recommendations, prompts you provide, text drafts, before-and-after content, original and generated image drafts, approval history, and AI usage information.
- Support information. Your name, email address, store domain, selected plan, and the message you submit. Please do not include passwords, API keys, customer lists, or sensitive personal information in support messages or AI prompts.
- Technical information. Request and error logs, job status, timestamps, browser or device information available in requests, and security records. App audit logs use a hash of the request IP address; hosting providers may process the original IP address.
Shopify may send event notifications containing additional data. The app stores event identifiers, status, and a payload hash rather than a full copy of those event payloads.
2. How and why we use information
We use information to connect your store, analyze products, generate requested suggestions and image edits, apply changes you approve, manage plan allowances, answer support requests, prevent abuse, and troubleshoot the service. Shopify handles subscription payment collection; Audit Rise does not collect payment-card numbers.
Where data protection law requires a legal basis, we rely on performing our agreement with you for the service, our legitimate interests in support and security, and applicable legal obligations. If a particular optional use requires consent, you may withdraw that consent.
For store data processed on a merchant's instructions, the merchant determines the purposes of that processing. Tdev Scripts manages its own support, account administration, and security records. We do not sell personal information or use it for targeted advertising.
3. AI and service providers
- Shopify: store authentication, authorized catalog access, subscriptions, and publishing the changes you approve.
- OpenAI: relevant product and store context, your instructions, and product images are sent for AI analysis, drafting, image editing, and safety checks when those features run in OpenAI mode. Do not put information in prompts that you do not want sent to this provider. Template mode does not use OpenAI for its template scans or text drafts; AI image editing requires OpenAI mode.
- Railway and hosting infrastructure: application hosting, databases, background jobs, and operational logs.
- Resend and Google/Gmail: delivery and handling of support emails, including the contact details and message you submit.
- Sentry, when enabled: error diagnostics and technical context to help investigate failures.
Providers process information under their own applicable service terms and data handling arrangements. Sending an AI request is not a promise of zero retention by the AI provider. Providers may process information outside your country, including in the United States. Contact us for information about applicable processing locations and transfer safeguards.
We may also disclose information when required by law or necessary to protect the service and the rights or safety of its users.
4. Retention and deletion
Completed webhook delivery records are eligible for deletion 30 days after processing. Technical audit logs are eligible after 90 days, and completed privacy-request records 90 days after completion. Our background cleanup runs at startup and every six hours; temporary service interruptions may delay deletion. Unresolved privacy requests are retained until they have been addressed.
Saved catalog snapshots, product audit history, text and image drafts, billing records, and usage counters support the installed service and do not have automatic expiry under this cleanup schedule. Uninstalling removes Shopify sessions when its notification is processed. An authenticated Shopify shop/redact notification deletes the app-held shop record and related database records. Verified deletion requests can also be sent to our privacy contact.
Support email, infrastructure logs, and backups are separate from the app database. Their retention depends on support needs, security investigations, provider settings, and any applicable legal obligations. Contact us to request deletion or ask about a particular record. Where information must be retained for legal reasons, we will explain the applicable restriction.
Uninstalling or deleting app records does not undo edits already approved and published to Shopify. Those product fields and images remain in your store until you change or remove them.
5. Security and browser storage
The app uses HTTPS, encrypted Shopify session storage, authenticated store access, and request protections. No online system can guarantee absolute security.
Shopify authentication may use cookies or similar storage. Audit Rise uses browser local storage to remember tutorial dismissal. The app does not add advertising trackers to your storefront. Shopify and infrastructure services have their own privacy practices.
6. Your choices and rights
You can review AI drafts before publishing, change available AI settings, and uninstall the app to revoke its access. Depending on your location and applicable law, you may request access, correction, deletion, restriction, portability, or object to processing. You may also complain to your local data protection authority, such as the CNIL in France.
Send privacy requests to tardif.92320@gmail.com. Include your store domain and the nature of your request, not your password. We may need to verify your authority to act for the store. Store customers should normally contact the merchant first; we assist merchants with requests about data processed on their behalf.
7. Changes to this policy
We may update this policy as the app or its data practices change. The date above identifies the latest version. Where required, we will provide additional notice of material changes.