Last updated: 2026-10-07
Merch Autopilot ("the app") is operated by Braden.Co, 111 N Oak St #1001, Sallisaw, OK 74955, United States. You can reach us at braden.cobusiness@gmail.com.
This policy explains what the app does with data when a merchant installs it on their Shopify store.
The app ranks the products inside a Shopify collection by commercial performance and proposes a new display order. A merchant reviews the proposal and explicitly approves it before anything is changed. That is the app's entire function.
With the merchant's permission, the app holds exactly two Shopify permissions: write_products and read_orders. It asks for nothing else.
Under write_products, for product and collection data:
Under read_orders, for order line economics over the merchant's chosen sales window (at most 60 days):
The app does not request and does not read:
This is not a promise about how we behave. The queries the app sends do not mention those fields, the data structures it uses have nowhere to put them, and automated tests fail the build if any of that changes.
Order data is never stored. It is read when a merchant opens a collection, used in memory to calculate how each product performed, and discarded when the request ends. Nothing is cached.
The app stores a merchandising audit trail. Each time it proposes or applies a reorder it records: the store's domain, which collection was affected, which products moved and to which positions, the ranking version, and a plain-English reason for each product's placement.
Those reasons include figures calculated from orders — for example “generated $1,240 in net revenue over 30 days”. These are totals for a product over a period of time. They contain no order, no purchase and no person, and no individual transaction can be identified from them.
Audit records are deleted 180 days after they are created. That is enforced by the app itself, which sweeps daily, and not only stated here. Records are also deleted in full when a store asks to be erased — see below.
The app stores its Shopify access credentials for each store, so it can work on the merchant's behalf. If a merchant signs in with a personal Shopify staff account, Shopify may also provide that staff member's name and email; these belong to the merchant's own team, not to shoppers. Credentials are deleted the moment the app is uninstalled.
The app stores one row of preferences per store: the store's domain and the number of days of sales history to rank on. It holds no personal data.
Shopify tells the app immediately, and the store's access credentials are deleted at once. The merchandising audit trail and the store's preferences are NOT deleted at that moment — a merchant who uninstalls and reinstalls within 48 hours keeps their history and their settings, which is what almost everyone doing that wants.
48 hours after the uninstall, Shopify sends a shop erasure request and everything else for that store is deleted: the audit trail, the preferences, and any session record that remained. After that the app holds nothing about the store at all.
If you are a shopper who has bought from a store using this app: we hold no personal data about you. We do not know your name, your email address, your address, or which orders are yours. We cannot identify you, because we never receive anything that would let us.
If you ask the store you bought from to provide or delete your data, Shopify forwards that request to us automatically. We search every record we hold for that store for any reference to you or your orders, and report or delete whatever we find. In practice there is nothing to find, and we say so.
To exercise any right, contact the store you purchased from. They are the controller of your data; we only process product performance information on their behalf.
A merchant can have every trace of their store deleted without contacting anyone: uninstall the app. Credentials go immediately and everything else within 48 hours, automatically, through Shopify's own erasure request.
Merchants may also request a copy of their data, or have it corrected, at braden.cobusiness@gmail.com.
Nobody. The app does not sell data, does not share it with advertisers, does not use it to train machine learning models, and does not send it to any analytics or marketing service. It has no analytics SDK, no error-tracking service and no email provider, and a test fails the build if one is added without this section being updated.
The app's only sub-processors are:
All traffic between the app, Shopify and a merchant's browser uses TLS. Every incoming webhook is verified against Shopify's signature before it is acted on, and one that fails is rejected before any handler runs.
Access credentials are held in the app's database and used only to make requests to Shopify on the merchant's behalf. The database is not reachable from the public internet: it accepts connections only from the app, over a private network.
We update this policy when the app's data handling changes, and update the date at the top. The policy is generated from the app's own source code, so a change to what the app reads or keeps changes this page in the same release.