MeriStoreBoost Pro

Privacy

Privacy Policy

MeriStoreBoost Pro processes only the information needed to provide, secure, bill, and support its Shopify storefront features.

Who is responsible

李云强 (LI YUNQIANG), trading as 未来暢想 under the MERI brand operates MeriStoreBoost Pro. The policy is effective 2026-09-09. The operator's required business-imprint contact details are available on lawful request via support@meridoll.com where required by applicable law. Privacy questions may be sent to support@meridoll.com.

Information we process

  • Shopify shop identity, installation status, authenticated session data, granted scopes, and access credentials needed to operate the installed app.
  • Merchant settings, enabled feature states, configuration revisions, tutorial visibility, theme compatibility results, and billing entitlement status.
  • Minimal webhook and operational records, including delivery IDs, topics, timestamps, payload fingerprints, retry state, sanitized error codes, and audit events.
  • Shopify may include a customer or request reference in a mandatory privacy webhook. We do not create buyer profiles or retain the raw privacy webhook payload; temporary references are cleared when processing completes.

We do not collect payment-card details. Shopify handles app plan approval and billing. Age Confirmation stores a visitor’s configured acknowledgement in that visitor’s browser; it is not identity or legal age verification and is not sent to our backend in this release.

Why we use information

We use information to authenticate merchants, isolate each shop’s data, save and deliver requested storefront settings, check theme compatibility, enforce paid access, process privacy requests, prevent duplicate webhook work, recover from transient failures, investigate incidents, and comply with Shopify requirements. We do not sell personal information or use it for behavioral advertising.

Shopify privacy requests

  • customers/data_request: records and processes the request; this release reports that it does not maintain customer profile data.
  • customers/redact: removes the temporary customer reference associated with the request.
  • shop/redact: deletes the shop tenant and its related sessions, settings, feature configuration, entitlement, compatibility, workflow, and audit data. A minimized, non-linkable processing receipt may remain for retry and audit safety.

Signed requests are acknowledged quickly, queued, deduplicated by Shopify webhook ID, retried on transient failure, and processed asynchronously.

Retention and deletion

Active installation and configuration data is retained while the app is installed and until the Shopify deletion lifecycle applies. Completed outbox work is scheduled for deletion after 90 days; failed outbox work, terminal webhook receipts, and theme compatibility audit records after 180 days. Executing retention requires a recent successful backup. Configured database backup retention keeps the latest seven daily and four weekly archives. Provider operational logs follow the applicable hosting settings. Live Chat text and conversation metadata are retained for 90 days. Attachments, when enabled, are relayed to support and deleted from temporary storage as soon as delivery completes; only minimal file metadata is retained with the conversation.

Service providers and international processing

Shopify provides the commerce platform, app authentication, Admin APIs, hosted extensions, webhooks, and app billing. Railway provides application and PostgreSQL hosting; the current deployment is in the Netherlands. Cloudflare R2 is the configured database backup destination. Zoho Mail hosts our support mailbox. YouTube supplies videos when a tutorial is opened. These providers may process data outside Japan under their applicable service and privacy terms. Contact us for information about the processing arrangements and safeguards applicable to your request.

Security and your choices

Controls include Shopify authentication and webhook HMAC validation, tenant-scoped data access, least-privilege API scopes, encrypted transport, idempotent processing, bounded request sizes, sanitized logging, backups, and restricted developer diagnostics. No system is perfectly secure. Merchants can uninstall the app through Shopify or contact us to request access, correction, export, restriction, or deletion where applicable.