Tashlight for Shopify — Privacy Policy
Last updated: 14 May 2026
1. What we collect from merchants
When you install Tashlight on your Shopify store, we store:
- Your shop domain (e.g.
your-store.myshopify.com) - An OAuth access token (AES-256-GCM encrypted at rest)
- Your subscription status and plan
- Widget configuration (display options you choose in the admin)
We do not read or store your product, order, or customer data.
2. What we collect from your customers
The Tashlight widget displayed on your storefront is a link out to a separate Tashlight signup page. No data is sent to Tashlight unless your customer explicitly creates a Tashlight account and chooses to save credentials there.
All credentials saved by the customer are end-to-end encrypted using zero-knowledge architecture — Tashlight, you, and Shopify cannot read them.
3. GDPR & data deletion
We honor the three mandatory Shopify GDPR webhooks:
customers/data_request— we hold no customer PII tied to your shopcustomers/redact— same; nothing to redactshop/redact— 48h after uninstall, all shop data is permanently deleted
4. Subprocessors
Tashlight runs on Cloudflare (compute) and Supabase (Postgres, EU region). No data is sold or shared with third parties for marketing.
5. Contact
Data Protection Officer: privacy@tashlight.com