MyMeridian is a pre-launch profitability dashboard for Shopify stores. It reads a store’s order, product, inventory and fulfilment records, combines them with recorded costs and clearly identified configured assumptions, and estimates the profit of each order and product. This policy describes every category of data it touches and what happens to it. The pre-launch waitlist portions apply when that public flow is available; merchant-store data portions apply when the production service launches.

Pre-Launch Status

The planned production address is mymeridian.io and staging is kept separately at staging.mymeridian.io. The production domain is controlled but still serves a temporary page; the MyMeridian service and staging hostname are not deployed there yet. MyMeridian is intended to be published by its founder as an individual. The planned support address is support@mymeridian.io; controlled delivery, the final legal publisher identity and a monitored contact will be confirmed before public distribution.

Pre-Launch Waitlist

A visitor may join the MyMeridian waitlist with an email address and, optionally, a Shopify store URL. We also retain campaign attribution supplied in the link they used (such as UTM source, medium and campaign), solely to understand which marketing generated interest. We do not collect names, passwords, Shopify access tokens, customer data or other unnecessary personal information in this flow.

A successful signup creates an email-bound Founding Merchant eligibility record. It records the 15% benefit for the first 12 months of an eligible monthly plan if the offer is activated at launch; it is not a public reusable coupon. We send the transactional waitlist confirmation regardless of marketing consent once the configured sender is verified. Product/newsletter mail is sent only to people who separately opt in, includes an unsubscribe link, and does not suppress necessary account or service notices.

Who This Policy Is For

The merchant who installs MyMeridian is our customer. Their store’s shoppers are not — we hold shopper data only as a processor acting on the merchant’s instructions, and the merchant remains the controller of it.

What We Read From Shopify

MyMeridian requests these access scopes at install, and no others. Each is requested because a specific figure cannot be computed without it.

MyMeridian requests no write scope. It cannot change a price, an order, or anything else in the store. Accepted pricing recommendations are recorded inside MyMeridian only; applying them remains a manual action the merchant takes in Shopify.

read_customers is not requested. Customer identity used by MyMeridian is limited to the id and email carried on orders, as described below.

Personal Data Specifically

Shopper personal data does reach MyMeridian, through read_orders. Exactly two fields are selected from Shopify’s customer object and stored:

No other field from that customer object is selected for use or persistence. Shopify may include more fields in an order webhook, but before recovery data is written MyMeridian projects the authenticated payload onto the exact fields listed here. It does not retain shopper name, phone number, billing or shipping address, IP address, payment card details or passwords.

From those fields and the orders themselves, MyMeridian stores per customer: the date of their first order, the channel and campaign that acquired them, their order count, and their lifetime revenue and profit. Per order it stores the order number, its processed and Shopify source-update timestamps, currency, the money totals above, financial and fulfilment status, the marketing channel, any UTM parameters, and the landing page URL of the visit the order is attributed to. Marketing URLs can contain personalized query values and are therefore treated as potentially personal data: matching landing, UTM and campaign values are cleared on customer redaction. The referring URL is used to classify that channel and may remain briefly in the minimized recovery copy described below, but is not stored on the order record. Line items are stored as title, SKU, quantity, price, discount, refunded quantity and the cost snapshotted when the order was placed. Fulfilment records linked to the order retain shipment and Shopify source-update timestamps, carrier, service, location, item count and configured costs; tracking numbers and destination addresses are not retained.

Because a shopper email address is among the fields read and stored,MyMeridian’s access to orders falls under Shopify’s protected customer data requirements at the level that covers customer email. The approved read_all_orders permission remains read-only, andMyMeridian continues to apply the applicable data-handling undertakings and least-privilege limits described in this policy.

What The Merchant Gives Us Directly

Cost assumptions shown in Costs & Connections — payment processing rates, shipping and pick-and-pack estimates, and fixed monthly overhead. MyMeridian supplies visible install defaults until the merchant reviews or replaces them; reviewing a fallback does not turn it into a measured cost. A merchant may also connect Meta Ads, Google Ads, TikTok Ads or ShipStation. MyMeridian then stores the provider access and refresh tokens encrypted at rest, the selected account identifier and imported campaign-spend or carrier-cost records. Disconnecting removes the local tokens and requests provider revocation where the provider supports it. These connections are not yet production-proven and will not be presented as active until their complete lifecycle passes staging verification.

How Data Is Stored And Secured

Who Else Sees It

MyMeridian does not sell store data, does not share it with advertisers, and does not use it to train models. It has no production merchant-data environment yet. Its planned production architecture uses Fly.io, Fly Managed Postgres and Upstash; Resend and Twilio Verify may process the minimum email or phone information needed for merchant or operator security communications after configuration. It is disclosed to Shopify as needed to provide the app. When a merchant chooses a connector, MyMeridian calls that provider only to read the merchant-authorized account, advertising report or carrier-label cost. Shopify customer emails, addresses and customer records are not sent to Meta, Google, TikTok or ShipStation by this connector flow.

How Long It Is Kept

Waitlist contact and eligibility data is retained only while MyMeridian is preparing or operating the stated early-access program, then deleted or anonymized when it is no longer needed. Transactional delivery receipts are retained for up to 90 days for reliability and abuse troubleshooting. A waitlist visitor can request access, correction or deletion through the public contact details below.

Store data is retained while the app is installed. On uninstall the store’s sessions are deleted immediately, and the remaining records are removed when Shopify sends shop/redact.

After customers/redact, keyed one-way digests of the Shopify customer id and, when supplied, email remain as pseudonymous erasure guards. The key is held outside the database. These guards are used only to stop a delayed webhook or later historical import from recreating the customer, and they are deleted with the store on shop/redact.

Requests To Access Or Erase Data

MyMeridian implements all three of Shopify’s mandatory compliance webhooks, and acts on each automatically:

A merchant may also request access or erasure directly using the contact details below, without going through Shopify.

International Transfers And Legal Basis

Data is processed on infrastructure that may be located outside the merchant’s country. Processing is carried out to perform the contract with the merchant, and on their instruction in respect of any shopper data.

Changes

Material changes to this policy are announced in the app before they take effect. The date at the top is the last substantive revision.

Contact

Email support@mymeridian.io. Support site: https://staging.mymeridian.io/support.