Privacy Policy
Last updated: 2026-09-22
This policy explains what data the Shopify app Capyo: Dynamic Pricing and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a data controller, and it is not legal advice about the pricing or competition rules that apply to you.
1. Who is responsible
The controller depends on the data. For your relationship with the app — the store record, plan and billing status, and support correspondence — and for this website, the controller is Capyo, operated by an individual developer. For everything the app processes about your shop's catalog, rivals, matches, alerts and price changes, you are the controller and Capyo acts as your processor under the Data Processing Agreement. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.
Operator legal name and address: [to be added]
For the personal data of your customers, you remain the controller. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses, and it requests no Shopify scope that would give it access to them — see section 2 for exactly what it does read and store.
2. Data the app processes
It comes from Shopify when you install the app, from the shop pages Capyo fetches, and from you. In detail:
- Store record. Your
.myshopify.comshop domain, your primary domain and store name, your current plan and when it was last checked, your store's currency and primary locale, the merchant email address the app has for alerts (if any), whether email alerts are enabled, when a trial ends, and setup state: install and uninstall timestamps and when the review prompt was shown. - Sessions. The Shopify access token issued to the app for your store, and the session fields Shopify supplies with it: the shop domain, the Shopify staff user id, first and last name, email address, locale, whether the user is the account owner or a collaborator, and the token's scope, expiry and refresh data. This is the data of the merchant and staff who use the app, not of your customers.
- Your catalog mirror. For each product: its Shopify product id and GID,
title, collection ids, whether it is marked priority, whether it is paused, and the
product's own last-updated time from Shopify. For each variant: its GID, SKU, barcode,
price, compare-at price, inventory unit cost (if one is set) and currency. This is read
through the Admin API with the
read_productsandread_inventoryscopes and refreshed by webhooks and a daily sync. - Rival shops you add. The domain, the platform Capyo detected for it (Shopify, WooCommerce or other), its status, when it was last fetched, its consecutive failure count and whether it is paused. Capyo also keeps the most recent catalog it fetched from each rival — the extracted product titles, URLs, SKUs, barcodes, prices, currencies and availability — so matching and checks can run without re-fetching every shop.
- Matches. Which of your variants Capyo paired with which rival product: the rival product URL, the rival's own product key, how the match was made (barcode, SKU, embeddings or a manual link), its confidence score, its state (pending, confirmed or rejected), the candidate products shown in the confirm queue, and when it was created and decided.
- Rival price observations. An append-only history per match: the observed price, its currency, whether the rival showed it as available, and when it was fetched.
- Rules. The scope you chose (all products, a collection or a product), the action (match the lowest or beat it by a percentage or amount), the direction, the minimum margin percent, whether automatic repricing is on, and whether the rule is active.
- Alerts. The old price, new price and currency, the percent change, whether it was applied and by what (automatic, approved or a manual override), the rule and floor in force, any failure reason, and when the alert was created and read.
- Price changes. Each price the app wrote through the Admin API: the old price, the new price, its source, the related rule and alert, when it was applied, when it was undone, and whether the row was reconstructed after a crash rather than written beside a real API call.
- Job and fetch telemetry. One row per check or sync job: its kind, start and finish time, whether it succeeded and any error text. A row per failed rival fetch: the URL, HTTP status (if any), reason and time. Queued job rows hold the job type and the identifiers it needs (shop, product, variant or rival ids) until the job completes.
- Product-usage events. Shop domain, an event name from a fixed list (install, rival added, catalog synced, match confirmed or rejected, first alert, price applied, undo used, plan changed and similar), non-identifying properties, and a timestamp — no personal data about your customers, used only to see which setup steps merchants get stuck on.
- Operational logs. Error and warning traces from the app's own process: the identifiers a job needs (shop domain, job id, error text) written to the container's rotating log buffer (three 10 MB files). The web server in front of the app is configured to keep no access logs, and no IP address or user agent is written to the database.
- Support correspondence. If you email us, we keep the message and our reply.
Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.
3. How Capyo fetches rival shops
Capyo reads only publicly reachable product pages, through a structured-first path: a
Shopify store's /products.json, the WooCommerce Store API, or a page's JSON-LD.
It sends an identifying user agent, CapyoPriceBot/1.0, including the app's own
address, and it respects the site's robots.txt: a path it is not allowed to
fetch is never fetched. It limits itself to one request per domain every 2 seconds and at
most 20 concurrent fetches across all shops, uses no logins, no captchas, no proxy pools and
no browser automation, and does not try to evade a site's access controls. A shop that
blocks Capyo is stored as blocked, with the reason shown, and is not checked again until you
ask it to be. Capyo stores only the extracted product data described in section 2 — never a
rival's page content as fetched.
4. What we never store
- Your customers' names, email addresses, postal addresses, phone numbers or customer ids.
- Order, checkout or payment data — the app requests no
read_ordersscope and no protected customer data. - IP addresses or user agents in the app's database; the web server keeps no access logs.
- Your theme code — the app does not edit theme files, because it has no storefront component at all.
- Any rival page content beyond the extracted titles, URLs, prices, currencies and availability described in section 2.
Shopify sends every public app the two mandatory customer-privacy webhooks
(customers/data_request and customers/redact). Capyo acknowledges
them; because it holds no customer personal data, there is nothing to return.
5. No storefront output
Capyo has no theme extension, no widget and no web pixel, and it adds no script to your storefront. The only thing it writes to Shopify is a variant price, through the Admin API, when a rule you set says so. Your shoppers never interact with Capyo.
6. This website
This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.
7. Why we process it, and on what legal basis
- To provide the app you installed — mirroring your catalog, fetching the rival shops you added, matching products, running checks, computing suggestions, applying the rules you set, and showing the dashboard, alerts and history. Legal basis: performance of a contract, Art. 6(1)(b) GDPR.
- To bill you through Shopify's Managed Pricing. We read which plan is active; Shopify performs the billing. Legal basis: Art. 6(1)(b) GDPR.
- To keep the service secure and working — queue handling, fetch health, error handling, abuse prevention, and the usage events that show which setup steps fail. Legal basis: legitimate interests, Art. 6(1)(f) GDPR.
- To answer support requests. Legal basis: Art. 6(1)(b) and (f) GDPR.
- To meet legal obligations, including Shopify's mandatory compliance webhooks. Legal basis: Art. 6(1)(c) GDPR.
We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.
8. How long we keep it
- Sessions and queued jobs: deleted immediately when Shopify sends the
app/uninstalledwebhook, and scheduled jobs for your shop are cancelled. - Rival price observations: pruned daily; rows older than 12 months are deleted.
- Fetch errors: pruned daily; rows older than 30 days are deleted.
- Everything else about your shop — store record, catalog mirror, rival
shops and their cached catalogs, matches, rules, alerts, price changes, job telemetry and
usage events: deleted when Shopify sends the
shop/redactwebhook, 48 hours after uninstall, which deletes every row for the shop in every table. A reinstall inside those 48 hours cancels the scheduled deletion. Ask us to delete earlier and we will. - Operational logs: kept only for as long as the container's rotation retains them (three 10 MB files), then overwritten.
- Database backups: taken daily and rotated after 14 days, so a row deleted by uninstall or shop-redact can remain inside a backup until that rotation passes. Backups are used only for disaster recovery, are readable only by the server's root and database accounts, and are never used to restore a deleted shop's data on request.
- Support correspondence: kept up to 24 months, deleted sooner on request.
9. Who else is involved (sub-processors)
| Sub-processor | Company country | What they do | Where the servers are |
|---|---|---|---|
| Shopify International Ltd | Ireland | The platform the app runs on and the source of all store data; also handles billing | Per Shopify's own DPA |
| Hostinger International Ltd | Cyprus | Application hosting — the virtual server the app runs on, including its PostgreSQL connection | Boston, Massachusetts, United States |
| netcup GmbH | Germany | Database hosting — the PostgreSQL database holding everything in section 2 | Manassas, Virginia, United States |
| GitHub, Inc. | United States | Hosting of this website only — no app data reaches it | GitHub Pages global infrastructure |
| OpenAI | United States | Embeddings for the optional semantic matcher — not active today. It is used only when the app is configured with an embeddings key, and it then receives product titles only (from your catalog and from the rival shortlist), never prices, order or customer data. Without a key the matcher falls back to lexical scores and OpenAI receives nothing | United States |
| Resend | United States | Email delivery for alerts — not active today. It starts processing data only once a sending domain is verified and email sending is switched on; until then, alerts stay in the app and Resend receives nothing | United States |
There is no analytics provider, no error-tracking SaaS, no advertising network and no CRM in this list. An optional second scoring model (TypeSafe's Jev) is not active either, and it would be added to this table before it processed anything. We will update this table before any new sub-processor starts processing, including when embeddings or email alerts are switched on.
10. International transfers
Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The optional embeddings calls to OpenAI, and any future alert email through Resend, also involve United States-based processors.
For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 11. The app stores no end-customer personal data, so nothing about your shoppers crosses a border. What does is the store configuration, catalog mirror, rival and match data, price observations and history, alerts, job telemetry and access token described in section 2.
Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.
11. Security
- All traffic to the app and to this website is served over HTTPS/TLS. There is no plaintext endpoint.
- The database is not exposed to the public internet: its firewall accepts PostgreSQL connections only from the application server's IP address, over an encrypted connection with password authentication.
- Shopify access tokens are stored in that database and are never written to logs or shown in the UI.
- Administrative access to the server and the database is limited to the operator, over SSH with key authentication.
- Webhook requests from Shopify are verified by HMAC signature before anything is acted on.
-
The app requests the minimum Shopify scopes it needs:
read_products,write_productsandread_inventory. It requests noread_ordersscope, noread_customersscope and no protected customer data. - Rival fetches are rate-limited, respect
robots.txtand use an identifying user agent, as section 3 describes. - Admin mutations are protected against cross-site requests and webhook routes are rate-limited.
We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.
12. Protected customer data
Capyo requests no Shopify protected customer data. Its scopes are
read_products, write_products and read_inventory. It
never receives customer names, emails, phone numbers or addresses, and it processes no order
data. A future feature that needed protected customer data would only follow a separate
Shopify approval and a change to this policy before it started.
13. Your rights
Under the GDPR you can ask us to:
- confirm what we hold about you and give you a copy (access, Art. 15);
- correct anything inaccurate (rectification, Art. 16);
- delete it (erasure, Art. 17);
- restrict what we do with it (Art. 18);
- hand it over in a machine-readable form, or send it to another provider (portability, Art. 20);
- stop processing based on legitimate interests (objection, Art. 21).
Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app starts the deletion described in section 8. Where a request concerns data the app holds on your instruction as controller, we forward it to you and support you in answering rather than answering on your behalf — that split is set out in the Data Processing Agreement.
You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.
14. Changes to this policy
When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.
15. Contact
gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.