MyMeridian
MyMeridian

Privacy Policy

Last updated 12 August 2026

MyMeridian is a pre-launch profitability dashboard for Shopify merchants. This policy describes the data handling implemented in the current product and the production service MyMeridian is preparing to operate. The waitlist portions apply when the public flow is available; merchant-store portions apply when the service is made available to merchants.

Roles. The merchant who installs MyMeridian is the controller of their store’s data and of any shopper data within it. MyMeridian’s individual publisher will operate the app as a processor acting on that merchant’s instructions. Shoppers who want their data accessed or erased should contact the store they bought from; MyMeridian answers those requests through Shopify on the merchant’s behalf, as described below.

Publisher And Contact

MyMeridian will be published by its founder as an individual. The production address is https://mymeridian.io; the separate staging address is https://staging.mymeridian.io. The public service is not live yet, and staging remains a separate environment. The general contact address is welcome@mymeridian.io and the planned merchant-support and technical-emergency address is support@mymeridian.io. Support delivery and monitoring must be verified before public distribution. The final legal publisher name and governing-law details will be supplied before Shopify submission.

What MyMeridian Reads From A Store

MyMeridian requests read-only Shopify access. It holds no write permission of any kind and cannot change a price, an order, a product or a customer record. Accepted pricing recommendations are recorded inside MyMeridian only; applying one remains a manual action the merchant takes in Shopify.

The scopes requested are:

read_customers is not requested. Customer identity used by MyMeridian is limited to the id and email carried on orders, as described below.

Shopper Personal Data

Shopper personal data does reach MyMeridian, through read_orders. Exactly two fields are selected from Shopify’s customer object and stored:

No other field from that customer object is kept. Shopify may include more fields in an order webhook, but the authenticated payload is projected onto the exact fields listed here before anything is written. MyMeridian does not retain shopper names, phone numbers, billing or shipping addresses, IP addresses, payment card details or passwords.

Because a shopper email address is among the fields stored, MyMeridian’s access to orders falls under Shopify’s protected customer data requirements at the level covering customer email. The approved read_all_orders permission remains read-only; MyMeridian continues to apply the applicable data-handling undertakings and least-privilege limits described in this policy.

What Is Derived And Stored Alongside It

Per customer: the date of their first order, the channel and campaign that acquired them, their order count, and their lifetime revenue and profit. Per order: the order number, processed and Shopify source-update timestamps, currency, money totals, financial and fulfilment status, marketing channel, any UTM parameters and the landing page of the attributed visit. Line items are stored as title, SKU, quantity, price, discount, refunded quantity and the cost snapshotted when the order was placed. Fulfilment records retain shipment and Shopify source-update timestamps, carrier, service, location, item count and configured costs; tracking numbers and destination addresses are not retained. Marketing URLs can contain personalized query values and are treated as potentially personal data; matching landing, UTM and campaign values are cleared on customer redaction.

What The Merchant Provides Directly

Cost assumptions shown in Costs & Connections — payment processing rates, shipping and pick-and-pack estimates, and fixed monthly overhead. MyMeridian supplies visible install defaults until the merchant reviews or replaces them; reviewing a fallback does not make it measured. If a merchant chooses a configured Meta Ads, Google Ads, TikTok Ads or ShipStation connection, MyMeridian receives the selected account identifier, account label and currency plus the minimum token or API credential needed to sync spend or shipping costs. Provider tokens are encrypted at rest and can be disconnected from inside the app. These provider connections are not yet production-proven and will not be represented as such before their complete lifecycle is tested in staging.

How Data Is Stored And Secured

Who Else Sees It

MyMeridian does not sell store data, does not share it with advertisers, and does not use it to train machine-learning models. MyMeridian is currently pre-launch and has no production merchant-data environment. The planned production architecture uses Fly.io for application hosting, Fly Managed Postgres for the database and Upstash for managed Redis; Shopify receives information required to provide the app. Resend and Twilio Verify may process only the email or phone information needed for merchant or operator security communications after those services are configured. This policy will be updated before launch if a production provider changes. When a merchant chooses to connect Meta, Google, TikTok or ShipStation, MyMeridian exchanges authorization details with that provider and requests only the account and cost data needed for the selected integration. MyMeridian does not send Shopify customer records to advertising platforms.

Pre-Launch Waitlist

A visitor may join the MyMeridian waitlist with an email address and an optional Shopify store URL. We retain campaign attribution passed in the signup link (such as UTM source, medium and campaign) only to understand which marketing generated interest. We do not request a name, password, Shopify access token, customer data or other unnecessary personal information for the waitlist.

A signup creates an email-bound Founding Merchant eligibility record for the stated 15% first-year monthly-plan benefit if activated at launch. It is not a public coupon. Transactional confirmation may be sent once MyMeridian's sender is verified; product/newsletter mail is sent only after separate consent and includes an unsubscribe link. Transactional delivery receipts are retained for up to 90 days for reliability and abuse troubleshooting. To request access, correction or deletion of waitlist data, use the contact details on this page.

How Long It Is Kept

Access And Erasure Requests

MyMeridian implements all three of Shopify’s mandatory compliance webhooks and acts on each automatically:

A merchant may also request access or erasure directly, using the contact address above, without going through Shopify.

International Transfers And Legal Basis

Data is processed on infrastructure that may be located outside the merchant’s country. Processing is carried out to perform the contract with the merchant, and on their instruction in respect of any shopper data.

Cookies

This marketing site runs no analytics or advertising trackers. If a visitor changes the appearance, the selected light or dark theme is stored locally in that browser. Inside the embedded app, Shopify’s own session mechanism is used to keep a merchant signed in; no advertising or cross-site tracking cookie is set by MyMeridian.

Changes To This Policy

Material changes will be reflected in the “last updated” date above and, where the change affects what is collected or who it is shared with, notified to installed merchants before it takes effect.

Contact

For support, contact support@mymeridian.io. The mailbox will be monitored before public distribution; until then, MyMeridian is not accepting merchant installations.