Privacy Policy

Last updated: 11 August 2026

Priorly keeps a history of your catalog so you can put it back. It never sees your customers, it sells nothing to anyone, and everything it stores is a copy of content you already own. The rest of this page is the detail behind those three sentences.

It covers what happens when a merchant installs the app and when anyone writes to us at support@veristock.app.

1. The short version

Priorly requests access only to the catalog content it keeps history of — products, collections, pages, and blog posts — and the permission to write that content back when a merchant restores an earlier version. It does not request access to Shopify customer, order, checkout, or payment data, and cannot read them.

It processes limited personal data about the merchant’s staff — the name and email Shopify supplies for the account that installs the app — and the technical information needed to run and secure the service.

We do not sell personal data, share it for cross-context behavioural advertising, or use it to train AI models. There is no analytics, advertising, or session-replay provider anywhere in the app.

2. Our role and the merchant’s role

For catalog content processed on a merchant’s instructions — the saved versions of products, collections, pages, and blog posts, and the records of what was restored — the merchant decides why it is processed. The merchant is the controller; Priorly is its processor.

We act as an independent controller only for what we process for our own purposes: administering the installation, operating and securing the service, responding to support requests, and complying with law.

3. What we process

3.1 Merchant and installation

3.2 Catalog history

This is the merchant’s business content. It becomes personal data only where a merchant has written personal information into their own catalog — a founder’s story on a page, a name in a blog post — and Priorly stores it exactly as written, for the merchant, and for nothing else.

3.3 Logs and error reports

Our hosting provider keeps a short record of each request — which page was asked for, whether it worked, and how long it took.

When the server hits an error, a report goes to Sentry: the error, its stack trace, the route, and the environment name. Sentry is configured not to collect the extras it can — no IP address, no user identity — and performance tracking is switched off entirely. There is no Sentry SDK in the browser at all — so no session replay, no screenshots, and no breadcrumbs are collected from a merchant’s browser.

4. What we do not request from Shopify

At install, Priorly asks for four permissions and no others: to read and write products, and to read and write pages and blog posts — collections travel with products. It has no access to customer names, contact details, addresses, orders, checkouts, payment details, card information, or inventory levels.

The write permissions exist for one reason: restoring an earlier version means writing it back. Priorly writes to the catalog only when a merchant asks it to restore something, and never writes anywhere else.

If the scopes change, we will update this policy before using anything newly accessible for a new purpose.

5. Why, and on what legal basis

Where we act for a merchant, we process on that merchant’s instructions and the merchant identifies its own legal basis.

Where we act for ourselves, under the GDPR and UK GDPR we rely on performance of a contract for providing and administering the app, and on our legitimate interests in securing the service, preventing abuse, diagnosing faults, and defending legal claims. We do not rely on consent unless we ask for it.

6. Cookies

Priorly sets no cookies of its own. No advertising cookies, no cross-site tracking, no third-party tag, pixel, or analytics script. The app runs inside the Shopify admin and relies on Shopify’s own session cookies, described in Shopify’s documentation.

7. Who we share it with

This is the complete list of providers that process anything:

ProviderPurposeLocation
ShopifyThe platform, authentication, and the catalog APIAs described by Shopify
Fly.ioApplication and database hostingAshburn, Virginia, United States
SentryServer-side error monitoringUnited States

Beyond these, we disclose information only where required by law or a valid legal request, to protect the rights and safety of Priorly, merchants or users, or in connection with a sale of the business under appropriate safeguards.

We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use merchant or catalog data to train AI models.

8. Where the data is

Priorly runs in the United States. Information from the EEA, the United Kingdom, Switzerland, or elsewhere is therefore transferred to and processed in the United States, whose data-protection laws differ from those where it came from.

Our hosting provider participates in the EU–US, UK, and Swiss–US Data Privacy Frameworks. Our providers publish data-protection terms for their services, including standard contractual clauses for transfers out of the EEA, the United Kingdom, and Switzerland.

If you need a data-processing agreement or details of the safeguards that apply to your own compliance work, write to support@veristock.app.

9. How long we keep it

InformationRetention
Shopify access token and app sessionWhile installed; deleted when Shopify notifies us of an uninstall
Saved catalog versionsFor the retention window of the shop’s plan — 30 days on Free, 90 days on Basic, 365 days on Advanced — older versions are pruned continuously
Restore records and history metadataUntil shop-data deletion completes after uninstall
Database backupsDaily encrypted snapshots, deleted by rotation after 5 days
Request logsHeld by our hosting provider for its retention period and then deleted. We copy them nowhere else
Error reportsHeld by Sentry for our account’s retention period and then deleted. We copy them nowhere else
Emails to usKept no longer than needed to resolve the matter and any follow-up

When the app is uninstalled:

  1. Shopify notifies us and we delete the access token and app sessions immediately;
  2. about 48 hours later Shopify asks us to erase the shop’s data;
  3. we delete everything remaining for that shop — every saved version, every restore record, and the history of what changed;
  4. backup copies go with the 5-day rotation.

Priorly answers all three of Shopify’s mandatory compliance webhooks. Because it holds no Shopify customer data, the answer to the customer-related ones is that we hold none.

10. Security

No internet service is completely secure and we cannot promise otherwise. If you think you have found a security problem, write to support@veristock.app.

11. Your rights

Depending on where you are, you may have the right to access your personal data, get a copy, correct it, have it deleted, restrict or object to processing, ask for portability, withdraw consent where consent was the basis, complain to a data-protection authority, and appeal a refusal.

To exercise any of them, write to support@veristock.app. We may need to verify who you are and what information you mean. Every request is read and answered by a person.

A merchant does not have to wait for us for the everyday case: uninstalling the app starts the deletion described in section 9.

We aim to answer within the period the law requires; under the GDPR and UK GDPR that is generally one month, with permitted extensions.

People in the EEA or the UK may complain to the data-protection authority where they live or work, or where they believe something went wrong.

12. United States

Where United States state privacy laws apply: we collect the categories in section 3, use them for the purposes in section 5, and disclose them to the recipients in section 7. We do not sell personal data, share it for cross-context behavioural advertising, process it for targeted advertising, or knowingly use sensitive personal data to infer characteristics. Eligible individuals may exercise access, correction, deletion, portability, opt-out, and appeal rights by writing to support@veristock.app. We will not discriminate against anyone for exercising a privacy right.

13. Automated decisions

Priorly does not profile anyone or make automated decisions with legal or similarly significant effects.

14. Changes

We will update the date at the top when this changes. Where a change materially affects how personal data is processed, we will tell merchants with the app installed.

15. Contact

For privacy, security, support, or data-rights requests: support@veristock.app