This page is the plain-language summary of how RivalEdge handles data — the same commitments formalized in our Privacy Policy. The short version: public data in, narrow product access (read your catalog + apply prices you approve), nothing private touched.
What we access
- Public competitor catalogs— product, price, variant, and stock feeds that any shopper’s browser can read. No private, customer, or order data of those stores.
- Your product catalog— through Shopify’s official API, used only to match your products to competitors.
- The contact details you give us — email and niche, only if you request an audit report or install the app.
Shopify scopes we request
read_products— read access to your product catalog, to match against competitors and build your action list.write_products— write access used only to apply price changes you approve: one click on a recommendation, or rules-based auto-reprice you configure (opt-in, with a price floor). It changes nothing but the product price, and only when you’ve approved it.
Those are the only scopes we request. We do notrequest access to orders, customers, or financials, and we never edit anything other than product prices you’ve explicitly approved (one-click apply, or your own auto-reprice rules). You can use RivalEdge purely for recommendations and apply changes yourself if you prefer.
What we never touch
- Customer personal data or order history.
- Payment or financial data — billing is handled entirely by Shopify.
- Anything behind a competitor’s login or private API.
How it’s protected & how long we keep it
- Store access is via Shopify’s official OAuth with a narrow product scope (read your catalog + apply prices you approve); data is transmitted over TLS.
- Competitor observations are retained per your plan’s price-history window and downsampled beyond it.
- Uninstalling the app stops monitoring and deletes your store’s stored data on the next retention cycle; we honor Shopify’s redaction webhooks.
- Every email includes a one-click unsubscribe honored via a suppression list.
Compliance
We support Shopify’s mandatory GDPR data-request and redaction webhooks (customers/data_request, customers/redact, shop/redact). Since we do not store store-customer personal data, customer-redaction requests have nothing to remove on our side; shop-redaction deletes that shop’s stored data.