Privacy Policy

Last updated: 28 July 2026

1. Overview

This Privacy Policy explains what data Selvra OS (“the Service”) collects when a merchant installs it from the Shopify App Store, why, and how it is protected. It should be read together with our Terms & Conditions.

2. Data We Collect Through Shopify's APIs

Selvra OS requests the following Shopify Admin API scopes:

  • read_products — product variant prices and a cost-of-goods metafield, used to calculate margin.
  • read_orders — line-item quantities and product references from the last 60 days, used to calculate units sold per product. We do not read customer names, emails, addresses, or payment details from orders.

Separately, if you connect a Google Ads account, we read campaign, ad group, and spend/conversion data, and — only with your explicit approval or an autonomy setting you configure — make the budget, bid, and negative-keyword changes described in our Terms.

3. Data We Collect Directly From You

We authenticate merchants using Shopify's offline access token flow, which does not request or store an individual staff member's name or email — only your shop domain and an encrypted access token for the shop itself. Beyond that, we store what you directly configure in the app: cost-of-goods/margin settings, autonomy preferences (which action types run automatically vs. require approval), and your Google Ads account connection.

We also generate automated operational logs tied to your shop domain — request timestamps, endpoint paths, and error reports (via Sentry, when enabled) — used solely to operate, debug, and maintain the Service. These are not used for analytics, profiling, or marketing, and are never shared with third parties beyond the hosting and error-tracking providers necessary to process them.

4. Data We Do Not Collect

Selvra OS does not store customer-level personal data. We never persist customer names, emails, phone numbers, or shipping/billing addresses. Order data is used only to aggregate anonymous unit-sold counts per product; no order ID or customer identifier is retained after that aggregation runs.

Selvra OS has no storefront- or checkout-facing component — it operates entirely through Shopify's Admin API and has no theme app extension, script, or pixel of any kind on your storefront. We do not use cookies or any tracking technology on your customers' devices, and we do not log how customers browse or navigate your store.

5. How Data Is Protected

Shopify and Google Ads access tokens are encrypted at rest. Internal service-to-service calls between our application layers require an authenticated, private connection — our backend is never directly reachable from the public internet. We do not log request bodies, webhook payloads, or token values.

6. Where Your Data Is Processed

Selvra OS is operated by a business established in the United Kingdom. The infrastructure that stores and processes your data is hosted in the United States. This means your data is transferred outside the UK/EEA to our hosting provider as part of providing the Service. We do not use additional international sub-processors beyond Shopify, Google Ads, and our hosting and error-tracking providers, all described in this policy.

7. Shopify Mandatory Compliance Webhooks

We implement Shopify's mandatory GDPR webhooks:

  • customers/data_request and customers/redact — we hold no customer-level personal data, so there is nothing to export or delete. We log a minimal, PII-stripped acknowledgment record (shop and customer ID only, never the email or phone Shopify includes in the raw webhook) for audit purposes.
  • shop/redact— when a merchant uninstalls and Shopify sends this webhook (around 48 hours after uninstall), we permanently delete the merchant's record and everything linked to it: campaigns, actions, Google Ads connection, autonomy settings, and cached product/COGS data.

8. Data Retention

Operational data (campaigns, actions, COGS cache, autonomy settings) is retained for as long as the app is installed and is deleted on uninstall per Section 7. A minimal compliance audit log (shop domain, webhook topic, and timestamp — never customer PII) is retained after uninstall to demonstrate compliance with Shopify's webhook requirements. Automated operational logs (Section 3) are retained only as long as needed for debugging and reliability purposes and are periodically rotated.

9. Third Parties

We share data only with the services necessary to provide the Service: Shopify (platform and billing), Google Ads (campaign management, at your direction), and our infrastructure/hosting and error-tracking providers. We do not sell data or share it for third-party advertising or marketing purposes.

10. Your Rights

If you are a Shopify merchant using Selvra OS, you can request details of what data we hold or ask us to delete it by uninstalling the app (see Section 7) or by contacting us directly. If you are a customer of a store using Selvra OS, direct data requests to that store — we hold no customer-level data ourselves (Section 4).

11. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be reflected here with an updated “Last updated” date.

12. Contact

For privacy questions or data subject requests, contact us at privacy@selvraos.com or via the Contact page.