Last updated: August 11, 2026
Who operates the app
AD Ready Store Auditor is operated by R.I.D. LLC / RID Marketing. Questions about this policy or the app’s handling of information can be sent to info@rid.marketing, by phone at +1 (929) 800-2110, or through rid.marketing.
Information received from Shopify
When a merchant installs or uses the app, Shopify provides the shop domain and OAuth session information needed to authenticate the store. The app stores Shopify access tokens and session metadata so authorized merchants can use embedded app features.
During a scan, the app reads store and merchant-facing information made available by its approved scopes, including shop details, products and variants, product media, legal policies, online-store pages, collections, and the primary storefront domain. It also retrieves the public storefront and a limited set of internal storefront links to run rules-based readiness checks.
The app does not request Shopify customer or order scopes and is not designed to retrieve customer records or order records.
Information created through app use
- Saved scan results, scores, findings, and scan timestamps.
- Free-scan usage counts.
- Billing purchase identifiers, unlock status, and unlock time.
- Feature-request type, message, store context, and submission time.
- Final Readiness Checklist completion states, timestamps, and optional merchant notes.
Why information is processed
Information is used to authenticate the merchant, run and save store readiness audits, show category reports, enforce free-scan and paid access rules, recover approved Shopify billing purchases, operate the checklist, receive feature feedback, provide support, maintain security, and comply with Shopify platform obligations.
Service providers and hosting
Shopify provides authentication, Admin API access, embedded app services, billing, and webhook delivery. Google Cloud Run hosts the application, Google Secret Manager stores protected runtime credentials, and Neon provides the PostgreSQL database. These providers process application data only as needed to operate and secure the service. Provider details may be updated when production infrastructure changes.
Security practices
The app uses Shopify authentication and webhook signature validation, limits access by shop, validates server-side actions, and avoids placing access tokens or webhook payloads in normal application logs. No system can guarantee absolute security, and safeguards may evolve as the app and its hosting environment change.
Retention and deletion
Session, scan, billing, feature-request, and checklist information is retained while needed to provide the app and meet operational or legal obligations. Shopify’s delayed shop/redact compliance webhook triggers deletion of stored records owned by that shop, including sessions, scan usage, feature requests, and checklist progress.
Shopify privacy requests
The app authenticates Shopify’s required customer data-request and customer-redaction webhooks. Because it does not request or store customer or order records, those requests are acknowledged without creating customer data. Shop-redaction requests delete shop-owned app records idempotently.
Merchant choices and rights
Merchants may contact R.I.D. LLC / RID Marketing to ask about stored app information, request correction where appropriate, or raise a deletion or privacy concern. Applicable rights can vary by location and request. Shopify account and platform data may also be managed through Shopify.
Policy changes
This policy may be updated when the app, its data practices, or legal requirements change. The revised policy will be posted on this page with an updated date.