01Overview & Scope
This Privacy Policy describes how MHIRI SOFTWARE (“we”, “our”, or “us”) collects, accesses, uses, and safeguards data when Shopify merchants install and interact with the ProfitGuard application (“the App”).
ProfitGuard is designed from the ground up on the principle of data minimization. The App evaluates product profit margins across your Shopify store catalog by contrasting retail prices against inventory unit costs (COGS), payment processing rates, shipping weight tier matrices, and expected return drag. The App does not operate as a customer profiling, marketing, or behavioral tracking system.
02Data We Collect & Purpose
To provide SKU profit analysis and facilitate one-click price corrections directly to your live store, ProfitGuard accesses and retains strictly the minimum operational data required:
| Data Category | Specific Data Points | Purpose |
|---|---|---|
| Catalog & Inventory | Shopify Product & Variant IDs, Product Titles, Variant Titles, SKUs, Retail Prices, Variant Weights, Weight Units, and Inventory Unit Costs (Cost per item). | Determining gross and net profit margins, computing break-even thresholds, and pushing updated prices back to Shopify upon merchant authorization. |
| Store Baseline Settings | Payment gateway percentage cut, fixed transaction fee, average units per order, tiered weight delivery amounts, and return drag percentage reserves. | Modeling realistic cost deductions to derive accurate SKU net unit economics. |
| Per-Variant Cost Overrides | Custom shipping dollar overrides, custom refund percentages, and optional internal notes set by the merchant. | Refining profit calculations for oversized, fragile, or high-return merchandise. |
| Order Volumes (Aggregated) | Product variant IDs and numerical quantities sold per transaction. | Computing realized cumulative financial drag (total dollars lost) on unprofitable products. |
03Zero Customer Personal Data (No Customer PII)
When orders occur in your store, our automated background worker inspects the payload only to read line items (identifying which Variant ID was purchased and how many units were sold). We explicitly bypass, ignore, and discard:
- Customer full names, first names, and last names
- Physical billing, delivery, and residential addresses
- Email addresses and telephone numbers
- IP addresses, device user agents, and geolocation records
- Credit card numbers, bank details, and payment transaction identifiers
04Infrastructure & Hosting Subprocessors
We do not sell, license, rent, or trade merchant or store data. Information is processed exclusively via reputable, enterprise-grade infrastructure providers adhering to strict security standards:
- Shopify Inc.: Provides the merchant authorization framework (OAuth 2.0) and Admin GraphQL API used to sync catalog items and write back price revisions.
- Cloud Infrastructure & Databases: Hosted in secure, isolated Linux containers running PostgreSQL for relational persistence and Redis for asynchronous queue state handling.
05Security & Encryption
We employ layered technical and operational safeguards designed to prevent unauthorized access, exposure, or tampering:
- Transport Layer Security (TLS): All web traffic between merchants, Shopify APIs, and ProfitGuard servers is enforced using modern HTTPS/TLS 1.3 encryption.
- Encryption at Rest: Persistent database volumes storing store baseline configurations and catalog snapshots are protected behind firewalled private container networks.
- Access Token Isolation: Shopify offline access tokens are restricted, stored securely via hashed session storage mechanisms, and never exposed to public browser scripts.
06Retention & GDPR Automated Erasure
Store catalog snapshots, cost overrides, and baseline configurations remain active in our database only while the App remains installed on your store.
In strict adherence to Shopify’s Partner Program requirements and international privacy laws (GDPR, UK GDPR, and CCPA/CPRA):
- Uninstall Webhook: When an
app/uninstalledevent is received, an automated cleanup worker purges the store record, sessions, cached metrics, and all related catalog snapshots within 48 hours. - Mandatory GDPR Webhooks: We actively listen to Shopify’s compliance endpoint (
/webhooks/compliance). In the event of ashop/redactevent, all historical store records are permanently deleted. - Customer Requests: Because ProfitGuard stores zero customer PII, any
customers/data_requestorcustomers/redactpayloads receive a direct, verified response confirming that no customer records exist in our database.
07Merchant Rights & Data Controls
As a Shopify merchant using ProfitGuard, you retain full rights over your store information:
- Right of Access: You can view all margin metrics, baselines, and catalog evaluations directly in your Dashboard at any time.
- Right of Export: Pro merchants can export their entire SKU net margin audit as a CSV file for local archival or accounting analysis.
- Right of Rectification: You can edit cost overrides, recalculate baseline percentages, or trigger a complete catalog resync whenever your numbers change.
- Right of Erasure: Uninstalling the App triggers full database deletion. You may also email our support desk at any time to request immediate manual removal of your store profile.
08Contact & Legal Entity
ProfitGuard is owned and operated by MHIRI SOFTWARE. If you have questions regarding this Privacy Policy, our data handling practices, or our compliance posture, please contact us:
MHIRI SOFTWARE – Privacy & Data Protection
Company: https://mhirisoftware.com
Product: https://profitguard.mhirisoftware.com
Email: support@mhirisoftware.com
Inquiries receive responses within 1 to 2 business days.