Privacy Policy
Last updated: 4 August 2026
Gridproof ("the app") is operated by Anis Apps ("we"). This policy describes what data the app processes when a merchant installs it on a Shopify store, and what this website collects from the people who visit it.
What we access
Gridproof requests only the read_products and
write_products Shopify scopes. The app cannot
access customer records, orders, payment information, or analytics.
We never ask for scopes we do not need.
What we store
- Store identity: your
.myshopify.comdomain, plan tier, and the offline API token Shopify issues to the app (encrypted at rest by our database provider). - Job history: the bulk-edit jobs you run — targeted entities, field values before and after each change, verification results, and error details.
- Checkpoint snapshots: point-in-time copies of the product fields a job may change (prices, tags, status, metafields), kept so you can preview and roll back. Retention follows your plan: 7 days (Free), 30 days (Standard), 90 days (Premium); snapshots are deleted automatically after that window.
- CSV files you upload, for the duration of the job plus the retention window.
- Audit log: per-field change records (entity, field, before, after, timestamp, source).
We store no customer personal data. Product data may incidentally contain merchant-authored text; we treat all of it as confidential.
Where it lives
All data is processed and stored in the European Union:
- Application + database: Railway (EU region, Amsterdam).
- Snapshots/CSV objects: Cloudflare R2 (EU jurisdiction).
- Error monitoring: Sentry (error events may include job/shop identifiers, never product content).
GDPR
customers/data_request— we hold no customer data; we respond accordingly.customers/redact— nothing to erase; acknowledged.shop/redact— within the required window after uninstall, all data for the store is erased: jobs, snapshots (including stored files), audit log, billing mirror, sessions, and the store record itself.
You may also request deletion at any time via support.
Sharing
We do not sell, rent, or share store data with third parties beyond the processors listed above. Data is used solely to provide the app's functionality.
Visitors to this website
Everything above concerns the app. This section covers gridproof.app itself — what it collects if you simply read these pages.
- Server logs: our host records the IP address, browser user-agent, page requested and time of each request, to keep the site available and to block abuse. We do not use them to profile anyone.
- Anything you email us: if you write to support, we keep the message and your address for as long as the matter is live.
There are no analytics, no advertising and no third-party
scripts on this site. The only thing stored in your browser is your
light/dark theme preference (gp-theme), which stays on your device
and is never sent to us — which is why you are not asked to accept cookies.
The legal basis for both is our legitimate interest (GDPR art. 6(1)(f)) in running a secure website and replying to the people who contact us. Logs are kept only for as long as our host retains them for security purposes; correspondence for as long as it is needed to resolve and record the exchange.
Contact
support@gridproof.app · Anis Apps, 8 place Roger Salengro, 31000 Toulouse, France.
The data controller is Mohamed Salah Djellali, entrepreneur individuel, trading as Anis Apps, at the address above — see the legal notice. You have the right to access, correct, erase, restrict or object to the processing of your personal data, and to receive it in a portable form — write to the address above. If you are in the EU and believe we have handled your data improperly, you may lodge a complaint with the CNIL, the French data-protection authority.