Privacy Policy
Checkout Field Auditor · Last updated: August 30, 2026
This Privacy Policy describes how ByteSize Studio LLC (“we,” “us,” or “our”) collects, uses, and protects information in connection with the Checkout Field Auditor application (the “App”) that we make available through the Shopify App Store. By installing or using the App, you agree to the practices described in this policy.
1. Who this policy covers
This policy is written for the Shopify merchants who install the App (“you” or the “Merchant”). The App is a merchant productivity tool. It does not collect, store, or process personal information belonging to your customers (buyers).
2. Information we access and collect
When you install the App, Shopify asks you to approve the data the App can access. The App accesses and uses only the following:
- Store profile and configuration (read-only). To generate an audit, the App reads store settings through the Shopify Admin API, including your .myshopify.com domain, your primary storefront domain, customer-account settings (such as whether login is required at checkout), the digital wallets enabled in your payment settings, tax-inclusion and shipping-tax settings, and published refund and contact policies. The App also reads the current App subscription status to determine which plan features to enable. With your approval, the App reads selected files from the published storefront theme and available checkout-and-accounts configuration metadata to produce evidence-based suggestions. This information is used at request time to score your checkout and display the correct features; audit results, theme contents, and checklist confirmations are not stored.
- Public storefront content (read-only). During an audit, the App requests the public homepage and cart page to check for visible policies, contact links, shipping controls, cost-transparency language, trust content, form markup, responsive metadata, and payment-method indicators. The response size and request duration are limited, links found in the page are not followed, and the page content is not stored.
- Authentication and session data. To keep the App securely connected to your store, we store a session record containing your store domain, an access token issued by Shopify, and the granted permission scope. For online sessions, this record may also include the name, email address, and locale of the staff user who authenticated, as provided by Shopify.
The App does not use cookies for tracking, does not run third-party advertising or analytics trackers, and does not collect your customers’ personal data, order data, or payment card information.
3. How we use information
- To authenticate your store and operate the App securely.
- To read your store’s checkout-related settings and produce a checkout audit with prioritized recommendations and clearly labeled automatic, suggested, or merchant-confirmed results.
- To determine which subscription plan is active so we can enable the appropriate features.
- To respond to your support requests.
We do not sell your information, and we do not use it for advertising.
4. How information is stored and protected
The App is hosted on Fly.io. Session data is stored in a database on an encrypted volume, and all communication between your browser, the App, and Shopify occurs over encrypted HTTPS/TLS connections. Access tokens are used only to make authorized Admin API requests on your behalf. We follow reasonable technical and organizational measures designed to protect the information we hold; however, no method of transmission or storage is completely secure.
5. Sharing and third parties
We do not sell or rent information. We share information only with:
- Shopify, whose APIs and platform the App relies on to function.
- Fly.io, our infrastructure provider, which hosts the App and its database.
- Authorities, where required to comply with applicable law, regulation, legal process, or a lawful governmental request.
6. Data retention and deletion
We retain session data only for as long as the App is installed on your store. When you uninstall the App, Shopify sends an app/uninstalled notification and we delete the associated session records. In line with Shopify’s mandatory privacy webhooks, we also honor the shop/redact request Shopify sends approximately 48 hours after uninstall by deleting any remaining data associated with your store. Because the App does not store customer personal data, customers/data_request and customers/redact requests result in no customer data being returned or deleted.
7. Your rights
Depending on your location, you may have rights under laws such as the EU/UK General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA), including the right to access, correct, or delete personal information we hold about you, and the right to withdraw consent. You can exercise the deletion right at any time by uninstalling the App, or by contacting us using the details below.
8. International data transfers
Our infrastructure and Shopify may process and store information in the United States and other countries. Where information is transferred across borders, we take steps to ensure it remains protected consistent with this policy and applicable law.
9. Children’s privacy
The App is a business tool intended for use by merchants and is not directed to children. We do not knowingly collect personal information from children.
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Material changes will be communicated through the App or the Shopify App Store listing where appropriate.
11. Contact us
If you have any questions about this Privacy Policy or our data practices, contact us at contact@bytesizestudio.net.
ByteSize Studio LLC