Pricewarden: Bulk Edit & Rules

Privacy Policy

Effective date: 3 October 2026 · Version 1.3 · Support · Terms

This policy explains what data the Pricewarden app (“Pricewarden”, “the app”, “we”) processes when a merchant installs it from the Shopify App Store, why, how long we keep it, and how it is deleted. It is written for merchants - store owners and their staff. We do not sell data, we do not use it for advertising, and we do not process your customers’ personal data.

This policy covers data processing only. Use of the app, including the fact that it is provided “as is” and used at your own risk, warranties and the limitation of our liability, is governed by our Terms of Service.

1. Who we are

Pricewarden is developed and operated by Machka Machka j.d.o.o., Zagreb, Croatia (European Union). Privacy questions and requests: info@hectone.com.

For the data of your store (products, prices, inventory, change history, rules) you are the controller and we process it only on your instructions, to provide the app you installed (we act as your processor). For our own operational records (your plan and billing status, support conversations, security and error logs) we are the controller.

2. What data we process

Everything below is store data or data you type into the app yourself. The app never receives order or customer records (see section 3).

DataWhy we need itHow long we keep it
Store identity - your .myshopify.com domain, Shopify plan name, product count, install and uninstall dates, app plan and billing statusOperate your account, apply plan limits, show billing statusWhile the app is installed; deleted within 48 hours after uninstall
Access credentials - the Shopify API access token issued to the app (stored encrypted, AES-256-GCM), and the login sessions of staff members who open the app (Shopify passes the staff member’s name, email address and locale with each session)Read and update your products on your behalf; keep you signed in inside the Shopify adminSessions are deleted the moment you uninstall; the encrypted token is deleted with the shop record within 48 hours
Catalog data - products and variants: titles, handles, SKUs, barcodes, vendor, type, category, tags, status, price, compare-at price, cost per item, inventory per location, whether SEO title/description, description and images are present, collection membership, and only those metafields you pick in a filter or editFilters, previews, bulk edits, catalog-health checks and the automations you configureKept in sync while installed; the catalog index is removed at uninstall and everything else within 48 hours
Change history - the tasks (“jobs”) you run: filters, operations, per-item before/after values; restore points, including an automatic daily copy of your catalog as the app sees it (titles, vendor, type, status, tags, prices, compare-at prices, SKUs, barcodes); price history; EU Omnibus reference recordsUndo and restore, product price timeline, EU Omnibus “lowest price in 30 days” proofJob history: 90 days after a task finishes (an active campaign is never removed). Undo window: 7 days on Free, 14 days on Founding. Restore points: 90 days, or until you delete them; the daily catalog copy: 30 days. Price history: 7 days on Free, 365 days on Founding (never more than 400 days); with EU Omnibus price tracking switched on it is kept up to 400 days on every plan, because it is the evidence behind the “lowest price in 30 days”. Omnibus references: up to 400 days. All of it is deleted within 48 hours after uninstall.
Automation rules and settings - stock-threshold, aging-markdown, auto-tag, Price Guard, market and Omnibus settings, discount rules, saved templatesRun the automations you set upUntil you delete them; deleted within 48 hours after uninstall
Notification settings - the email address you enter, Slack / Discord / custom webhook URLs and signing secret, Telegram chat ID (only if you link a chat)Deliver the notifications you switched onUntil you remove them; deleted within 48 hours after uninstall
Support - tickets and messages you send from the in-app Help & Support window, image attachments you upload, your shop domain and planAnswer your requestDeleted together with your shop data
Technical logs and alerts - server logs (request path, shop domain, job IDs, error messages) and internal alert recordsKeep the service running, diagnose failures, prevent abuseAlert records 60 days; log files are rotated on a rolling basis
Usage counters - number of changes and tasks per dayEnforce plan limitsReset daily; deleted with the shop

3. What we do not process - your customers’ data

5. Sub-processors and recipients

We use a small number of providers. Data is hosted in the European Union. Where a provider you choose to connect is outside the EU, the transfer relies on that provider’s EU data-transfer safeguards (for example Standard Contractual Clauses).

ProviderWhat forWhen
ShopifyThe platform: the app runs inside your Shopify admin, uses the Shopify Admin API and Shopify handles all billingAlways
Hetzner Online GmbH (EU data centre)Hosting of the application servers, database, cache and backupsAlways
Zoho Corporation B.V. (Zoho Mail, EU data centre)Delivers the notification emails you enable to the address you enter (the email text: job title, counts, your shop domain)Only if you switch on email notifications
TelegramDelivers job and alert messages to a Telegram chatOnly if you link a Telegram chat in the app
Slack, Discord or your own webhook endpointReceive the job / alert payloads you configure (title, message, shop domain, counts)Only if you configure them
Error monitoring service (Sentry)May receive error reports (stack trace, request path, shop domain) so we can fix failures; cookies and access tokens are strippedOnly if we have it enabled
AI drafting assistant (Anthropic)When we answer a support ticket, the ticket text and your shop domain may be used to draft a reply; a human reviews every draft before it is sent to youOnly for support tickets you open, and only if we have it enabled

We do not share data with anyone else, and we never sell it.

6. Security

7. Retention and deletion

When you uninstall

  1. Immediately (Shopify’s app/uninstalled notification): your login sessions are deleted, running and scheduled tasks are cancelled, all automations stop, the catalog index and caches are removed, and billing is marked cancelled.
  2. Within 48 hours (Shopify’s shop/redact request): the store record and everything linked to it is deleted - encrypted access token, tasks and their item history, restore points, price history, Omnibus references, rules, templates, notification settings, support conversations and alerts, including the copies in our backup database.
  3. Reinstall within 48 hours: your settings and history are still there and the free trial is not restarted.

Delete sooner, or delete parts

Automatic clean-up while you use the app

8. Your rights and contact

Under the GDPR you have the right to access, rectify, erase, restrict or object to the processing of personal data concerning you, and to data portability. To exercise these rights write to info@hectone.com. You can export your price history, Omnibus proof log, restore points and catalog data as CSV from inside the app at any time. You may also lodge a complaint with your local data-protection authority; ours is the Croatian Personal Data Protection Agency (AZOP).

The app itself sets no tracking cookies. Inside the Shopify admin it relies on Shopify session tokens; any cookie set during Shopify’s installation handshake is technical and short-lived. This page and the support page set no cookies at all.

9. Changes to this policy

We may update this policy when the app or the law changes. The effective date at the top always shows the current version. If a change materially affects how your data is processed we will tell you in the app before it takes effect.