Privacy Policy
Privacy Policy
Last Updated: November 21, 2025
At screets, we respect your privacy and are committed to protecting your personal information. This Privacy Policy explains how we collect, use, store, and protect your data when you interact with our website and products, including our Shopify app Umay Search & Filter.
This policy applies to all current and future products and services offered by screets.
1. Who We Are
screets is a personal project maintained by an individual developer, with occasional assistance from collaborators. We build small tools and applications for e-commerce businesses. Our current product in development is Umay Search & Filter, a Shopify app designed to enhance product search and filtering capabilities for online stores.
2. Information We Collect
2.1 Information You Provide Directly
- Email Address: When you subscribe to our mailing list for updates and early access notifications.
- Contact Information: Any information you provide when contacting our support team.
2.2 Information Collected Through Our Shopify App
- Shop Information: Store name, shop domain, shop owner email, and basic shop configuration.
- Product Data: Product titles, descriptions, variants, prices, availability, tags, and product metadata necessary for search and filtering functionality.
- Collection Data: Collection names, descriptions, and organization structure.
- Search Analytics: Search queries performed by store visitors (not linked to individual customers), search result performance, and aggregated usage statistics.
2.3 Automatically Collected Information
- Technical Data: IP address, browser type, device information, and access timestamps.
- Usage Data: How merchants interact with our app interface, feature usage patterns, and app performance metrics.
- Cookies: We use essential cookies to maintain authentication and app functionality.
3. How We Use Your Information
3.1 Service Delivery
- Providing and improving search and filtering functionality for Shopify stores.
- Processing and displaying product catalog information.
- Generating AI-powered search intent analysis to improve search results.
- Maintaining app performance and stability.
3.2 Communication
- Sending update notifications and product announcements to subscribers who opted in.
- Responding to support inquiries and technical issues.
- Providing important service-related notifications.
3.3 Analytics and Improvement
- Analyzing search patterns to improve our AI algorithms.
- Understanding how merchants use our app to enhance features.
- Identifying and fixing technical issues.
- Conducting internal research and development.
3.4 What We Do NOT Do
- We do not sell, rent, or trade your personal information to third parties.
- We do not use your data for targeted advertising.
- We do not share merchant or customer data with competitors.
- We do not track individual end-customer behavior across stores.
4. Data Storage and Infrastructure
4.1 Cloudflare D1 Database
- Stores merchant account information.
- Stores shop configuration and settings.
- Stores product and collection catalog data synchronized from Shopify.
- Stores aggregated analytics data (search queries, performance metrics).
4.2 Cloudflare Workers KV
- Caches AI-generated search intent data for commonly searched terms.
- This data is not shop-specific and helps optimize app performance across all users.
- No personal or customer-identifying information is stored in KV.
4.3 Cloudflare Workers
- Hosts our application logic and API endpoints.
- Processes requests between Shopify stores and our services.
4.4 Security Measures
- Encryption at Rest: All data stored in Cloudflare D1 is encrypted using AES-256 encryption.
- Encryption in Transit: All data transmission uses TLS/SSL encryption.
- Access Controls: Strict authentication and authorization mechanisms protect data access.
- Regular Security Audits: We continuously monitor and improve our security practices.
5. Data Retention
- Active Merchants: Data is retained while the app is installed and actively used.
- After App Uninstall: Shop and catalog data is deleted within 48 hours of app uninstallation, as required by Shopify's privacy policies.
- Email Subscribers: Email addresses are retained until you unsubscribe or request deletion.
- Analytics Data: Aggregated, anonymized analytics may be retained longer for product improvement purposes.
- Legal Requirements: Some data may be retained longer if required by law or for legitimate business purposes (e.g., resolving disputes, enforcing agreements).
6. Third-Party Services
6.1 Shopify
Our app integrates with Shopify's platform and APIs. We access merchant data through Shopify's Storefront API and Admin API in accordance with Shopify's API Terms of Use. Shopify's own privacy policy applies to data they collect and process.
6.2 Cloudflare
We use Cloudflare's infrastructure services (D1, Workers KV, Workers) for hosting, data storage, and content delivery. Cloudflare complies with major data protection regulations including GDPR. Learn more at Cloudflare's Trust Hub.
6.3 AI Processing
Search intent analysis uses AI models to improve search results. This processing does not involve personal customer information and operates on anonymized search query patterns.
7. Your Rights and Choices
7.1 Access and Portability
- Request a copy of the personal data we hold about you.
- Request data in a structured, commonly used format.
7.2 Correction and Updates
- Update or correct inaccurate information.
- Merchants can update shop data directly through their Shopify admin.
7.3 Deletion and Erasure
- Request deletion of your personal information.
- Uninstalling the app automatically triggers data deletion within 48 hours.
- Email subscribers can unsubscribe at any time.
7.4 Restrict Processing
- Request limitations on how we process your data.
- Opt out of non-essential communications.
7.5 Object to Processing
- Object to certain types of data processing.
- Withdraw consent where processing is based on consent.
7.6 How to Exercise Your Rights
To exercise any of these rights, please contact us at hi@screets.io. We will respond to your request within 30 days.
8. Children's Privacy
Our services are not intended for individuals under the age of 13 (or under 16 in the European Economic Area). We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a child, please contact us immediately.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. We use Cloudflare's global network, which maintains compliance with international data protection regulations including GDPR through appropriate safeguards such as Standard Contractual Clauses.
10. Data Protection for European Users (GDPR)
- We process data based on legitimate interest, contractual necessity, or consent.
- You have the right to lodge a complaint with your local data protection authority.
- We maintain appropriate technical and organizational measures to protect your data.
- Data transfers outside the EEA are protected by appropriate safeguards.
11. California Privacy Rights (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose.
- Right to request deletion of your personal information.
- Right to opt out of the sale of personal information (we do not sell personal information).
- Right to non-discrimination for exercising your privacy rights.
12. Compliance with Privacy Laws
- Subscribing to mandatory GDPR webhooks (customer data requests, customer redaction, shop redaction).
- Processing data deletion requests within required timeframes.
- Maintaining data processing agreements as required by law.
- Implementing appropriate security measures to protect personal data.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of significant changes by:
- Posting the updated policy on our website with a new "Last Updated" date.
- Sending email notifications to subscribers if changes materially affect how we handle their data.
- Displaying in-app notifications to merchants for significant policy updates.
Your continued use of our services after changes take effect constitutes acceptance of the updated policy.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or how we handle your personal information, please contact us:
We will respond to your inquiry within 30 days.