Privacy Policy
Last updated 12 August 2026
MyMeridian is a pre-launch profitability dashboard for Shopify stores. It reads a store’s order, product, inventory and fulfilment records, combines them with recorded costs and clearly identified configured assumptions, and estimates the profit of each order and product. This policy describes every category of data it touches and what happens to it. The pre-launch waitlist portions apply when that public flow is available; merchant-store data portions apply when the production service launches.
Pre-Launch Status
The planned production address is mymeridian.io and staging is kept separately at staging.mymeridian.io. The production domain is controlled but still serves a temporary page; the MyMeridian service and staging hostname are not deployed there yet. MyMeridian is intended to be published by its founder as an individual. The planned support address is support@mymeridian.io; controlled delivery, the final legal publisher identity and a monitored contact will be confirmed before public distribution.
Pre-Launch Waitlist
A visitor may join the MyMeridian waitlist with an email address and, optionally, a Shopify store URL. We also retain campaign attribution supplied in the link they used (such as UTM source, medium and campaign), solely to understand which marketing generated interest. We do not collect names, passwords, Shopify access tokens, customer data or other unnecessary personal information in this flow.
A successful signup creates an email-bound Founding Merchant eligibility record. It records the 15% benefit for the first 12 months of an eligible monthly plan if the offer is activated at launch; it is not a public reusable coupon. We send the transactional waitlist confirmation regardless of marketing consent once the configured sender is verified. Product/newsletter mail is sent only to people who separately opt in, includes an unsubscribe link, and does not suppress necessary account or service notices.
Who This Policy Is For
The merchant who installs MyMeridian is our customer. Their store’s shoppers are not — we hold shopper data only as a processor acting on the merchant’s instructions, and the merchant remains the controller of it.
What We Read From Shopify
MyMeridian requests these access scopes at install, and no others. Each is requested because a specific figure cannot be computed without it.
read_orders— order totals, discounts, taxes, shipping charged, line items and refunds. This is the revenue side of every profit number. A Shopify order also carries the customer who placed it, so this scope — and not any customer scope — is how the two fields selected from Shopify’s customer object, listed under Personal data specifically below, reach MyMeridian.read_all_orders— extends that read-only order history beyond Shopify’s default 60-day window so lifetime profitability, repeat-customer cohorts and seasonal trends are complete. This permission is already approved and does not add any write access.read_products— products and variants, so line items can be grouped by what was actually sold.read_inventory— the per-variant unit cost recorded on the inventory item. Without it, cost of goods is zero and every margin would be overstated.read_fulfillments— when each order shipped, used for fulfilment capacity and shipping cost.read_reports— Shopify Shipping label-cost reports by order, carrier and service. Shopify separately gates those reports behind Level 2 protected-customer-data approval covering name, address, phone and email. This is a ShopifyQL access gate: MyMeridiandoes not query or persist shopper name, address or phone, and the connection stays paused until Shopify grants the approval. The expanded request has not been submitted yet, and MyMeridian will not query, retain or use those fields merely because approval is available.
MyMeridian requests no write scope. It cannot change a price, an order, or anything else in the store. Accepted pricing recommendations are recorded inside MyMeridian only; applying them remains a manual action the merchant takes in Shopify.
read_customers is not requested. Customer identity used by MyMeridian is limited to the id and email carried on orders, as described below.
Personal Data Specifically
Shopper personal data does reach MyMeridian, through read_orders. Exactly two fields are selected from Shopify’s customer object and stored:
- the Shopify customer id carried on the order — the stable identifier used to link that store’s repeat orders and to match access or erasure requests; and
- the email address on that customer record. It is stored so that a
customers/data_requestorcustomers/redactnaming a shopper can be matched to the right rows and answered, and it is included in the export handed to the merchant for a data request.
No other field from that customer object is selected for use or persistence. Shopify may include more fields in an order webhook, but before recovery data is written MyMeridian projects the authenticated payload onto the exact fields listed here. It does not retain shopper name, phone number, billing or shipping address, IP address, payment card details or passwords.
From those fields and the orders themselves, MyMeridian stores per customer: the date of their first order, the channel and campaign that acquired them, their order count, and their lifetime revenue and profit. Per order it stores the order number, its processed and Shopify source-update timestamps, currency, the money totals above, financial and fulfilment status, the marketing channel, any UTM parameters, and the landing page URL of the visit the order is attributed to. Marketing URLs can contain personalized query values and are therefore treated as potentially personal data: matching landing, UTM and campaign values are cleared on customer redaction. The referring URL is used to classify that channel and may remain briefly in the minimized recovery copy described below, but is not stored on the order record. Line items are stored as title, SKU, quantity, price, discount, refunded quantity and the cost snapshotted when the order was placed. Fulfilment records linked to the order retain shipment and Shopify source-update timestamps, carrier, service, location, item count and configured costs; tracking numbers and destination addresses are not retained.
Because a shopper email address is among the fields read and stored,MyMeridian’s access to orders falls under Shopify’s protected customer data requirements at the level that covers customer email. The approved read_all_orders permission remains read-only, andMyMeridian continues to apply the applicable data-handling undertakings and least-privilege limits described in this policy.
What The Merchant Gives Us Directly
Cost assumptions shown in Costs & Connections — payment processing rates, shipping and pick-and-pack estimates, and fixed monthly overhead. MyMeridian supplies visible install defaults until the merchant reviews or replaces them; reviewing a fallback does not turn it into a measured cost. A merchant may also connect Meta Ads, Google Ads, TikTok Ads or ShipStation. MyMeridian then stores the provider access and refresh tokens encrypted at rest, the selected account identifier and imported campaign-spend or carrier-cost records. Disconnecting removes the local tokens and requests provider revocation where the provider supports it. These connections are not yet production-proven and will not be presented as active until their complete lifecycle passes staging verification.
How Data Is Stored And Secured
- Data is held in a PostgreSQL database, isolated per store, and reached only over TLS.
- Shopify session tokens are stored server-side and are never exposed to the browser.
- Third-party connector tokens are encrypted with AES-256-GCM using a key held outside the database. OAuth state is one-use, short-lived and stored only as a one-way hash.
- Every webhook Shopify sends is HMAC-verified before it is acted on; an unverified request is rejected with 401 and nothing is written.
- For crash recovery, a verified webhook is reduced to the fields its processor actually uses before it is written. The projected copy is cleared as soon as processing succeeds. A failed projected order copy is retried and is irreversibly cleared after seven days; names, addresses, phone numbers, IP addresses and payment metadata never enter that queue.
- The minimum customer id and email carried by a mandatory compliance request are purpose-limited recovery state and remain only until that legal action succeeds.
shop/redactneeds no customer payload. Compliance work is never marked complete merely because an ordinary recovery-retention deadline passed.
Who Else Sees It
MyMeridian does not sell store data, does not share it with advertisers, and does not use it to train models. It has no production merchant-data environment yet. Its planned production architecture uses Fly.io, Fly Managed Postgres and Upstash; Resend and Twilio Verify may process the minimum email or phone information needed for merchant or operator security communications after configuration. It is disclosed to Shopify as needed to provide the app. When a merchant chooses a connector, MyMeridian calls that provider only to read the merchant-authorized account, advertising report or carrier-label cost. Shopify customer emails, addresses and customer records are not sent to Meta, Google, TikTok or ShipStation by this connector flow.
How Long It Is Kept
Waitlist contact and eligibility data is retained only while MyMeridian is preparing or operating the stated early-access program, then deleted or anonymized when it is no longer needed. Transactional delivery receipts are retained for up to 90 days for reliability and abuse troubleshooting. A waitlist visitor can request access, correction or deletion through the public contact details below.
Store data is retained while the app is installed. On uninstall the store’s sessions are deleted immediately, and the remaining records are removed when Shopify sends shop/redact.
After customers/redact, keyed one-way digests of the Shopify customer id and, when supplied, email remain as pseudonymous erasure guards. The key is held outside the database. These guards are used only to stop a delayed webhook or later historical import from recreating the customer, and they are deleted with the store on shop/redact.
Requests To Access Or Erase Data
MyMeridian implements all three of Shopify’s mandatory compliance webhooks, and acts on each automatically:
customers/data_request— everything held about the named customer is assembled into an export and made available to the merchant, who is the controller and responds to the shopper. The export includes every normalized customer, linked order, line-item and fulfilment field, including derived cost and profit fields, plus any still-pending minimized recovery payload that names the customer or belongs to one of their linked orders. The authenticated Privacy requests screen receives metadata only and shows every uncollected obligation; collected history is paginated. The full report is returned only from a shop-scoped, no-store download after the merchant explicitly asks for it, and that same transaction records the first collection time. This handoff remains available without an active subscription. The export expires 31 days after the request whether or not it is collected and is removed by an hourly sweep (and by the startup catch-up sweep after downtime). If erasure has already completed, the response is an empty, de-identified record: it retains neither the supplied customer id nor email and does not recreate erased data.customers/redact— the customer record is deleted and its link is removed from every order; the orders retain their own Shopify order id and economic history but no customer link or Shopify customer identifier. Stored landing URLs, UTM values and campaign strings are cleared from those linked orders, and customer and attribution URLs are removed from matching pending order recovery payloads. A different Shopify customer id is not affected merely because it shares an email address. The current redaction delivery may retain only its customer id until completion is durably recorded, so a crash cannot suppress the legal action. The keyed erasure guards described above then prevent in-flight webhooks and later imports from recreating the customer. Deleting the orders outright would silently rewrite the merchant’s own historical revenue.shop/redact— every record belonging to that store is deleted, including sessions, orders, products, cost rules and connectors.
A merchant may also request access or erasure directly using the contact details below, without going through Shopify.
International Transfers And Legal Basis
Data is processed on infrastructure that may be located outside the merchant’s country. Processing is carried out to perform the contract with the merchant, and on their instruction in respect of any shopper data.
Changes
Material changes to this policy are announced in the app before they take effect. The date at the top is the last substantive revision.
Contact
Email support@mymeridian.io. Support site: https://staging.mymeridian.io/support.