Last updated: 22 July 2026
rebicon (“the App”, “we”, “us”) is a Shopify app that keeps a readable change history of a merchant’s product and collection catalog and lets the merchant undo or roll back changes. This policy explains what data the App accesses, why, how long we keep it, and the choices you have. The App is operated by Artem, an individual (sole trader) (Georgia).
Our customer is the merchant who installs the App on their Shopify store. This policy describes how we handle the merchant’s store data and the personal data of the merchant’s staff who use the App. We are a data processor acting on the merchant’s instructions for store data, and a data controller for the limited account/staff data described below.
When you install the App, Shopify grants it the following access. We request the minimum needed to run the change-history feature:
| Data | Shopify scope | Why |
|---|---|---|
| Products, collections, files, publications, inventory | read_products, read_files, read_publications, read_inventory | Build and display the change history and before/after diffs. |
| Write access to products | write_products | Apply an undo / rollback you request. |
| Order date and total only (optional) | read_orders | The optional “Sales impact” feature correlates a change with a later dip in sales. We read only the date and total amount of orders. We do not read or store buyer/customer personal data, line items, or contact details. |
We share data only with the infrastructure providers needed to run the App:
| Provider | Purpose | Region |
|---|---|---|
| Shopify | Platform the App runs on; source of store data | Global |
| Fly.io | Application hosting | EU (Frankfurt) |
| Supabase | Database (change history and account data) | EU (Frankfurt) |
| Sentry | Error diagnostics (technical logs; not used to profile merchants) | United States |
| Resend | Transactional email (e.g. welcome, support, digest), when enabled | United States |
Notifications you route to your own Slack or Discord workspace are sent to the webhook endpoint you configure; the content of those messages is governed by Slack’s / Discord’s own policies.
We keep your catalog change history for a window that depends on your plan:
| Plan | Change-history retention |
|---|---|
| Free | 30 days |
| Pro | 90 days |
| Team | 365 days |
| Enterprise | Unlimited (until deleted) |
History older than your retention window is automatically deleted. When you uninstall the App, or on a Shopify data-erasure request, we delete your store’s data (see below).
Data is encrypted in transit (HTTPS/TLS). Access tokens and merchant-configured webhook URLs are encrypted at rest. Access to production systems is restricted to authorized personnel.
We honor Shopify’s mandatory data-protection webhooks: customers/data_request,
customers/redact, and shop/redact. Uninstalling the App triggers deletion of
your store’s data in line with the retention above.
Depending on your location (e.g. under GDPR or CCPA), you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict its processing. To exercise any of these rights, contact us at gitflow@proton.me and we will respond within the period required by applicable law.
Our primary hosting and database are in the EU (Frankfurt). Some sub-processors may process data in other regions; where required, such transfers are covered by appropriate safeguards (e.g. Standard Contractual Clauses).
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, notify merchants through the App or by email.
Artem, an individual (sole trader)
Georgia
Email: gitflow@proton.me