Filter My Blog

Privacy policy

Last updated

This page is provided for information and is not legal advice. If you need advice specific to your situation, consult a qualified professional in your jurisdiction.

This policy describes what Filter My Blog ("the app") collects when it's installed on a Shopify store, why, how long it's kept, and how you can request access to, correction of, or deletion of it. The app is developed and operated by Marti Belegu, a sole trader based in Tirana, Republic of Albania ("we," "us").

The app is installed by Shopify merchants ("you," "the merchant") on their stores. In relation to the personal data described below, the merchant is generally the data controller for data about their own staff, and we act as a processor on the merchant's behalf and, separately, as a controller for the limited operational data described in Section 3.

1. The app requests one permission

Filter My Blog requests exactly one Shopify access scope: read_content, which allows it to read your store's blogs and articles. It does not request access to customers, orders, products, or any other store data, and it holds no permission to write to your store beyond the shop metafield it creates to mirror your own filter settings back to your theme. The app does not request access to any protected customer data category.

2. What we collect from your store

The database behind the app holds the following, and nothing else:

DataWhat it isPersonal data?
Shop configurationYour shop domain, your chosen plan, and your filter settings: tag visibility, order, styling, wording.No
Staff account detailsThe name, email address and locale of the staff member who installs the app, provided directly by Shopify as part of the standard OAuth installation process, along with the access token Shopify issues to the app.Yes. This is the only personal data the app holds
Article indexA copy of each blog article's title, tags, publish date, URL, and a short excerpt (up to 300 characters), used to power blog search. Full article bodies are never stored.No
Tag and search countersDaily totals of tag impressions, tag clicks, and search terms (with how many searches for each term found no results).No individual identifiers. See Section 3 on the one exception

3. What we collect from your store's visitors

The app is built specifically to avoid collecting anything that could identify an individual shopper or reader. It does not set cookies, does not read or store IP addresses, and does not generate or store any device, session, or browser fingerprint identifier, on any plan.

Two things are recorded about how the filter bar is used, both as plain daily totals with nothing attached that identifies who was involved:

  • Tag impressions and clicks: a running count per tag, per blog, per day.
  • Search terms: a running count per search term, per blog, per day, plus how many of that day's searches for that term returned no results. This is the one piece of free text a visitor types that the app records, which is why it is kept only temporarily. See Section 5.

Full detail on exactly what is and isn't collected is also in the documentation.

4. How the data is used

  • Rendering your filter bar with your chosen settings.
  • Powering the analytics report available on the Pro plan, and the article-count and popularity-based ordering features on other plans.
  • Determining and enforcing your plan's entitlements.
  • Responding to support requests you send us, using the contact details you provide at that time.
  • Complying with legal obligations, including Shopify's own requirements of app developers.

Nothing collected is sold, rented, or used for advertising.

5. How long data is kept

  • Shop configuration and staff account details are kept for as long as the app is installed, and are not deleted automatically on uninstall. See Section 7.
  • Tag and search counters are kept for roughly 400 days on a rolling basis, then automatically deleted.
  • The article index is rebuilt nightly and reflects your store's current content; entries for deleted articles are removed on the next rebuild.

6. Sub-processors and where data is hosted

Data is processed using the following service providers, each acting under its own terms and, where applicable, a data processing agreement with us:

ProviderPurposeLocation
ShopifyThe platform the app runs on and is installed throughVaries by Shopify infrastructure
VercelApplication hostingFrankfurt, Germany (EU)
SupabaseDatabase hosting (Postgres)EU (Zurich region)
ResendDelivers messages sent through this website's contact form. Not used by the app itself.United States

See the Data processing addendum for the merchant-facing version of this information.

7. Uninstalling and automatic deletion

Uninstalling the app does not, by itself, delete anything. This is intentional, so that reinstalling restores your settings without reconfiguration. Shopify requires every app to erase a shop's data automatically, and this app does so on Shopify's standard schedule following an uninstall. There is no separate in-app control that changes this behaviour or triggers it early. See the documentation for detail.

8. Your rights

Depending on where you or your store's visitors are located, you may have rights under the EU/UK General Data Protection Regulation, the California Consumer Privacy Act, or similar laws, including the right to access, correct, delete, or export data, and to object to or restrict certain processing. To exercise any of these rights, or to ask what is specifically stored about your shop, contact us and select "Privacy or data request." We aim to respond within 30 days.

Because the app does not collect any data that identifies an individual shopper or reader (Section 3), there is generally nothing for us to provide in response to a request made on behalf of a specific visitor to your store. See what we collect for why.

9. Shopify's mandatory compliance webhooks

As required for every Shopify app, we implement Shopify's three mandatory privacy webhooks:

  • Customer data request: acknowledged; the app holds no data associated with an individual customer to return.
  • Customer redact: acknowledged; the app holds no data associated with an individual customer to erase.
  • Shop redact: permanently deletes the shop's configuration, article index, and tag/search counters from our database, automatically, on Shopify's schedule after uninstall.

10. Children's privacy

The app is a business tool for Shopify merchants and is not directed at children. We do not knowingly collect personal data from children.

11. Changes to this policy

If this policy changes materially, the "last updated" date at the top of this page will change accordingly. Continued use of the app after a change constitutes acceptance of the updated policy.

12. Contact

For any question about this policy or your data, use the contact form and select "Privacy or data request".

Loading search index
to navigate to selectEsc to close