Data Protection
Last updated: 1 August 2026
This page sets out the technical and organisational measures we apply to merchant data, and serves as our data processing summary for merchants who need one for their own compliance records.
Roles
The merchant is the controller. Ignite Apps is the processor, acting only on the merchant's documented instructions.
Categories of data
No customer personal data. The app reads product content and writes review metafields and image files.
Purpose of processing
Product copy is the input to review generation; files hold the generated author images.
Protected customer data
This app requests no customer or order scopes, so no protected customer data is accessed. Scopes granted: write_products, write_files.
Security measures
- TLS in transit; access tokens encrypted at rest.
- HMAC-verified OAuth callbacks and webhooks.
- Least-privilege scopes — we request only what the app needs.
Retention and deletion
- The shop domain and an encrypted offline access token, plus a credit ledger and usage log.
- On uninstall and on the shop/redact webhook, which purges the shop's rows.
GDPR / CCPA compliance webhooks
We implement all three of Shopify's mandatory compliance webhooks. Each request is verified with an HMAC signature and an unsigned or mis-signed request is rejected with HTTP 401.
customers/data_request— responds with the customer data we hold.customers/redact— erases the named customer's data.shop/redact— erases the store's stored connection and all associated records.
Sub-processors
Cloudflare (compute, storage, DNS).
Contact
Data protection enquiries: support@ignitehk.org.