Blog SEO Toolkit

Privacy Policy

Effective date: 2026-06-10 · Last updated: 2026-06-10

1. Introduction

This Privacy Policy describes how Blog SEO Toolkit ("we", "us", or "our") collects, uses, and protects information when you install or use the Blog SEO Toolkit application ("App") on your Shopify store. The App is provided to merchants through the Shopify App Store and operates as an embedded application within the Shopify Admin.

By installing or using the App, you agree to the collection and use of information in accordance with this policy. If you do not agree, please uninstall the App.

2. Who this policy applies to

This policy applies to merchants (store owners and staff) who install and use the App in the Shopify Admin. The App is designed for merchants to manage blog SEO settings, table-of-contents display, and store-wide internal linking rules.

The App is not intended to collect personal information directly from your store's customers (buyers). We do not operate a customer-facing account or marketing database for end consumers.

3. Information we collect

When you install and use the App, we may collect and process the following information:

  • Shop and account information: your Shopify store domain (myshopify.com address), OAuth access tokens, granted API scopes, subscription/plan status, and installation/uninstallation timestamps.
  • App configuration data: internal link rules (keywords, target URLs, priorities), global TOC settings, and related preferences you configure in the App.
  • Content metadata: article identifiers and SEO-related metadata synced or cached to support App features (for example, article titles, handles, excerpts, and SEO metafield values associated with blog articles).
  • Shopify metafields: the App writes configuration and SEO-related data to Shopify metafields on your shop and articles using Shopify's APIs, as described in the App documentation.
  • Transient storefront content: when internal linking is processed via the App Proxy, article HTML may be transmitted to our servers temporarily for keyword replacement. This content is processed in memory for the request and is not stored as a permanent customer content archive.
  • Technical and operational logs: webhook delivery records, error logs, initialization status, and similar diagnostic information needed to operate and secure the App.
  • Billing information: subscription status is managed through Shopify's Billing API. We do not collect or store your payment card details.

4. How we use information

We use the information described above to:

  • Provide, maintain, and improve App features (TOC, SEO metafields, internal links).
  • Authenticate your store and communicate with Shopify APIs on your behalf.
  • Sync configuration to your storefront theme extension and shop metafields.
  • Process subscription billing through Shopify.
  • Respond to support requests and troubleshoot errors.
  • Comply with legal obligations and Shopify Partner Program requirements.

We do not sell merchant data. We do not use merchant data for unrelated advertising or cross-app profiling.

5. Legal bases (EEA/UK merchants)

Where applicable data protection laws require a legal basis, we process merchant data based on: (a) performance of our contract with you (providing the App); (b) our legitimate interests in securing and improving the App; and (c) compliance with legal obligations. Where required, we rely on your instructions as the data controller for any personal data you process through your store.

6. Data sharing and subprocessors

We may share information with:

  • Shopify: as the platform through which the App is installed, authenticated, billed, and integrated with your store.
  • Hosting and infrastructure providers: to host the App, database, and logs (for example, cloud hosting services where the App is deployed).
  • Professional advisers or authorities: when required by law or to protect rights, safety, and security.

We require service providers to handle data only for authorized purposes and with appropriate safeguards.

7. Data retention

We retain merchant and App configuration data for as long as the App is installed on your store and as needed to provide the service.

When you uninstall the App, we mark your shop record for deletion after a grace period (currently 7 days) to allow recovery from accidental uninstalls. After that period, or upon receipt of a valid shop/redact compliance webhook from Shopify, we delete associated App data from our systems, including rules, caches, logs tied to your shop, and session records.

Data stored in Shopify (metafields, theme app extension settings) remains in your Shopify account according to Shopify's policies until you remove it.

8. Customer data and GDPR webhooks

The App does not intentionally collect or store personal information about your customers. If Shopify sends mandatory compliance webhooks related to customer data requests or erasure, we respond as required by Shopify's policies:

  • customers/data_request: we acknowledge the request; we do not maintain a separate customer profile database.
  • customers/redact: we acknowledge the request; no additional customer records are stored by the App beyond what Shopify provides.
  • shop/redact: we delete remaining App data associated with your shop.

As the merchant, you remain responsible for privacy notices and lawful processing of your customers' personal data on your storefront.

9. Security

We use industry-standard measures to protect data, including HTTPS/TLS for data in transit, access controls, and Shopify OAuth/session mechanisms. No method of transmission or storage is 100% secure; we cannot guarantee absolute security.

10. International transfers

Your information may be processed in countries other than your own, including where our servers or service providers are located. Where required, we implement appropriate safeguards for cross-border transfers.

11. Your rights

Depending on your location, you may have rights to access, correct, delete, or restrict processing of your personal data, or to object to certain processing. To exercise these rights, contact us using the details below. You may also uninstall the App at any time from your Shopify Admin.

12. Children's privacy

The App is a business tool for merchants and is not directed to children under 16 (or the applicable age in your jurisdiction).

13. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Material changes may also be communicated through the App or Shopify where appropriate.

14. Contact us

If you have questions about this Privacy Policy or our data practices, contact:

Blog SEO Toolkit
Email: zornz0316@gmail.com