Manage Product Notes Logo Manage Product Notes
Privacy Policy Effective: 23 Aug 2026
Overview Data We Collect How We Use It Storage & Security GDPR / CCPA Retention & Deletion Sub-processors Policy Changes Contact
Legal · Data Protection

Privacy Policy for
Manage Product Notes

This policy explains, in plain terms, what information the Manage Product Notes app collects from merchants who install it, how that information is used and stored, and the rights available to shop owners and their customers under GDPR and CCPA.

Developer: Md Al Amin Islam Scope used: write_products Customer PII stored: None

Pinned for merchants

  • Zero customer PII. We never collect storefront visitor or shopper personal data.
  • Notes live in Shopify metafields. Your product note content stays inside your store's own data, under the $app:notes namespace.
  • Full webhook compliance. customers/data_request, customers/redact, and shop/redact are all supported automatically.
  • Clean uninstall. Shop data is deleted from our database once your store uninstalls the app.
01

Introduction & Overview

Manage Product Notes ("the App", "we", "us") is a Shopify application developed by Md Al Amin Islam that allows merchants to create internal notes, visible only to store staff, and customer-facing notes, displayed directly on storefront product pages. Notes can be applied to individual products, collections, or product tags, given a priority level, pinned for quick access, or built from a saved template.

This Privacy Policy describes what data the App collects when a merchant installs it, why that data is needed, how it is stored and protected, and how merchants and their customers can request access to, or deletion of, their data. It applies to every store that installs Manage Product Notes from the Shopify App Store.

By installing the App, a merchant agrees to the collection and use of information as described here, alongside Shopify's own Privacy Policy and Terms of Service, which govern the underlying platform.

02

Information We Collect

We separate what we collect into two distinct categories: information about the merchant's shop, and information contained in the notes the merchant creates. We do not collect information about the merchant's customers.

A. Merchant / Shop Data

When a store installs the App and completes Shopify OAuth, we receive and store the following shop-level information in order to authenticate requests and operate the App:

Data pointPurpose
Store domain (*.myshopify.com)Uniquely identifies the shop and authenticates API requests
Shop nameDisplayed inside the App's admin interface
Contact emailAccount communication and support
Country, currency, timezoneCorrect formatting of dates, currency, and note scheduling within the App
Shopify access tokenSecure, authenticated communication with the Shopify Admin API

B. Product Data & Note Content

To provide its core functionality, the App reads and writes the following through the write_products scope:

  • Product IDs and product titles, used to associate notes with the correct product, collection, or tag
  • Note content: title, description, visibility (internal or customer-facing), priority, and pinned status

Note content is written directly into Shopify Product Metafields under the app-reserved namespace $app:notes. This means note data is stored as part of the merchant's own Shopify store data, not in a separate, App-owned content database.

C. Customer (Shopper) Data

We do not collect, store, or track any personal data belonging to a merchant's customers or storefront visitors. This includes names, email addresses, physical addresses, payment details, order history, browsing behavior, or any other personally identifiable information. Customer-facing notes are static content configured by the merchant — they are not personalized to, or triggered by, any individual visitor.

D. Data We Do Not Collect

The App does not request scopes for, and never accesses, customer records, order data, payment information, or any financial details processed by Shopify.

03

How We Use Collected Information

Information described in Section 2 is used strictly to operate, maintain, and support the App:

  • Authentication & App functionality — maintaining a secure session between the App and the merchant's Shopify Admin
  • Rendering notes — reading and writing note content to and from product metafields so notes appear correctly in the admin and, where applicable, on the storefront
  • Localization — using shop country, currency, and timezone to display dates and formats correctly
  • Customer support — using the shop's contact email to respond to support requests
  • Compliance — responding to Shopify's mandatory privacy webhooks and legal data requests

We do not sell, rent, or share merchant or shop data with third parties for marketing purposes. We do not use collected data to build advertising profiles, and the App contains no advertising or marketing trackers of any kind.

04

Data Storage & Metafield Security

The App uses two distinct, complementary storage locations:

  • Shopify Metafields — All note content (titles, descriptions, visibility, priority, pinned status) is stored inside Shopify's own infrastructure, under the reserved $app:notes namespace. This data is scoped to the App and is removed automatically by Shopify when the App is uninstalled.
  • Application Database — Shop-level records (store domain, shop name, contact email, country, currency, timezone, and access token) are stored in a PostgreSQL database, hosted on Railway, secured with encrypted connections and access controls limited to the App's own backend services.
All data in transit between the App, Shopify, and our database is encrypted via HTTPS/TLS. Access to the production database is restricted to the App's authenticated backend and is not exposed publicly.
05

Customer Privacy & GDPR / CCPA Compliance

Because the App does not collect personal data from storefront customers, there is no shopper-level personal data for us to process under the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA).

For the limited merchant data we do process (Section 2A), we recognize the following rights for merchants, consistent with GDPR and CCPA:

  • Right to access — request a copy of the shop data we hold
  • Right to rectification — request correction of inaccurate shop data
  • Right to erasure — request deletion of shop data, including via app uninstall
  • Right to restrict or object to processing — where applicable under local law

Requests can be made at any time via the contact details in Section 9, and will be handled within the timeframe required by applicable law.

GDPR aware CCPA aware No shopper PII collected
06

Data Retention & Deletion (Shopify Webhooks)

The App implements Shopify's three mandatory GDPR webhooks, which are triggered automatically by Shopify and require no manual action from the merchant:

WebhookWhat happens
customers/data_request Logged and acknowledged. As the App holds no customer personal data, there is no shopper record to return.
customers/redact Logged and acknowledged. No shopper personal data exists in our systems to redact.
shop/redact All shop-level records (Section 2A) are permanently deleted from our PostgreSQL database, typically within 48 hours of receipt, and no later than 30 days as required by Shopify.

Note content stored in Shopify metafields is owned by the merchant's store and is handled according to Shopify's own metafield lifecycle — it is removed when the associated product is deleted, or cleaned up automatically upon app uninstallation.

Shop records are retained only for as long as the App remains installed, plus any short grace period required to process the shop/redact webhook. We do not retain shop data indefinitely or for purposes unrelated to operating the App.

07

Third-Party Services & Sub-processors

The App relies on a small number of infrastructure providers to operate:

ProviderRole
ShopifyCore platform, Admin API, metafield storage, OAuth authentication
Railway (PostgreSQL hosting)Hosts the App's application database (shop-level records only)

We do not use third-party advertising networks, analytics trackers, or marketing pixels. The App does not set marketing or advertising cookies; it relies solely on Shopify's secure session authentication tokens to keep merchants signed in to the Admin interface.

Should the App add further sub-processors in the future, this section will be updated accordingly and merchants notified per Section 8.

08

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in the App's functionality, data practices, or legal requirements. Material changes will be reflected by updating the "Effective" date at the top of this page. We encourage merchants to review this page periodically.

Continued use of the App after a change becomes effective constitutes acceptance of the revised policy.

09

Contact Information

Questions about this Privacy Policy, or requests relating to data access, correction, or deletion, can be directed to:

DeveloperMd Al Amin Islam
AppManage Product Notes
Emailmdalamin212104@gmail.com
WebSitemdalamin.site

We aim to respond to all privacy-related inquiries within a reasonable timeframe, and no later than required by applicable data protection law.