Privacy Policy
EPOC Analytics Dash Shopify App Privacy Policy
Effective date: June 02, 2026
This Privacy Policy explains how EPOC Studios ("EPOC", "we", "us", or "our") collects, uses, stores, and protects information in connection with the EPOC Analytics Dash Shopify app, hosted at connect.epoc.studio.
The EPOC Analytics Dash Shopify app is a read-only Shopify connector used to send approved Shopify store data into EPOC reporting, analytics, product visibility, and inventory analytics workflows. It supports the EPOC Dashboard and related EPOC analytics systems. It is intended for merchants, client organizations, and authorized EPOC users, not for consumer use.
If a separate written agreement between EPOC and a client organization applies to the same data, that agreement controls where it conflicts with this Policy.
1. Our role
For Shopify store, order, product, inventory, and reporting data processed for a merchant or client organization, EPOC generally acts as a service provider or processor on behalf of that merchant or client organization.
For app operation, security, troubleshooting, installation management, compliance webhooks, and internal administration, EPOC may act as an independent controller.
2. Information we collect
We collect only the information needed to install the app, maintain the Shopify connection, sync approved read-only Shopify data, operate analytics workflows, and satisfy Shopify platform requirements.
2.1 Shopify store and installation information
- shop domain and myshopify.com domain
- Shopify shop identifier and store metadata
- app installation status
- app scopes approved by the merchant
- installation, reconnection, token refresh, and uninstall timestamps
- connection status, sync status, and error state
- account mapping information used to connect the store to the correct EPOC Dashboard account
2.2 Shopify product, variant, catalog, and inventory information
- product IDs, product titles, handles, descriptions, URLs, vendors, product types, tags, status, and publication state
- product and variant image URLs and related image metadata
- variant IDs, SKUs, titles, options, prices, compare-at prices, barcodes, and inventory item identifiers
- inventory quantities, inventory policy, inventory tracking state, and inventory location signals where enabled
- product collections and catalog metadata where available under approved scopes
This data is used for product visibility, inventory analytics, forecasting inputs, stock-risk review, merchandising context, and reporting inside EPOC analytics systems.
2.3 Shopify order, sales, refund, and reporting information
- order IDs and order timestamps
- order totals, subtotal, discounts, taxes, shipping, refunds, returns, and net sales
- line-item product IDs, variant IDs, SKUs, quantities, prices, discounts, and fulfillment-related signals
- reporting aggregates made available by Shopify
- historical order/reporting data where authorized for analytics lookback windows
This data is used to calculate sales performance, blended reporting, product velocity, inventory forecasting inputs, and merchant analytics. EPOC does not use this app to write orders, alter products, modify inventory, or change store configuration.
2.4 App session and operational records
- Shopify session identifiers and OAuth state values
- encrypted access tokens and related credential metadata
- webhook delivery metadata and verification state
- sync job records, sync timestamps, retry counts, and error logs
- app health, diagnostic, and security logs
- admin/operator audit records for connection handoff and account mapping
2.5 Customer personal information
The app is designed primarily for business analytics and operational reporting. Depending on the approved Shopify scopes and the merchant's store data, limited customer personal information may appear in order or line-item data, such as customer identifiers or contact-related fields made available by Shopify.
EPOC does not use this app to sell customer personal information. EPOC limits use of any customer personal information to providing the app, analytics, reporting, security, troubleshooting, compliance, and merchant support.
3. How we use information
- authenticate and maintain the Shopify app installation
- connect or reconnect a Shopify store to EPOC analytics systems
- sync approved Shopify sales, reporting, product, variant, inventory, and catalog data
- power EPOC Dashboard reporting and related analytics workflows
- support product visibility, inventory analytics, sales velocity, and forecasting inputs
- map Shopify stores to the correct merchant, client organization, or EPOC account
- monitor connection health and sync reliability
- investigate errors, abuse, unauthorized access, and security events
- satisfy Shopify platform, webhook, and compliance requirements
- provide merchant, client, and internal operational support
4. Shopify access scopes
The app requests read-only Shopify access scopes needed for analytics and inventory workflows. Current configured scopes may include:
read_productsread_inventoryread_ordersread_all_ordersread_reports
The exact scopes presented to a merchant during installation are shown in Shopify's authorization screen. EPOC does not request write scopes for this app unless the app is later updated and the merchant approves the revised scopes.
5. How we share information
- the merchant or client organization that authorized the app
- authorized EPOC staff and service providers who need access to operate analytics, reporting, support, security, or infrastructure
- hosting, database, logging, monitoring, email, and security vendors used to operate the app and EPOC analytics systems
- Shopify, as required to operate the app, validate webhooks, handle app lifecycle events, and comply with platform requirements
- regulators, courts, or other parties when required by law or necessary to protect rights, safety, and security
We do not sell merchant data or customer personal information.
6. Data storage and security
- encrypted storage for Shopify access tokens and integration credentials
- restricted access for authorized personnel
- HTTPS for app traffic
- webhook verification and OAuth-based installation flows
- logging and audit records for sensitive operational events
- least-privilege access patterns where practical
No method of transmission or storage is completely secure. We work to protect information, but cannot guarantee absolute security.
7. Retention
We retain Shopify app data for as long as needed to provide analytics services, maintain business records, troubleshoot issues, satisfy legal or contractual obligations, and support security and compliance.
When a merchant uninstalls the app, EPOC will stop active app-based syncs for that store. Some historical analytics records, logs, backups, or derived business records may be retained where needed for legitimate business, legal, security, or contractual purposes, unless deletion is required by applicable law or platform obligations.
8. Shopify compliance webhooks and deletion requests
The app supports Shopify compliance webhook topics including:
customers/data_requestcustomers/redactshop/redact
EPOC uses these webhooks to review and process Shopify privacy and deletion obligations associated with the app. Merchants or authorized users may also contact EPOC directly using the contact information below.
9. Merchant choices and controls
- review requested scopes during Shopify authorization
- uninstall the app from the Shopify admin
- contact EPOC to request support, correction, deletion, or review of app-related data
- request clarification about which EPOC account or analytics workspace is connected to the store
Uninstalling the app may disable Shopify-powered analytics, reporting, product visibility, and inventory workflows in EPOC systems.
10. International processing
Information may be processed in the United States or other locations where EPOC or its service providers operate. By installing or using the app, the merchant authorizes processing in those locations, subject to applicable law and agreements.
11. Changes to this Policy
We may update this Policy from time to time. The updated version will be posted at the app's public privacy policy URL or otherwise made available through EPOC-controlled channels. The effective date above indicates when the Policy was last updated.
12. Contact
For privacy questions, requests, or Shopify app data inquiries, contact:
EPOC Studios
Email: admin@epocstudios.online