Skip to content
ShopGrade logo ShopGrade
Menu Product For agencies For brands Sample report Pricing Sign in Add to Chrome
Sign in Add to Chrome
Legal

Privacy Policy

Last updated: July 31, 2026 · Applies to shopgrade.in and the ShopGrade Chrome extension

The short version

ShopGrade stays dormant until you consent. It checks HTTPS pages for Shopify markers and deeply analyzes only confirmed, publicly accessible Shopify storefronts. On those stores it processes public page text and structure, URLs, resource timing, and performance signals. It never reads form values, passwords, private messages, or network request and response bodies. Individual audit data is local by default; optional AI, sharing, monitoring, and Agency workspace features send the data described below.

Who controls your data

ShopGrade provides the ShopGrade Chrome extension, shopgrade.in, and related services, and is the controller of personal data described in this policy. Contact support@shopgrade.in for privacy questions or requests.

How storefront analysis works

After you choose Agree and enable Shopify audits, the extension can run on HTTPS pages so it can recognize Shopify storefronts on custom domains. On unconfirmed pages it performs only the checks needed to determine whether Shopify markers are present. Deeper analysis starts only after a page is confirmed as a public Shopify storefront.

On a confirmed store, ShopGrade processes the current URL and hostname; visible public text; titles, meta tags, links, buttons, images and alt text; structured data; Shopify theme and app indicators; page structure counts; resource URLs, sizes and timing; and browser performance signals such as LCP, CLS, INP, FCP, TTFB and long tasks. This is website content and web-browsing activity under Chrome Web Store terminology, even though it concerns a public storefront.

The extension does not read form-field values, passwords, private messages, browser history outside pages where it runs, payment-card data, or network request and response bodies. It does not sell data or use it for advertising.

Optional screenshots and AI analysis

Visual AI analysis runs only after you confirm the disclosure. ShopGrade asks Google PageSpeed to render the audited store's public homepage and optional product page in an isolated server-side browser without your Chrome cookies. It then sends those rendered screenshots together with the store URL, measured audit metrics, industry, and any monthly revenue you entered to OpenAI. It never captures or sends your normal-profile session.

Other AI report features may send the audited store URL, measured storefront findings, report settings, industry, currency and optional monthly revenue to OpenAI when you request the feature. AI output and modeled revenue opportunities are advisory estimates, not guarantees.

Other data we process

  • Account and authentication: name, email address, account identifiers, verification/recovery state, authentication session tokens, and Google OAuth data if you choose Google sign-in.
  • Preferences and report inputs: persona, agency/store name, logo, brand color, prepared-by name, audit focus, thresholds, excluded domains, industry, currency, and optional monthly revenue.
  • Usage and anti-abuse: plan, billing period, report quota, report credits, a per-install identifier, a coarse client-provided SHA-256 device marker, and keyed one-way request/network markers derived from the client IP that Appwrite supplies to our function. These signals enforce free-quota and hosted-report request limits, not advertising; ShopGrade does not store the raw IP in these records.
  • Billing records: Paddle customer/subscription identifiers, plan and status. Paddle, our Merchant of Record, handles card and payment details; ShopGrade does not receive card numbers.
  • Monitoring: store URL, last score, change thresholds, schedule, and alert destination when you explicitly enable a monitor.
  • Team and client workspace: team membership, roles, invite email addresses, client/store names, notes, stages, folders, tags, scores, dates, LCP/CLS/INP values, and audit history for Agency workspace collaboration.
  • User-generated reports: audit data and eligible branding uploaded when you generate a secure server-hosted report.

Where data is stored and shared

  • Individual workspace: settings, leads and audit history are stored in Chrome extension storage on your device by default.
  • Agency workspace: client records and audit history are synchronized to ShopGrade's Appwrite backend so authorized team members can collaborate across devices.
  • Shared reports: generation uploads the report and eligible branding to the backend. It is available only to people who possess its unguessable capability link, is blocked and automatically deleted after 15 days, and can be permanently deleted sooner from your account.
  • Account, quota, monitoring and team records: stored with Appwrite in its Frankfurt (EU) region.

Website analytics and cookies

shopgrade.in offers optional Google Analytics 4 to measure aggregate visits, viewed pages, referrals, and device/browser information. Google Analytics is not loaded until you select Accept analytics. Essential site functions remain available if you choose Essential only. The extension itself does not include Google Analytics.

Your choice is stored in your browser's local storage. You can accept, reject, or withdraw consent at any time through Cookie settings in the site footer. Withdrawing clears accessible ShopGrade analytics cookies and reloads the page to stop analytics. Google's processing is described in the Google Privacy Policy.

Processors and service providers

  • Appwrite: authentication, account, workspace, report, monitoring and quota storage.
  • OpenAI: user-requested AI analysis of storefront audit data and, for visual analysis, screenshots.
  • Google: optional Google sign-in, PageSpeed Insights/CrUX lookups using the store URL, and consent-based website analytics. The shopgrade.in website also loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com); your browser's IP address and request headers are received by Google to deliver the fonts.
  • jsDelivr (Cloudflare/Fastly CDN): the shopgrade.in website and account portal load the Appwrite JavaScript SDK from cdn.jsdelivr.net; your browser's IP address and request headers are received by the CDN to deliver the script.
  • Paddle: payment processing and subscription administration as Merchant of Record. The checkout page loads Paddle.js from Paddle's domains to run the secure checkout overlay.
  • Resend: all transactional and account email. This includes account-security messages - email-address confirmation links and password-reset links - as well as monitor alerts and team invitations. Your email address, and the single-use link, are transmitted to Resend to deliver these messages.

Legal bases, retention and transfers

Where GDPR or similar law applies, we process account, quota, requested reports, sharing, monitoring and team features to perform our contract with you. We use legitimate interests for service security, fraud prevention, debugging and abuse controls. We rely on consent for automatic storefront analysis, optional visual AI capture, and website analytics; you may withdraw consent at any time, without affecting earlier lawful processing.

We keep account and billing records while your account is active and as needed for legal, tax, dispute and fraud-prevention obligations. Server-hosted reports expire after 15 days and can be deleted sooner; access is refused immediately at expiry even if physical cleanup is delayed. Keyed per-minute hosted-report request counters are removed after two days. Monitoring delivery outbox content is removed after completion and a bounded retry/audit window (no more than 60 days). Device and keyed network anti-abuse records expire after two years without activity. Account deletion removes ShopGrade profiles, reports, monitors and their alert outbox rows, workspace data, jobs, usage meters, invitations and authentication sessions; Paddle invoices, transaction records, and limited dispute or tax records may remain where Paddle or law requires them. Direct ShopGrade account identifiers are removed from retained internal credit bookkeeping. One-way hashes of the former account and Paddle customer IDs are retained for up to two years only to reject or acknowledge delayed billing events without recreating the account. Locally stored data remains until you clear extension storage or uninstall.

Some processors, including OpenAI, Google, Paddle and Resend, may process data outside your country. Where required, transfers use recognized safeguards such as adequacy decisions or standard contractual clauses provided by the processor.

Your privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to your local data-protection authority. ShopGrade does not make solely automated decisions that produce legal or similarly significant effects. Email support@shopgrade.in from your account address to exercise a right.

Deleting data

Use Reports in the account dashboard to permanently delete an individual report immediately; its link stops working and the action cannot be reversed. Use Delete account to permanently remove your ShopGrade account and backend service data; any active subscription is ended immediately. Email support@shopgrade.in if self-service deletion fails or to make a privacy-rights request. Clear extension storage or uninstall to remove local settings, leads and audit history. Ask an Agency workspace owner to remove shared client data, or contact us.

Chrome Web Store and Google API disclosure

ShopGrade's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.

Changes and contact

We will update the date above when this policy changes and provide an in-product or email notice before material changes take effect where appropriate. Privacy questions and requests: support@shopgrade.in.

See also: Terms of Service · Refund Policy
ShopGrade logo ShopGrade

A Chrome extension that audits public Shopify storefronts for conversion, trust, SEO, performance and mobile issues, and turns the findings into a prioritized report.

Product

Add to Chrome How it works Sample report Pricing FAQ

Use cases

For agencies For brands Sign in Create account

Trust

Permissions Privacy Policy Terms of Service Refund Policy Cookie settings support@shopgrade.in
ShopGrade
© 2026 ShopGrade. All rights reserved. Back to top