Skip to policy
SpecLeafCatalog Atelier

Merchant data lifecycle

Data Deletion

The self-service, Shopify-mandated and direct-request paths for removing SpecLeaf data safely and without exposing account secrets.

Updated
August 30, 2026
Applies to
SpecLeaf Shopify App

Merchant deletion options

A merchant can reduce or remove active SpecLeaf data without emailing support. Archive or replace individual Brand Kits and Saved Setups in the app. To end the Shopify connection and begin deletion for the whole store, uninstall SpecLeaf from the Shopify admin.

Before uninstalling, download any document the business must keep. SpecLeaf's generated files are temporary, and uninstalling makes active files unavailable as their objects move through deletion.

What happens after uninstall

When Shopify confirms uninstallation, SpecLeaf:

  • revokes active use of the installation and removes Shopify app sessions stored for the shop;
  • deletes generation jobs, Brand Kits, Saved Setups and quota windows from the active tenant records;
  • cancels the app's active plan state and removes stored subscription identifiers from normal merchant use; and
  • queues uploaded logo objects and generated PDF or ZIP objects for deletion from storage.

A minimal shop lifecycle record, webhook-receipt metadata and deletion-outbox state may remain temporarily so authenticated Shopify retries cannot affect a later reinstall and so object deletion can finish safely. This limited state is not used for catalog production or marketing.

Shopify shop redaction

Shopify generally sends the mandatory shop/redactwebhook 48 hours after a merchant uninstalls an app. SpecLeaf verifies that the request came from Shopify, marks the remaining shop state for redaction, removes directly useful tenant data and completes queued binary-object deletion.

Once pending object deletion is complete, remaining shop lifecycle, webhook-receipt and deletion-outbox records are removed. A delayed or retried webhook associated with an older installation is not permitted to delete a provably newer reinstall.

Generated files and request details

Even while the app remains installed, download access to a generated PDF or ZIP expires after 60 minutes in this deployment. The underlying object is then eligible for scheduled cleanup. Replaced logos are also queued for deletion.

Selected product identifiers and detailed generation configuration are purged after the first successful export download or when an undownloaded generation expires. Limited job summaries, counts, timing, quota and billing records may remain as described in the Privacy Policy until uninstall or the end of their applicable operational, accounting or legal period.

Requests from Shopify customers

SpecLeaf does not request customer or order scopes and does not use customer commerce data to make catalogs. A customer should first contact the Shopify merchant with whom they interacted. The merchant controls that relationship and can start Shopify's privacy workflow.

SpecLeaf subscribes to customers/data_request andcustomers/redact. For a verified request, we identify or remove any information that must be handled. Because no customer or order data is retrieved for document production, the response will ordinarily confirm that SpecLeaf holds no associated customer commerce record. Limited identifiers in the webhook are used only to process and acknowledge the request.

Submit a direct request

A merchant, authorized representative or customer may email [email protected] with the subject “SpecLeaf data deletion.” Include:

  • the relevant .myshopify.com store domain;
  • whether you are the store owner, an authorized staff member, a customer or an authorized representative;
  • the category of information and request you are asking us to review; and
  • a safe method for follow-up from an email address associated with the merchant or original request when possible.

Do not send passwords, OAuth tokens, identity documents, payment information or a full customer export in the first message. We will request only the minimum additional information needed to verify identity and authority. For security, a direct email cannot be used to bypass a merchant or Shopify authorization process.

Timing and limited exceptions

We respond to verified privacy requests within the period required by Shopify and applicable law, ordinarily within 30 days. Binary objects can require additional processing time after a deletion is queued, and protected backups, if any, age out through their normal lifecycle rather than returning to active use.

We may retain a narrowly limited record where required for tax, accounting, fraud prevention, security, legal claims or another legal obligation. We will restrict that record to the permitted purpose and delete it when the obligation ends. We may deny or narrow a request where law permits, and will explain the reason when allowed.

Questions or requests

Contact SpecLeaf

Include your Shopify store domain and enough detail for us to identify the request. Please do not email passwords, access tokens, payment card information or other sensitive secrets.

[email protected]