Privacy Policy — rebicon

Last updated: 22 July 2026

rebicon (“the App”, “we”, “us”) is a Shopify app that keeps a readable change history of a merchant’s product and collection catalog and lets the merchant undo or roll back changes. This policy explains what data the App accesses, why, how long we keep it, and the choices you have. The App is operated by Artem, an individual (sole trader) (Georgia).

1. Who this policy is for

Our customer is the merchant who installs the App on their Shopify store. This policy describes how we handle the merchant’s store data and the personal data of the merchant’s staff who use the App. We are a data processor acting on the merchant’s instructions for store data, and a data controller for the limited account/staff data described below.

2. What data we access and why

When you install the App, Shopify grants it the following access. We request the minimum needed to run the change-history feature:

DataShopify scopeWhy
Products, collections, files, publications, inventoryread_products, read_files, read_publications, read_inventoryBuild and display the change history and before/after diffs.
Write access to productswrite_productsApply an undo / rollback you request.
Order date and total only (optional)read_ordersThe optional “Sales impact” feature correlates a change with a later dip in sales. We read only the date and total amount of orders. We do not read or store buyer/customer personal data, line items, or contact details.

3. What we store

4. What we do not collect

5. Service providers (sub-processors)

We share data only with the infrastructure providers needed to run the App:

ProviderPurposeRegion
ShopifyPlatform the App runs on; source of store dataGlobal
Fly.ioApplication hostingEU (Frankfurt)
SupabaseDatabase (change history and account data)EU (Frankfurt)
SentryError diagnostics (technical logs; not used to profile merchants)United States
ResendTransactional email (e.g. welcome, support, digest), when enabledUnited States

Notifications you route to your own Slack or Discord workspace are sent to the webhook endpoint you configure; the content of those messages is governed by Slack’s / Discord’s own policies.

6. Data retention

We keep your catalog change history for a window that depends on your plan:

PlanChange-history retention
Free30 days
Pro90 days
Team365 days
EnterpriseUnlimited (until deleted)

History older than your retention window is automatically deleted. When you uninstall the App, or on a Shopify data-erasure request, we delete your store’s data (see below).

7. Data security

Data is encrypted in transit (HTTPS/TLS). Access tokens and merchant-configured webhook URLs are encrypted at rest. Access to production systems is restricted to authorized personnel.

8. Data deletion and your rights

We honor Shopify’s mandatory data-protection webhooks: customers/data_request, customers/redact, and shop/redact. Uninstalling the App triggers deletion of your store’s data in line with the retention above.

Depending on your location (e.g. under GDPR or CCPA), you may have the right to access, correct, export, or delete personal data we hold about you, and to object to or restrict its processing. To exercise any of these rights, contact us at gitflow@proton.me and we will respond within the period required by applicable law.

9. International transfers

Our primary hosting and database are in the EU (Frankfurt). Some sub-processors may process data in other regions; where required, such transfers are covered by appropriate safeguards (e.g. Standard Contractual Clauses).

10. Changes to this policy

We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, notify merchants through the App or by email.

11. Contact

Artem, an individual (sole trader)
Georgia
Email: gitflow@proton.me