This policy explains what information the UGC & Shoppable YouTube Videos app (the "App") collects when you install it on your Shopify store, how that information is used, who it is shared with, and how you can have it deleted. It applies to merchants who install the App and to visitors who view the App's video widgets on a merchant's storefront.
The short version.
The App stores the YouTube videos, product links, and widget settings you create, plus the standard Shopify installation details needed to run an embedded app. It does not collect any personal information about your customers, it has no analytics or tracking of any kind, and it does not sell or share your data with anyone for advertising.
Uninstalling the App permanently deletes your data from our database.
When you install the App, Shopify provides us with the information needed to authenticate and run an embedded app. We store:
.myshopify.com domainThis is information you enter or select yourself while configuring widgets:
Using the permissions you grant at install, the App reads your product catalogue (so you can pick products to link to a video), reads your theme information (to help place widgets), and writes app-owned metaobjects (to publish your widget configuration to your storefront). We only retain the specific product details listed in section 1.2 — we do not copy or retain your wider catalogue.
The App collects no information at all about people who visit your storefront. Widgets are rendered directly by your Shopify theme from data already published to your store. Viewing a widget, scrolling it, or playing a video sends no request of any kind to our servers. Adding a product to the cart from a video uses Shopify's own cart endpoint on your own domain; that request never reaches us.
We use the information described above only to:
We do not use your information for advertising, we do not sell it, and we do not share it with third parties except as described in section 4.
The App relies on the following services. We share no data with anyone else.
| Service | What it receives and why |
|---|---|
| Shopify | Hosts your store and provides the App's install, authentication, product, theme, and metaobject APIs. Your widget configuration is stored on Shopify as app-owned metaobjects so your storefront can render it. |
| Google / YouTube | When you paste a video URL or enter a channel handle, our server asks YouTube's public oEmbed and Data API services for that video's or channel's public details. These requests come from our server using our own API key and do not identify you or your store to Google. |
| Our hosting provider | Runs the App's server and PostgreSQL database. Standard server logs may record IP addresses and request details for security and troubleshooting, and are retained only for a short period. |
Two things on your storefront involve Google directly. You may want to reflect these in your own store's privacy policy or cookie notice:
youtube-nocookie.com domain,
which limits the tracking cookies YouTube sets. Playback is then governed by
Google's own privacy policy and YouTube's terms of service.
Within the Shopify admin, the App uses only the cookies and session tokens strictly necessary to keep you securely signed in during the install and authentication flow.
shop/redact request, typically sent 48 hours after uninstall, we delete all remaining
data for that store. Because we hold no customer personal information, there is nothing for us to
return or erase in response to a customers/data_request or customers/redact
request.
Data is transmitted over encrypted HTTPS connections and stored in an access-restricted PostgreSQL database on a private server. Access tokens are stored so the App can call the Shopify API on your behalf and are never exposed to your storefront or to third parties. Any custom CSS you write is sanitised before it is published, and it is scoped so it can only affect its own widget. No system can be guaranteed completely secure, but we limit risk by collecting as little information as possible — in particular, by holding no customer personal data at all.
Depending on where you are located, you may have the right to access, correct, export, or delete the personal information we hold about you, to object to or restrict how we use it, and to lodge a complaint with your local data protection authority. Most of this you can do yourself: the data the App holds is visible and editable in the App, and uninstalling deletes it. For anything else, email us at the address below and we will respond within 30 days.
Because the App holds no customer personal information, requests from your own customers about their personal data will need to be handled through Shopify or your store's own records.
The App's server and database are located in a single region, and information may be processed in a country other than your own. Where information is transferred internationally, we rely on appropriate safeguards recognised under applicable data protection law.
The App is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect personal information from anyone under 16.
We may update this policy as the App changes. The "last updated" date at the top reflects the most recent revision. If a change materially affects how we handle your information, we will make a reasonable effort to notify merchants through the App or by email.
For any question about this policy, or to make a privacy request, contact:
GurkhaDevs
Email: gurkhadevs@gmail.com