Privacy Policy
Last updated: 11 August 2026
Priorly keeps a history of your catalog so you can put it back. It never sees your customers, it sells nothing to anyone, and everything it stores is a copy of content you already own. The rest of this page is the detail behind those three sentences.
It covers what happens when a merchant installs the app and when anyone writes to us at support@veristock.app.
1. The short version
Priorly requests access only to the catalog content it keeps history of — products, collections, pages, and blog posts — and the permission to write that content back when a merchant restores an earlier version. It does not request access to Shopify customer, order, checkout, or payment data, and cannot read them.
It processes limited personal data about the merchant’s staff — the name and email Shopify supplies for the account that installs the app — and the technical information needed to run and secure the service.
We do not sell personal data, share it for cross-context behavioural advertising, or use it to train AI models. There is no analytics, advertising, or session-replay provider anywhere in the app.
2. Our role and the merchant’s role
For catalog content processed on a merchant’s instructions — the saved versions of products, collections, pages, and blog posts, and the records of what was restored — the merchant decides why it is processed. The merchant is the controller; Priorly is its processor.
We act as an independent controller only for what we process for our own purposes: administering the installation, operating and securing the service, responding to support requests, and complying with law.
3. What we process
3.1 Merchant and installation
- the shop’s
myshopify.comdomain; - Shopify shop and installation identifiers;
- the name, email address, and Shopify user ID of the staff account that installs the app, as supplied by Shopify;
- an access token issued by Shopify, used only for the approved scopes;
- app session and authentication records;
- which paid plan, if any, the shop is on;
- anything a merchant chooses to send us by email.
3.2 Catalog history
- the state of each product, collection, page, and blog post at the moment it changes — titles, descriptions, prices, image references, collection membership, publication state, and the rest of what the merchant wrote into their own catalog;
- when each change happened and how we learned of it;
- periodic snapshots of the whole catalog, taken to catch changes a notification never arrived for, and honest records of the windows where something may have been missed;
- records of restores: what was put back, when, and the values it replaced, so a restore can itself be undone.
This is the merchant’s business content. It becomes personal data only where a merchant has written personal information into their own catalog — a founder’s story on a page, a name in a blog post — and Priorly stores it exactly as written, for the merchant, and for nothing else.
3.3 Logs and error reports
Our hosting provider keeps a short record of each request — which page was asked for, whether it worked, and how long it took.
When the server hits an error, a report goes to Sentry: the error, its stack trace, the route, and the environment name. Sentry is configured not to collect the extras it can — no IP address, no user identity — and performance tracking is switched off entirely. There is no Sentry SDK in the browser at all — so no session replay, no screenshots, and no breadcrumbs are collected from a merchant’s browser.
4. What we do not request from Shopify
At install, Priorly asks for four permissions and no others: to read and write products, and to read and write pages and blog posts — collections travel with products. It has no access to customer names, contact details, addresses, orders, checkouts, payment details, card information, or inventory levels.
The write permissions exist for one reason: restoring an earlier version means writing it back. Priorly writes to the catalog only when a merchant asks it to restore something, and never writes anywhere else.
If the scopes change, we will update this policy before using anything newly accessible for a new purpose.
5. Why, and on what legal basis
Where we act for a merchant, we process on that merchant’s instructions and the merchant identifies its own legal basis.
Where we act for ourselves, under the GDPR and UK GDPR we rely on performance of a contract for providing and administering the app, and on our legitimate interests in securing the service, preventing abuse, diagnosing faults, and defending legal claims. We do not rely on consent unless we ask for it.
6. Cookies
Priorly sets no cookies of its own. No advertising cookies, no cross-site tracking, no third-party tag, pixel, or analytics script. The app runs inside the Shopify admin and relies on Shopify’s own session cookies, described in Shopify’s documentation.
7. Who we share it with
This is the complete list of providers that process anything:
| Provider | Purpose | Location |
|---|---|---|
| Shopify | The platform, authentication, and the catalog API | As described by Shopify |
| Fly.io | Application and database hosting | Ashburn, Virginia, United States |
| Sentry | Server-side error monitoring | United States |
Beyond these, we disclose information only where required by law or a valid legal request, to protect the rights and safety of Priorly, merchants or users, or in connection with a sale of the business under appropriate safeguards.
We do not sell personal data, share it for cross-context behavioural advertising, use it for targeted advertising, or use merchant or catalog data to train AI models.
8. Where the data is
Priorly runs in the United States. Information from the EEA, the United Kingdom, Switzerland, or elsewhere is therefore transferred to and processed in the United States, whose data-protection laws differ from those where it came from.
Our hosting provider participates in the EU–US, UK, and Swiss–US Data Privacy Frameworks. Our providers publish data-protection terms for their services, including standard contractual clauses for transfers out of the EEA, the United Kingdom, and Switzerland.
If you need a data-processing agreement or details of the safeguards that apply to your own compliance work, write to support@veristock.app.
9. How long we keep it
| Information | Retention |
|---|---|
| Shopify access token and app session | While installed; deleted when Shopify notifies us of an uninstall |
| Saved catalog versions | For the retention window of the shop’s plan — 30 days on Free, 90 days on Basic, 365 days on Advanced — older versions are pruned continuously |
| Restore records and history metadata | Until shop-data deletion completes after uninstall |
| Database backups | Daily encrypted snapshots, deleted by rotation after 5 days |
| Request logs | Held by our hosting provider for its retention period and then deleted. We copy them nowhere else |
| Error reports | Held by Sentry for our account’s retention period and then deleted. We copy them nowhere else |
| Emails to us | Kept no longer than needed to resolve the matter and any follow-up |
When the app is uninstalled:
- Shopify notifies us and we delete the access token and app sessions immediately;
- about 48 hours later Shopify asks us to erase the shop’s data;
- we delete everything remaining for that shop — every saved version, every restore record, and the history of what changed;
- backup copies go with the 5-day rotation.
Priorly answers all three of Shopify’s mandatory compliance webhooks. Because it holds no Shopify customer data, the answer to the customer-related ones is that we hold none.
10. Security
- everything travels over an encrypted connection, and the database is encrypted where it is stored;
- messages that claim to come from Shopify are checked to be genuine before anything is acted on;
- the app writes to the catalog only when a merchant asks it to restore something, and every restore records what it replaced, so it can be undone;
- passwords and keys are held by the hosting platform, not written into the app;
- the app asks Shopify for the least it can work with, and holds no customer, order, or payment data to lose in the first place.
No internet service is completely secure and we cannot promise otherwise. If you think you have found a security problem, write to support@veristock.app.
11. Your rights
Depending on where you are, you may have the right to access your personal data, get a copy, correct it, have it deleted, restrict or object to processing, ask for portability, withdraw consent where consent was the basis, complain to a data-protection authority, and appeal a refusal.
To exercise any of them, write to support@veristock.app. We may need to verify who you are and what information you mean. Every request is read and answered by a person.
A merchant does not have to wait for us for the everyday case: uninstalling the app starts the deletion described in section 9.
We aim to answer within the period the law requires; under the GDPR and UK GDPR that is generally one month, with permitted extensions.
People in the EEA or the UK may complain to the data-protection authority where they live or work, or where they believe something went wrong.
12. United States
Where United States state privacy laws apply: we collect the categories in section 3, use them for the purposes in section 5, and disclose them to the recipients in section 7. We do not sell personal data, share it for cross-context behavioural advertising, process it for targeted advertising, or knowingly use sensitive personal data to infer characteristics. Eligible individuals may exercise access, correction, deletion, portability, opt-out, and appeal rights by writing to support@veristock.app. We will not discriminate against anyone for exercising a privacy right.
13. Automated decisions
Priorly does not profile anyone or make automated decisions with legal or similarly significant effects.
14. Changes
We will update the date at the top when this changes. Where a change materially affects how personal data is processed, we will tell merchants with the app installed.
15. Contact
For privacy, security, support, or data-rights requests: support@veristock.app