Merch Studio – Privacy Policy

Last updated: 2 October 2026

Merch Studio (“the app”) is a Shopify app published by Unlikely (“we”, “us”). It helps merchants arrange and present their collections. This policy explains what data the app processes when a merchant installs it, why, where it is kept, and how it is deleted.

Who this policy is for

The app is used by merchants and their staff inside the Shopify admin. The app does not collect, read or store any data about the merchant’s customers — no names, email addresses, phone numbers, postal addresses, orders or payment details.

Data the app processes

When a merchant installs and uses the app, we process:

  • Store identification: the store’s Shopify domain (for example my-store.myshopify.com) and the date of installation.

  • Merchandising configuration: what the merchant creates in the app — collection orders, pins, sorting and boost rules, rule presets, editorial tiles and their translations, row layouts, product card copies and card media choices, display and stock settings, and which collections are active. This references Shopify products, collections, files, locations and metafields by their Shopify IDs.

  • Published state and activity history: what was last published for each collection, and a log of each publication (date, collection, what changed).

  • Staff identifier: the numeric Shopify staff user ID of the person who published a change or changed the automation setting. We do not store their name or email address.

  • Stock state: for collections whose rules use stock, whether each product is in or out of stock at the locations the merchant counts.

  • Plan: the store’s subscription plan, as reported by Shopify.

  • Access credentials: the access token Shopify issues to the app for the store. It is encrypted by the app before it is stored, and never sent to a browser.

  • Technical diagnostics: page performance measurements and error reports from the app’s screens, with secrets and URL parameters removed, and the cost of each call to Shopify’s API.

Product, collection and theme data are read from Shopify when needed to show and apply the merchandising. They stay in Shopify; the app keeps only the IDs and states listed above.

Data stored in the merchant’s store

When a merchant publishes, the app writes its configuration into the store, in metafields and metaobjects reserved to the app (namespace $app:merch). Merchants can see them in the Shopify admin but not edit them. A theme app extension reads them to display the merchandising on the storefront. The app never modifies theme files.

Why we process it

Only to provide the app’s features to the merchant: editing and publishing collections, showing their history, applying the plan the merchant subscribed to, and keeping the app reliable. We do not use the data for advertising or profiling, and we do not sell or rent it.

Service providers

The app runs on the following providers, which process data on our behalf only:

  • Shopify — the platform the app is built on.

  • Vercel — hosting of the app, and short-lived technical logs.

  • Convex — the database holding the data listed above.

  • Inngest — background jobs, such as removing the access token on uninstall, refreshing the theme’s page size, and following stock changes.

Retention and deletion

  • The activity history is deleted after 90 days.

  • The stored access token is deleted when the app is uninstalled.

  • When Shopify asks us to erase a store’s data (48 hours after uninstall), all of the store’s data held by the app is deleted.

  • Technical logs are kept by the hosting provider for a few days at most.

  • Data written into the merchant’s store stays there under the merchant’s control.

Security

All traffic uses HTTPS. Access to the app requires a session verified with Shopify. The store’s access token is encrypted with AES-256-GCM before it is stored. Each store’s data is isolated from every other store’s.

Your rights

Merchants and their staff can ask us to access, correct or delete their data, or ask any question about this policy, by writing to [email protected]. Requests about a store’s customers can be sent the same way; the app holds no customer data.

Changes

We will update this page when the app’s data handling changes, and change the date above.

Contact

Unlikely — [email protected]

Commerce doesn't have to be a pain,
we can make it simple.