Privacy Policy

Last updated: July 1, 2025 · Effective: July 1, 2025

Zikrova ("we," "our," or "us") is committed to protecting the privacy of Shopify merchants and their customers who use the Zikrova application ("App"). This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

By installing or using Zikrova, you agree to the collection and use of information in accordance with this policy.


1. Information We Collect

1.1 Shopify Store Data

When you install Zikrova, we receive access to specific data from your Shopify store through Shopify's OAuth 2.0 authorization flow. The data we access includes:

  • Store name, domain (myshopify.com URL), email address, timezone, and currency settings
  • Product and variant information including titles, SKUs, prices, and inventory quantities — only for products you choose to link or operate on
  • Access tokens necessary to authenticate API requests on your behalf

We request only the minimum API scopes required to deliver the App's functionality: read_products, write_products, read_inventory, and write_inventory.

1.2 Data You Provide

  • Source product URLs you paste into the App (Amazon, Walmart, eBay, AliExpress, Temu, DHgate, CJDropshipping, or custom URLs)
  • Pricing rules you configure (multipliers, margins, floor/ceiling values)
  • Sync preferences and notification settings
  • Email addresses for alert notifications
  • Slack webhook URLs you optionally provide

1.3 Automatically Collected Data

  • Sync logs: timestamps, source prices scraped, Shopify prices set, sync outcomes
  • Error logs: failed scrape attempts and API errors for debugging
  • Pricing history: a record of every price change made through the App (used for the undo feature and analytics)
  • App usage analytics: feature usage patterns used to improve the product (no personally identifiable information)

1.4 Customer Data

Zikrova does not access, store, or process your store's customer data (orders, customer profiles, emails, or payment information). We exclusively access product and inventory data.


2. How We Use Your Data

  • Price monitoring: We use source URLs you provide to scrape current prices from supplier platforms and compare them to your Shopify prices.
  • Price updates: We use your Shopify access token to update product variant prices and inventory quantities on your behalf, according to your configured rules.
  • Notifications: We use your email address and/or Slack webhook to send you price change alerts and sync status updates.
  • Billing: Subscription management is handled entirely through Shopify's Billing API. We do not collect or store payment card information.
  • Analytics: We use aggregated, anonymized usage data to understand how the App is being used and to improve features.
  • Support: We may use your store information to diagnose and resolve support requests you submit.

We do not sell your data to third parties. We do not use your data for advertising. We do not share your data with any third party except as required to operate the App (see Section 4).


3. Data Storage and Security

3.1 Storage

Your data is stored in a PostgreSQL database hosted on secure cloud infrastructure. Data is encrypted at rest and in transit using industry-standard TLS 1.2+ encryption.

3.2 Retention

  • Active store data is retained for the duration of your subscription.
  • Sync logs and price history are retained for 12 months on Free and Starter plans, 24 months on Growth, and indefinitely on Pro.
  • On app uninstall, we receive a Shopify shop/redact webhook and delete all your store's data within 30 days.

3.3 Security Practices

  • All Shopify webhook payloads are verified using HMAC signature validation
  • Access tokens are stored encrypted and never logged
  • We conduct regular security reviews of our codebase and infrastructure
  • Access to production data is restricted to authorized personnel only

4. Third-Party Services

To deliver the App's functionality, we use the following third-party services:

  • Shopify API: Required for reading and updating product data in your store. Governed by Shopify's Privacy Policy.
  • Scraping proxy services (ScraperAPI / Oxylabs): Used to fetch prices from supplier platforms. Only the source URLs you provide are sent. No personal data is transmitted.
  • eBay Developer API: Used to retrieve pricing data from eBay. Governed by eBay's Developer Program policies.
  • CJDropshipping API: Used to retrieve pricing data from CJDropshipping. Governed by CJ's API terms.
  • Email delivery (SMTP provider): Used to send notification emails to addresses you configure. Email content contains only price change data you have chosen to monitor.
  • Redis / BullMQ (Upstash): Used to manage background sync job queues. No personal data is stored in the queue beyond task identifiers.
  • Fly.io: Our application hosting provider. Governed by Fly.io's Privacy Policy.

5. GDPR and Your Rights

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation (GDPR):

  • Right of access: Request a copy of the personal data we hold about your store.
  • Right to rectification: Request correction of inaccurate data.
  • Right to erasure: Request deletion of your data ("right to be forgotten"). Uninstalling the App triggers automatic deletion within 30 days.
  • Right to data portability: Request your data in a machine-readable format (JSON or CSV).
  • Right to restrict processing: Request that we limit how we use your data.
  • Right to object: Object to our processing of your data.

To exercise any of these rights, contact us at privacy@zikrova.app. We will respond within 30 days.

5.1 Shopify Compliance Webhooks

Zikrova subscribes to all mandatory Shopify compliance webhooks:

  • customers/data_request — We respond confirming we do not store customer personal data.
  • customers/redact — We respond confirming no customer data exists to redact.
  • shop/redact — All shop data is deleted within 30 days of receiving this webhook.

6. Children's Privacy

Zikrova is a B2B application intended for use by Shopify merchants and their authorized staff. We do not knowingly collect data from individuals under the age of 18.

7. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email (to the address associated with your Shopify store) and by displaying a notice within the App. Your continued use of Zikrova after changes take effect constitutes acceptance of the updated policy.

8. Governing Law

This Privacy Policy is governed by applicable data protection law. For merchants in the EEA, this includes the GDPR. For merchants in California, this includes the CCPA.

Contact Us

For privacy-related questions, data requests, or concerns:

Email: privacy@zikrova.app
Support: support@zikrova.app

We aim to respond to all privacy inquiries within 5 business days.