Legal
Privacy policy
Last updated August 20, 2026
Store Locator Pro requests no Shopify data scopes. It cannot read your products, orders, customers, or any other store record. It stores the store locations you import, your widget settings, and anonymous search counts — nothing else.
Who this covers
“We” means the developer of Store Locator Pro (the “app”). “You” means the Shopify merchant who installs it. “Shoppers” means visitors to your storefront who use the store locator widget.
What the app accesses from Shopify
The app is installed with an empty access-scope list. Shopify therefore grants it no permission to read or write your products, orders, customers, inventory, or content. The only Shopify data it holds is what authentication requires:
- Your shop domain and access token — required to keep you signed in to the embedded admin and to receive webhooks.
What you give the app
- Store locations. The business records you import by CSV or enter by hand: name, address, coordinates, phone, email, website, images, social links, opening hours, and tags. These describe your retail locations, not individual people.
- Widget settings. Colors, labels, custom CSS, map provider choice, and any map API key you choose to supply.
- Import jobs. Progress and per-row validation results, kept so an interrupted import can resume.
What the app records about shoppers
When a shopper searches your locator, the app writes one analytics row containing the search text, whether any store matched, how many results were returned, and an approximate coordinate for the heatmap. Coordinates from a shopper’s device location are rounded to roughly one kilometre before they are stored.
These rows carry no shopper identifier — no name, no email, no customer ID, no session ID, no IP address, and no advertising identifier. They cannot be traced back to an individual. Analytics rows are deleted automatically once they are 90 days old.
Forms you can switch on
Two optional features collect information from people directly. Both are off unless you turn them on, and while a feature is off its form accepts nothing at all.
- Stockist applications. A retailer applying to appear on your map submits their business name, address, phone, email, website, and an optional message. These describe a business, and once you approve one it becomes a location on your map.
- Shopper messages. If you enable the “Contact this store” button, a shopper submits their name, email, and message. This is personal data. It is shown only to you, in the app’s Inbox, so that you can reply.
Neither form stores the sender’s IP address. An IP address is read in memory to rate-limit submissions and is discarded immediately; it is never written to the database.
Who else receives data
- Geoapify — when you import or edit a location, its address is sent to Geoapify to convert into map coordinates. Shopper-typed searches are also geocoded so results can be sorted by distance. When a shopper asks for nearby stores without sharing their device location, the shopper’s IP address is sent to Geoapify once to estimate an approximate area; the app does not store the IP address. See the Geoapify privacy policy.
- Google — when the Help page says answers are written by AI, every question you ask it is sent to Google’s Gemini API to compose the reply. Sent with it: the conversation so far in that chat, and the app’s own documentation — our help guides and an internal support handbook describing how the app works. Nothing else goes with them: not your store name, not your locations, not shopper messages or stockist applications. If the Help page instead says answers come from our help guides, no assistant is configured and no request is made at all. See the Google privacy policy.
- Your chosen map provider — the built-in map loads tiles from its provider. If you supply your own Google Maps or Mapbox key, shoppers’ map requests go to that provider under your account and their terms.
- Our hosting and database provider — stores the data above on our behalf.
We do not sell your data, and we do not share it for advertising.
How long data is kept
- Analytics rows — deleted automatically after 90 days.
- Locations, settings, and import jobs — kept until you delete them or uninstall the app.
- Shopper messages — deleted automatically 90 days after you mark a message as handled.
- Stockist applications — kept until you delete them or uninstall, because an approved application is the record behind a location on your map.
- On uninstall — your session, locations, settings, and analytics are deleted when Shopify sends the uninstall webhook.
- On a Shopify erasure request — a
shop/redactwebhook deletes all remaining locations, settings, import jobs, analytics, form submissions, and sessions for your shop. Acustomers/redactwebhook deletes any shopper message sent from that person’s email address, and acustomers/data_requestmakes those messages available so you can supply them.
Security
Traffic to the app is served over HTTPS. Storefront requests reach the app through Shopify’s signed app proxy, and admin requests are verified with Shopify session tokens. Access tokens are stored server-side and are never exposed to the storefront.
Your rights
You can export or delete your location data at any time from the app’s Locations page, and export analytics from the Analytics page. Uninstalling removes your data as described above. Depending on where you live, you may also have the right to request a copy of your data, correct it, or ask us to erase it — write to us and we will action it.
Changes
If this policy changes materially, the date at the top of this page is updated and, where the change affects how merchant data is handled, we notify installed merchants.
Contact
Questions or requests: storelocatorprohelp@gmail.com