Skip to policy
SpecLeafCatalog Atelier

Data stewardship

Privacy Policy

A plain account of what SpecLeaf reads, what it creates, how long it keeps it and what happens when a merchant uninstalls.

Effective
August 30, 2026
Applies to
SpecLeaf Shopify App

Scope and our role

This Privacy Policy explains how SpecLeaf (“SpecLeaf,” “we,” “us” or “our”), operated by the developer identified in the Shopify App Store listing, handles information when a merchant installs or uses the SpecLeaf Shopify application, related support channels and this website (collectively, the “Service”).

For information a merchant makes available through Shopify, SpecLeaf generally acts as a processor or service provider on the merchant's instructions. The merchant remains responsible for its own privacy notices, legal basis and responses to its customers. We may act as an independent controller for merchant account, billing, security, fraud-prevention and support records.

Information we handle

Installation and merchant account data

When a merchant installs SpecLeaf, Shopify provides the store domain and an OAuth authorization that allows the app to operate. We retain installation status and timestamps, the granted scope, Shopify session credentials and access tokens, and, where Shopify supplies them for an authenticated session, limited user details such as a Shopify user identifier, name, email address, locale and account status. Tokens are used only to authenticate requests to Shopify and are not displayed in the app.

Read-only catalog data

SpecLeaf requests the read_products scope. At a merchant's direction, it reads product and variant titles, descriptions, prices, SKUs, barcodes, vendor, product type, collections, images, options and supported product metafields needed to preview or generate a document. Product identifiers selected for a generation request are temporarily recorded while that job is active. SpecLeaf does not write to the catalog.

SpecLeaf does not request Shopify customer, order, payment, inventory or theme scopes. It does not intentionally retrieve or use those records to create catalogs.

Merchant content and settings

We store the brand kits and saved setups a merchant chooses to create. They can include profile names, colors, uploaded logos, layout and export settings, and optional company details such as a business name, website, email, phone number, address or footer text. Merchants should not place unnecessary personal or sensitive information in these fields.

Generation, usage and billing records

We process document choices and selected product identifiers, create temporary PDF or ZIP files, and record operational details such as job status, format, product and page counts, file size, checksums, timestamps, download counts, processing duration, failure codes and quota usage. We store a merchant's plan, billing interval, trial and subscription status, Shopify subscription identifier and current billing-period dates. Shopify, not SpecLeaf, collects payment card or bank details.

Technical, security and support data

We process request timing, error and security events, limited device or browser information provided in ordinary web requests, support messages, and pseudonymous references used to troubleshoot deliveries. Authentication secrets, authorization headers and webhook bodies are redacted from application logs. We retain limited webhook receipt metadata, such as a delivery identifier, topic, status and timestamps, to prevent duplicate processing; the receipt does not retain the webhook payload.

How we use information

We use information only as reasonably necessary to:

  • authenticate the merchant, connect to Shopify and provide previews, branded catalogs, product sheets and exports;
  • save merchant-selected brand, layout and document preferences;
  • administer plans, enforce export quotas and reconcile subscription status with Shopify;
  • secure, monitor, maintain and improve the reliability of the Service, including preventing abuse and duplicate webhook work;
  • answer support requests and communicate material service or policy changes; and
  • comply with Shopify requirements, applicable law and valid legal process, and protect the rights and safety of merchants, users and SpecLeaf.

Depending on the jurisdiction and our role, these activities are based on performing our contract with the merchant, the merchant's instructions, our legitimate interests in operating a secure service, consent where required, and compliance with legal obligations.

Service providers and disclosures

We do not sell personal information, rent merchant catalog data, or share personal information for cross-context behavioral advertising. We disclose information only as needed to operate the Service, including to:

  • Shopify. SpecLeaf runs on Shopify's platform, uses Shopify authentication and APIs, and uses Shopify's billing flow. Shopify handles information under its own privacy terms.
  • Infrastructure providers. Vendors that provide hosting, managed databases, object storage, queues, monitoring, security and email or support tooling may process information for us under contractual restrictions.
  • Legal and safety recipients. We may disclose information when reasonably necessary to comply with law or valid process, investigate fraud or security incidents, enforce our terms, or protect rights, safety and property.
  • Business transaction recipients. Information may be transferred in a merger, financing, acquisition, reorganization or sale of assets, subject to appropriate confidentiality and this Policy or notice of any material change.

We require service providers to use information only to perform services for SpecLeaf and to apply appropriate security measures.

Retention and deletion

We keep information only for the period needed for the purposes described above, then delete or de-identify it, subject to technical deletion cycles and any legal obligation to preserve a limited record.

  • Generated files. Download access expires after 60 minutes in this deployment. The underlying PDF or ZIP object is then eligible for scheduled deletion. A merchant must download and retain any file it needs; SpecLeaf is not an archival service.
  • Generation requests. Selected product identifiers and detailed request configuration are purged after the first completed export download or when an undownloaded job expires. Limited job summaries, counts, timestamps, quota and billing records may remain while the app is installed and for a reasonable period needed for support, security and accounting.
  • Brand kits and saved setups. These remain until the merchant archives, replaces or removes them, or uninstalls the app. Replaced or removed logo objects are queued for deletion.
  • Webhook receipts. Limited delivery receipt metadata normally expires after 90 days and may be removed sooner as part of shop redaction. Webhook payloads are not stored in those receipts.
  • Uninstallation. Uninstalling immediately removes active sessions, generation jobs, brand kits, saved setups and quota windows from the active tenant. Logo and generated-file objects are queued for deletion. Minimal shop lifecycle, billing-state, webhook-receipt and deletion-outbox data may remain only as needed to authenticate retries and complete deletion.

Backup, security and legal-hold copies, if any, may remain until their normal protection cycles end and are not returned to active use. We may retain a record longer if required by tax, accounting, fraud-prevention or other law, and will limit it to that purpose.

Shopify mandatory privacy webhooks

SpecLeaf subscribes to Shopify's mandatory privacy topics and verifies that each request is authenticated by Shopify before it is processed:

  • customers/data_request — we identify data associated with the requested customer. Because SpecLeaf does not request customer or order scopes, this will ordinarily confirm that no customer commerce record is held; any limited webhook identifiers are used only to process the request.
  • customers/redact — we delete any customer-associated information that the Service is required to remove. SpecLeaf does not use customer data as part of document generation.
  • shop/redact — after a shop uninstalls, this request initiates final redaction of remaining shop records and binary objects. Shopify generally sends this topic 48 hours after uninstallation.

We respond to verified privacy requests within the time required by Shopify and applicable law, ordinarily within 30 days, unless law permits or requires limited continued retention. Merchants remain responsible for communicating with their customers and forwarding any request that does not arrive through Shopify's workflow.

Security and session technologies

SpecLeaf uses administrative, technical and organizational safeguards designed for the nature of the information, including Shopify OAuth, scoped read-only access, authenticated download routes, webhook authentication, access controls, secret and payload redaction, file-expiry controls and deletion workflows. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.

The Service uses Shopify authentication and strictly necessary session technologies to keep a merchant signed in and protect requests. We do not use merchant catalog data to build advertising profiles. Merchants should protect their Shopify account, use appropriate access controls and notify us promptly of suspected unauthorized access.

International processing

Shopify, SpecLeaf and our infrastructure providers may process information in countries other than the merchant's or customer's country. Where required, we use recognized transfer safeguards and contractual protections. Local laws in those countries may differ from those where the information originated.

Rights and choices

Depending on location, an individual may have rights to access, correct, delete, restrict, object to or receive a portable copy of personal information, and to withdraw consent where processing is based on consent. Rights may be limited by law and we may need to verify identity and authority before acting.

A Shopify customer should first contact the merchant from whom they purchased or interacted, because the merchant controls its customer relationship. The merchant may use Shopify's privacy-request workflow, which sends the mandatory webhooks described above. A merchant or authorized representative may contact us at [email protected]. Merchants can remove active app data by archiving profiles and presets or by uninstalling SpecLeaf through Shopify.

Individuals may also complain to their local data-protection authority. We will not discriminate for exercising an applicable privacy right.

Children

SpecLeaf is a business application for Shopify merchants and is not directed to children. We do not knowingly collect personal information directly from children through the Service. If you believe a child has provided information directly to us, contact us so we can review and delete it as appropriate.

Changes to this Policy

We may update this Policy to reflect changes to the Service, Shopify requirements, law or our processing practices. We will post the revised version here with a new effective date and provide additional notice through the app or another appropriate channel when a change is material. Continued use after the effective date is subject to the revised Policy.

Contact

The SpecLeaf developer identified in the Shopify App Store listing is responsible for this Policy. For privacy questions, requests or complaints, email [email protected]. Include the relevant store domain and identify whether you are the merchant, an authorized user or a customer of that merchant.

Questions or requests

Contact SpecLeaf

Include your Shopify store domain and enough detail for us to identify the request. Please do not email passwords, access tokens, payment card information or other sensitive secrets.

[email protected]