Privacy Policy
Last updated: 18 September 2026
Who we are
Klarshelf ("we", "the app") is operated by Michele Scotellaro. Contact: support@klarshelf.com.
For the data described below we act as a processor on behalf of the merchant who installs the app; the merchant is the controller.
What the app accesses
| Permission | Why |
|---|---|
read_products, write_products | Read product data to audit it; write an approved title metafield or description |
read_translations, write_translations (optional) | Read translation coverage; write approved translations |
read_locales, read_markets | Know which languages and markets the store publishes |
The app does not request access to customers, orders, checkouts or payment data, and therefore never receives them. It does not use Shopify's protected customer data.
What we store
- Store identifiers: the
.myshopify.comdomain, the store's Shopify ID, installation date, plan and usage counters. - Product data: titles, descriptions, product types, categories, vendors, options, variant prices, barcodes, image counts, publication status and existing translations.
- Audit results: the issues found, per product and per language.
- AI proposals: the generated text, the facts the model reported using, quality-check results and the value a field had before a change.
- Change log: what was written to the store, when, and the previous value, so changes can be undone.
- Technical data: Shopify session tokens, webhook identifiers and application logs.
Automated processing with AI
When a merchant asks for proposals, the relevant product text (title, description, product type, category, vendor, options, existing translations) is sent to Anthropic for generation. No store identifiers or personal data are included in that request.
Anthropic processes this data in the United States. Under Anthropic's commercial terms, data sent through the API is not used to train their models. The transfer relies on the data processing terms and standard contractual clauses in Anthropic's commercial agreement.
Proposals are never applied automatically: a merchant reviews and approves each one.
Where data is stored
| Provider | Role | Location |
|---|---|---|
| Render | Application hosting | Frankfurt, Germany (EU) |
| Supabase | PostgreSQL database | Frankfurt, Germany (EU) |
| Anthropic | AI text generation | United States |
| Shopify | Source of the data | Per Shopify's own terms |
How long we keep it
- Data is kept while the app is installed, so audits and the change log stay available.
- When a merchant uninstalls, Shopify sends a shop redaction request (normally 48 hours later). On that request we delete every record belonging to that store: store record, products, audit results, findings, proposals, change log, sessions and webhook records.
- Application logs kept by our hosting provider may contain store domains, but no product or personal data.
Merchant rights
A merchant can at any time see everything the app stores about their store inside the app, undo any change the app made, uninstall the app — which triggers deletion as described above — or ask us at support@klarshelf.com to export or delete their data sooner.
Security
Access to production systems is limited to the operator. Connections to Shopify and to our database are encrypted in transit. Webhook requests are verified with Shopify's HMAC signature and rejected when invalid.
Changes
We update this page when the app changes what it collects, and note the date at the top. Material changes are announced in the app or by email to the store contact.