Privacy Policy
Last updated: 30 August 2026
MigrationAudit is a read-only Shopify app that audits a store after a migration. It is a product of Veristack, operated by SpiralWorld LLC. This policy describes exactly what the app stores and what it does not, as the app is actually built.
The short version
The app reads your store’s catalog and content, saves the audit findings so you can look at them again, and stores the token that lets it talk to Shopify on your behalf. It requests no access to customer data, and it never changes anything in your store.
What the app stores
| Data | Why |
|---|---|
| Your shop domain (for example, your-store.myshopify.com) | Identifies which store an audit and a purchase belong to. |
| Shopify session data: the access token issued to the app, the scopes you granted, and its expiry | Required to call the Shopify Admin API on your behalf. Without it the app cannot run a scan. |
| Audit results: the score, the counts by severity, and the findings themselves | So you can reopen your latest audit without re-running it. The findings contain store catalog and content details — product titles and IDs, SKUs, variant prices, whether images have alt text, redirect paths, navigation link targets, page and blog titles, and metafield definition names. |
| A plan record: your shop domain, whether the store is on Free or Pro, and how many scans it has run | Enforces the single free scan and records the one-time Pro unlock. |
What the app does not collect
- No customer data. The app requests these read-only scopes and no others: read_products, read_content, read_online_store_navigation, read_themes, read_legal_policies. None of them grant access to protected customer data. It never sees customer names, email addresses, shipping addresses, or orders.
- No payment details. The $49 one-time purchase is processed entirely by Shopify. Card details never reach this app.
- No advertising trackers. The app sets no advertising cookies and does not sell or share data with advertisers.
The app is read-only
Every scope it requests is a read scope. The app has no ability to create, edit, or delete anything in your store, and it never attempts to. Findings tell you what to fix and link to Shopify’s own instructions; you make the changes yourself.
Who else processes this data
- Supabase — the database where sessions, audit results, and plan records are stored.
- Vercel — hosts and serves the application.
- Sentry — error monitoring. When something goes wrong, Sentry receives the technical error details and the shop domain it happened on. The option that would send personal information such as IP addresses and request headers is switched off.
- Shopify — authentication and billing.
How long it is kept, and how it is deleted
- While the app is installed: audit results are kept until the app is uninstalled. There is no automatic expiry — that is deliberate, so your last audit is still there when you come back.
- When you uninstall: Shopify sends an app/uninstalled notification and the app immediately deletes the stored session for your shop, which revokes its own access.
- 48 hours after uninstall: Shopify sends a shop/redact notification and the app deletes everything remaining for your shop — audit results, the plan record, and any leftover session rows.
- Customer data requests: Shopify’s mandatory customers/data_request and customers/redact notifications are received and acknowledged. Because the app stores no customer data, there is nothing to return and nothing to erase.
If you want your data removed sooner than the uninstall flow does it, email support.veristack@protonmail.com from the address associated with the store and we will delete it.
Security
The database credential used to read and write this data is only ever used by server-side code and is never sent to the browser. Traffic is served over HTTPS. Access tokens are stored so the app can call Shopify on your behalf, and are deleted when you uninstall.
No system is completely secure, and this policy makes no claim that this one is. If we become aware of a breach affecting your data, we will contact you.
Your rights
You can ask what is stored for your shop, ask for it to be corrected, or ask for it to be deleted. Uninstalling the app triggers deletion automatically. For anything else, email support.veristack@protonmail.com.
Changes to this policy
If this policy changes, the date at the top changes with it. Material changes will be reflected here before they take effect.
Contact
Privacy, GDPR, and data-deletion requests: support.veristack@protonmail.com
MigrationAudit, a product of Veristack, operated by SpiralWorld LLC.