Privacy policy
Last updated: 2026-09-15
This policy explains how Glossa ("the app"), operated by [set LEGAL_ENTITY_NAME], [set LEGAL_ADDRESS], handles information when a merchant installs and uses the app on a Shopify store.
Information the app processes
- Store content that Shopify marks as translatable — for example product titles and descriptions, collections, pages, metafields, metaobjects, theme texts and policies — and the translations the app creates.
- Store information: the shop domain and ID, the store's languages and themes, and the access token Shopify issues to the app.
- Settings and usage: the languages, themes and schedule the merchant chooses, job history and logs, and the number of translated characters used for billing.
The app does not request access to, and does not store, customer or order information.
How the information is used
- To translate the store's content and write the translations back to Shopify.
- To show progress, results and history, and to let merchants revert jobs.
- To reuse earlier translations of identical text for the same store (translation memory), which is never shared with other stores.
- To calculate usage and bill it through Shopify.
- To operate, secure and support the service.
Service providers
- OpenAI (United States) processes the text sent for translation. Under OpenAI's API terms, data sent through the API is not used to train its models.
- DigitalOcean (data center in Frankfurt, Germany) hosts the app and its database.
- Shopify handles installation, authentication and billing.
Retention and deletion
Job logs and field-level results are kept for the history period of the merchant's plan and then deleted. When the app is uninstalled, all work stops immediately, and Shopify asks the app to delete the store's data 48 hours later; the app then deletes all settings, history, translation memory and usage records it holds for that store. Translations already written to the store remain in Shopify and can be managed there.
Your rights
Merchants can request access to, correction of, or deletion of their data at any time by contacting [set SUPPORT_EMAIL]. Where the GDPR applies, [set LEGAL_ENTITY_NAME] processes store content on behalf of the merchant, and merchants may also lodge a complaint with a supervisory authority.
Security
Data is transmitted over encrypted connections, access tokens are stored only on the app's servers, and access to production systems is restricted to the operator's staff.
Contact
[set LEGAL_ENTITY_NAME], [set LEGAL_ADDRESS] — [set SUPPORT_EMAIL]