Privacy policy
Last updated: 6 June 2026
This translation is provided for convenience. The French version of this policy is the authoritative one and prevails in case of any discrepancy.
1. Data controller
The data controller is Mathis Fedeli, publisher of ShopAudit, the e-commerce audit app for Shopify stores. ShopAudit analyses a store's public storefront (SEO, performance, visuals, checkout journey) and returns a report of recommendations to the merchant.
For any question about this policy or about your data, you can contact the data controller at mathis.fedeli83@gmail.com (the postal address is provided on request at that address).
2. Data we process
ShopAudit only processes the data needed to carry out the audit:
- Store data: domain name, URL, and product catalogue data (titles, descriptions, prices, stock, SEO metadata, image alt text) obtained through the Shopify Admin API with your explicit authorisation.
- Public storefront content: crawled pages of your store (HTML, images, performance) as a visitor would see them.
- OAuth session: access token and store identifier, to maintain the secure connection to your store.
- Sales aggregated by size (Merchandising module, optional): to spot unsellable products, we read order lines through the Admin API β only the quantity, the variant's size option and the product type. We access no data identifying the buyer (name, email, address, payment). Processing is transient: only aggregates (units sold per size) are kept β never an individual order or customer record.
We never identify your customers (buyers): no name, no email, no address, no payment method. The Merchandising module uses order lines, but only to derive sales statistics per size β never linking a sale to a person.
3. Purposes and legal bases
Each processing activity rests on a legal basis within the meaning of Article 6 GDPR:
- Providing the audit service (generating scores, issues and recommendations; applying the 1-click fixes you confirm) β legal basis: performance of the contract between you and ShopAudit (Art. 6(1)(b)).
- Security and correct operation (authentication, abuse prevention, technical logs) β legal basis: legitimate interest (Art. 6(1)(f)).
- Service improvement (aggregated, anonymised statistics) β legal basis: legitimate interest (Art. 6(1)(f)). No data is ever resold.
4. Processors and data location
We neither sell nor rent your data. It may be processed by technical sub-processors strictly necessary to run the service, each covered by a data processing agreement (DPA):
- Anthropic, PBC (Claude models) β AI analysis of your storefront's pages and images to produce the diagnostic. Location: United States. The content sent is not used to train the models.
- Infrastructure host β secure storage of audit reports and screenshots. Location: European Union (EU data centre).
- Shopify Inc. β provider of the platform and the Admin API, as well as billing (Shopify Billing).
5. Transfers outside the European Union
The AI analysis involves transferring storefront content to Anthropic, in the United States. That transfer is covered by the European Commission's Standard Contractual Clauses, ensuring an adequate level of protection in line with Chapter V GDPR. On the Free plan (no AI), no content is transferred outside the European Union.
6. Retention and deletion
Audit reports are kept for as long as the app is installed, so that you have a history. In line with Shopify's requirements and the GDPR:
- On uninstall, your OAuth session is deleted immediately.
- Within 48 hours of uninstall, all of your store's data (audits, issues, screenshots, tracked competitors) is permanently erased through the
shop/redactwebhook. - You may request deletion of your data at any time by writing to mathis.fedeli83@gmail.com.
7. Your rights
Under the GDPR you have rights of access, rectification, erasure, restriction, objection and portability over your data. To exercise them, contact us at mathis.fedeli83@gmail.com. We reply within one month.
If, after contacting us, you believe your rights are not being respected, you have the right to lodge a complaint with the competent supervisory authority. ShopAudit's publisher is established in France, where that authority is the CNIL (Commission Nationale de l'Informatique et des LibertΓ©s) β www.cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07. You may also lodge a complaint with the supervisory authority of your own country of residence.
8. Cookies
ShopAudit uses neither advertising cookies nor third-party trackers. Only cookies strictly necessary to run the embedded app (secure Shopify session) are used; they are exempt from consent under the CNIL's guidance.
9. Security
Traffic is encrypted over HTTPS. Access tokens are stored securely and are never exposed client-side. Access to your store is limited to the permissions you grant (catalogue read, and write only for the fixes you confirm).
10. Changes
We may update this policy. The date of the last update appears at the top of the page. In case of a substantial change, we will inform you inside the app.
ShopAudit β Contact : mathis.fedeli83@gmail.com Β· Terms of service