C Capyo
es
Instalar en Shopify

Privacy Policy

Last updated: 2026-09-22

This policy explains what data the Shopify app Capyo: Dynamic Pricing and this website process, why, on what legal basis, and how long it is kept. It is written for the merchant who installs the app. It is not legal advice about your own obligations as a data controller, and it is not legal advice about the pricing or competition rules that apply to you.

1. Who is responsible

The controller depends on the data. For your relationship with the app — the store record, plan and billing status, and support correspondence — and for this website, the controller is Capyo, operated by an individual developer. For everything the app processes about your shop's catalog, rivals, matches, alerts and price changes, you are the controller and Capyo acts as your processor under the Data Processing Agreement. Contact for anything in this document, including all data-protection requests: gimbernat13@gmail.com.

Operator legal name and address: [to be added]

For the personal data of your customers, you remain the controller. Capyo is built to never receive your customers' names, email addresses, phone numbers or physical addresses, and it requests no Shopify scope that would give it access to them — see section 2 for exactly what it does read and store.

2. Data the app processes

It comes from Shopify when you install the app, from the shop pages Capyo fetches, and from you. In detail:

Where any of this is personal data, it is the personal data of you — the merchant and your staff — not of your customers.

3. How Capyo fetches rival shops

Capyo reads only publicly reachable product pages, through a structured-first path: a Shopify store's /products.json, the WooCommerce Store API, or a page's JSON-LD. It sends an identifying user agent, CapyoPriceBot/1.0, including the app's own address, and it respects the site's robots.txt: a path it is not allowed to fetch is never fetched. It limits itself to one request per domain every 2 seconds and at most 20 concurrent fetches across all shops, uses no logins, no captchas, no proxy pools and no browser automation, and does not try to evade a site's access controls. A shop that blocks Capyo is stored as blocked, with the reason shown, and is not checked again until you ask it to be. Capyo stores only the extracted product data described in section 2 — never a rival's page content as fetched.

4. What we never store

Shopify sends every public app the two mandatory customer-privacy webhooks (customers/data_request and customers/redact). Capyo acknowledges them; because it holds no customer personal data, there is nothing to return.

5. No storefront output

Capyo has no theme extension, no widget and no web pixel, and it adds no script to your storefront. The only thing it writes to Shopify is a variant price, through the Admin API, when a rule you set says so. Your shoppers never interact with Capyo.

6. This website

This site is a set of static pages. It sets no cookies, runs no analytics, and contains no tracking pixels, no advertising tags and no embedded third-party content. The typeface is self-hosted rather than loaded from a font CDN. The host of these pages processes the ordinary request data any web server sees, including your IP address, to deliver them.

7. Why we process it, and on what legal basis

We do not use your data for our own advertising, we do not profile you, and we never sell or rent it.

8. How long we keep it

9. Who else is involved (sub-processors)

Sub-processorCompany countryWhat they doWhere the servers are
Shopify International Ltd Ireland The platform the app runs on and the source of all store data; also handles billing Per Shopify's own DPA
Hostinger International Ltd Cyprus Application hosting — the virtual server the app runs on, including its PostgreSQL connection Boston, Massachusetts, United States
netcup GmbH Germany Database hosting — the PostgreSQL database holding everything in section 2 Manassas, Virginia, United States
GitHub, Inc. United States Hosting of this website only — no app data reaches it GitHub Pages global infrastructure
OpenAI United States Embeddings for the optional semantic matcher — not active today. It is used only when the app is configured with an embeddings key, and it then receives product titles only (from your catalog and from the rival shortlist), never prices, order or customer data. Without a key the matcher falls back to lexical scores and OpenAI receives nothing United States
Resend United States Email delivery for alerts — not active today. It starts processing data only once a sending domain is verified and email sending is switched on; until then, alerts stay in the app and Resend receives nothing United States

There is no analytics provider, no error-tracking SaaS, no advertising network and no CRM in this list. An optional second scoring model (TypeSafe's Jev) is not active either, and it would be added to this table before it processed anything. We will update this table before any new sub-processor starts processing, including when embeddings or email alerts are switched on.

10. International transfers

Merchant data processed through the app is stored on servers located in the United States — the application server in Boston, Massachusetts and the PostgreSQL database in Manassas, Virginia. Both are operated for us by European companies (Hostinger International Ltd, Cyprus; netcup GmbH, Germany), but the processing itself happens outside the EEA, which engages Chapter V of the GDPR. The optional embeddings calls to OpenAI, and any future alert email through Resend, also involve United States-based processors.

For those transfers we rely on the Standard Contractual Clauses included in those providers' data processing terms, together with the technical and organisational security measures in section 11. The app stores no end-customer personal data, so nothing about your shoppers crosses a border. What does is the store configuration, catalog mirror, rival and match data, price observations and history, alerts, job telemetry and access token described in section 2.

Hosting locations can change; any change of hosting location or sub-processor is announced in the app and on this page before it takes effect. Shopify may transfer data internationally under its own DPA and transfer mechanisms, which govern the Shopify-to-merchant relationship independently of this policy.

11. Security

We do not claim a formal certification (no ISO 27001, no SOC 2) and we do not claim encryption at rest beyond what the hosting providers apply to their own storage.

12. Protected customer data

Capyo requests no Shopify protected customer data. Its scopes are read_products, write_products and read_inventory. It never receives customer names, emails, phone numbers or addresses, and it processes no order data. A future feature that needed protected customer data would only follow a separate Shopify approval and a change to this policy before it started.

13. Your rights

Under the GDPR you can ask us to:

Email gimbernat13@gmail.com and we will answer within one month. You do not need to justify a request. Uninstalling the app starts the deletion described in section 8. Where a request concerns data the app holds on your instruction as controller, we forward it to you and support you in answering rather than answering on your behalf — that split is set out in the Data Processing Agreement.

You can also complain to a data-protection supervisory authority — normally the one where you live, work, or where you believe the problem occurred.

14. Changes to this policy

When this policy changes, the new version appears on this page with a new date at the top. The version in force is the one published here.

15. Contact

gimbernat13@gmail.com — data-protection requests, security reports and everything else. See also our Terms of Service and the Data Processing Agreement.