Skip to content

Data requests

Last updated

To request access, deletion, or correction of data StorePilot holds, email hello@usestorepilot.com with your store's .myshopify.com domain. We aim to respond within 30 days. Requests filed through Shopify's own privacy tools reach us automatically — no email needed.

What you can request

  • Access: a copy of the data StorePilot holds about your store, or about one of your customers.
  • Deletion: erasure of that data (GDPR "right to be forgotten" / CCPA deletion).
  • Correction: fixing data that's inaccurate.

Merchants can ask directly. A shopper's request about their data on your store should go through you (the merchant) or through Shopify's privacy tools — for your store's data, you are the controller and StorePilot processes on your behalf.

How to make a request

Email hello@usestorepilot.com and include:

  • Your store's .myshopify.com domain — it's how StorePilot's data is keyed, so we can't locate anything without it.
  • What you're asking for: access, deletion, or correction.
  • For a request on behalf of a customer: whatever the customer gave you to identify themselves. Do read the note below on what we can actually link to a person.

Where possible, write from an email address associated with the store so we can verify the request is really yours.

Shopify-initiated requests are automatic

When a privacy request is filed through Shopify (for example, from your admin's customer privacy tools), Shopify notifies every installed app. StorePilot receives those webhooks — customer data request, customer redact, and shop redact — and runs the corresponding lookup or deletion automatically. Uninstalling the app triggers the shop-level deletion the same way: Shopify sends a shop-redact request and we delete the store's data on receipt.

What to expect

  • We aim to acknowledge your email within a few business days, and to complete every request within 30 days of receiving it.
  • We'll confirm in writing what we found and, for deletions, what was removed.
  • If we can't act on a request (for example, we can't verify it came from the store owner), we'll say so and explain why.

A note on what we can link to a person

StorePilot's behavior data is keyed to opaque, rotating session IDs and holds no direct customer identifiers — no names, no emails, no IP addresses, no customer account IDs. That means we usually cannot connect stored events to a specific person, so an access or deletion request about an individual customer typically comes back as "no personal data held". We run the check for every request and confirm the result in writing — we don't just assume it. Your store's customer and order records live with Shopify and your store, not with StorePilot; requests about those go to the store or to Shopify.

What StorePilot holds

What the app collects, how consent works, and how long data is kept are described in the app privacy policy. This website's own data practices (waitlist, contact form, analytics) are covered by the website privacy policy.

This page is provided for transparency and is not legal advice. Final wording should be reviewed by counsel before relying on it.