Meerkat Scout
Sign inBook a demo

Legal · GDPR & data rights

Your rights, our role, and exactly what happens when you leave.

This page states plainly where Scout is a controller and where it is a processor, lists the rights you can exercise, and walks through the uninstall-to-deletion timeline step by step.

EffectiveSeptember 2, 2026
Privacy contactprivacy@meerkatscout.com
Read withPrivacy Policy
Scout is the controller Your merchant account data Shop domain, the name and email on your Shopify account, plan and billing history, support correspondence. We decide why and how this is processed, so we answer for it.
You are the controller · Scout is the processor Your catalog and order data Products, variants, feeds, diagnostics, and any order data you choose to share. It flows through Scout on your instructions and for your purposes. You decide; we process.

01 · Roles

Controller or processor

GDPR asks one question first: who decides why and how personal data is used? That party is the controller. A party that handles data on the controller's instructions is a processor. Scout is each of these for different data, and the distinction is not blurred here because your rights and our duties depend on it.

Merchant account data — Scout is controllerCatalog and order data — you are controller, Scout is processor
What it is. Your shop domain; the name and email address on your Shopify account; your plan, charge history and support correspondence.What it is. Products and variants, store metadata, generated feeds, channel diagnostics, channel credentials, and — only if you enable it — order data with personal fields already stripped.
Why we hold it. To run your account, bill you through Shopify, support you, and meet our own legal obligations. We set those purposes.Why we hold it. Because you installed Scout and configured it to sync, transform and publish your catalog. You set the purpose; we carry out your instructions.
What that means for you. Exercise your rights directly with us (section 3). We answer for how it is used.What that means for you. We process it only on your instructions, keep it isolated to your store, delete it when you leave, and help you meet your own GDPR obligations — including through the Shopify webhooks in section 5.

Where Scout uses third-party services to carry out your instructions — the channels you connect, taxonomy APIs, a search API, an AI model provider, and our hosting — those services act as our sub-processors for that data (section 9).

02 · Shoppers

Your shoppers

Scout does not collect personal data about your customers. We store no customer names, email addresses, postal addresses, phone numbers, or IP addresses. When order data is ingested for Conversion Intelligence, those fields are removed before the record is stored, and an automated schema test fails our build if any personal field is ever introduced.

If one of your shoppers exercises a right with you, Scout will have nothing about that person to return or erase — and we confirm that automatically through the Shopify webhooks below.

03 · Rights

Your rights

For your merchant account data, and for the catalog data we hold on your behalf, every merchant can:

  • Access and exportReceive a copy of the data Scout holds for your store, in a machine-readable format.
  • ErasureHave all operational data for your store deleted — on request, or automatically when you uninstall.
  • RectificationCatalog data is mirrored from Shopify: correct it there and Scout follows. Account details we hold directly, we will correct on request.
  • Restriction and objectionAsk us to pause processing of your account data, or object to a particular use, while a question is resolved.
  • Withdraw optional accessRevoke the optional order permission in your Shopify admin at any time; the rest of Scout keeps working.
  • ComplainRaise a concern with us first, or with your supervisory authority at any time (section 11).

04 · Requests

Making a request

Email privacy@meerkatscout.com from the email address on your Shopify account and include your shop domain. We will confirm receipt and respond within one month, as GDPR requires; if a request is unusually complex we may extend that by up to two further months and will tell you why.

We verify that a request comes from the store owner or an authorized staff account before acting on it. Requests are free unless they are manifestly unfounded or repetitive.

05 · Webhooks

Shopify privacy webhooks

Shopify requires every app to implement three privacy webhooks. Scout implements all three and handles each automatically.

WebhookWhat Scout does
customers/data_requestA shopper has asked you for their data. Scout searches its records for the customer and returns a confirmation that no personal data is held — because none is stored.
customers/redactA shopper has asked you to erase their data. Scout checks for any record tied to that customer and deletes it if found; in normal operation there is nothing to delete.
shop/redactSent by Shopify about 48 hours after you uninstall. Scout deletes every operational record for the store: catalog mirror, feeds, history, diagnostics, credentials, and any order data. Financial records are kept as described in section 6.

06 · Leaving

Uninstall and deletion timeline

  1. 01You uninstall Scout from your Shopify admin. Your subscription ends through Shopify Billing. Scout's access tokens for your store are revoked by Shopify immediately, so Scout can no longer read your catalog or publish feeds.
  2. 02A brief holding period. Scout retains the store record because Shopify sends the formal erasure request (shop/redact) approximately 48 hours after uninstall. Nothing is processed or published during this period. If you reinstall within it, your configuration is still there.
  3. 03The erasure request arrives and Scout deletes all operational data for the store: catalog mirror, rules, generated feeds, publication history, channel diagnostics, encrypted channel credentials, and any order data. Raw third-party API responses were already on a 30-day automatic deletion cycle.
  4. 04Financial records remain, unlinked. Billing and charge records are retained for 7 years under accounting law, with the linkage to your shop identity severed so they can no longer be tied back to your store.

Feeds you already published live in each channel's systems under that channel's terms. Scout cannot delete them after uninstall; remove them in the channel if you wish.

08 · Location

Where data is held

Scout is hosted by Google Cloud Platform in us-east1 (South Carolina, United States). Where data about EU or UK merchants leaves the EEA or UK — including to the channels you connect — the transfer relies on Standard Contractual Clauses, with the UK Addendum where applicable.

Channel credentials are encrypted at rest with keys held in Google Cloud Key Management Service (Cloud KMS), and every record is scoped to a single store at the database level.

09 · Sub-processors

Sub-processors

When acting as your processor, Scout uses these categories of sub-processor. The current named list is in the Privacy Policy.

  • The sales channels you choose to connect (feed data).
  • Marketplace taxonomy APIs — Amazon, Walmart, eBay (product identifiers).
  • A search API provider that returns public shopping listings for competitive price monitoring. Receives product titles and identifiers only; raw responses are deleted within 30 days.
  • An AI model provider that generates pricing and content recommendations. Receives product context only (titles, descriptions, attributes, price signals) — never customer or order data — under terms that exclude training on submitted data.
  • Hosting and key management — Google Cloud Platform, Google Cloud Key Management Service (Cloud KMS).

We will update that list and notify installed merchants in the app at least 30 days before adding a new sub-processor.

10 · DPA

Data processing agreement

As your processor, Scout's obligations to you under Article 28 GDPR are set out in our data processing agreement: incorporated into the Terms of Service.

11 · Contact

Complaints and contact

You have the right to lodge a complaint with the supervisory authority in your country. We would ask that you raise it with us first so we can try to resolve it.

Meerkat Scout, a sole proprietorship owned by Nana A. Smith 255 Park Avenue, Worcester, MA 01605, United States Privacy: privacy@meerkatscout.com Data protection officer: Not required — none appointed. A sole proprietor processing no shopper personal data does not meet the Article 37 threshold. EU / UK representative: Not currently appointed. If the service is offered to EU or UK data subjects, an Article 27 representative may be required; this will be revisited.

Export or erase

One email. Your data, or its deletion, within a month.

Write from the email on your Shopify account, include your shop domain, and say whether you want an export or an erasure. We confirm receipt and act within the statutory period.

How to make a request privacy@meerkatscout.com