MyMeridian is a profitability dashboard for Shopify stores. It reads a store’s order, product, inventory and fulfilment records, combines them with recorded costs and clearly identified configured assumptions, and estimates the profit of each order and product. This policy describes every category of data it touches and what happens to it, including the public waitlist and merchant-store service.

Service And Support

The public service is available at mymeridian.io. The current support contact appears in the Contact section below.

Waitlist

A visitor may join the MyMeridian waitlist with an email address and, optionally, a Shopify store URL. We also retain campaign attribution supplied in the link they used (such as UTM source, medium and campaign), solely to understand which marketing generated interest. We do not collect names, passwords, Shopify access tokens, customer data or other unnecessary personal information in this flow.

A successful signup creates an email-bound waitlist record and may create an eligibility record for an offer communicated at signup. We send the transactional waitlist confirmation regardless of marketing consent once the configured sender is verified. Product/newsletter mail is sent only to people who separately opt in, includes an unsubscribe link, and does not suppress necessary account or service notices.

Who This Policy Is For

The merchant who installs MyMeridian is our customer. Their store’s shoppers are not - we hold shopper data only as a processor acting on the merchant’s instructions, and the merchant remains the controller of it.

What We Read From Shopify

MyMeridian requests these access scopes at install, and no others. Each is requested because a specific figure cannot be computed without it.

MyMeridian requests no write scope. It cannot change a price, an order, or anything else in the store. Accepted pricing recommendations are recorded inside MyMeridian only; applying them remains a manual action the merchant takes in Shopify.

read_customers is not requested. Customer identity used by MyMeridian is limited to the id and email carried on orders, as described below.

Personal Data Specifically

Shopper personal data does reach MyMeridian, through read_orders. Exactly two fields are selected from Shopify’s customer object and stored:

No other field from that customer object is selected for use or persistence. Shopify may include more fields in an order webhook, but before recovery data is written MyMeridian projects the authenticated payload onto the exact fields listed here. It does not retain shopper name, phone number, or a full billing or shipping address such as street, city or postal code, nor an IP address, payment card details or passwords.

From those fields and the orders themselves, MyMeridian stores per customer: the date of their first order, the channel and campaign that acquired them, their order count, and their lifetime revenue and profit. Per order it stores the order number, its processed and Shopify source-update timestamps, currency, the money totals above, financial and fulfilment status, the marketing channel, any UTM parameters, and the landing page URL of the visit the order is attributed to. Marketing URLs can contain personalized query values and are therefore treated as potentially personal data: matching landing, UTM and campaign values are cleared on customer redaction. The referring URL is used to classify that channel and may remain briefly in the minimized recovery copy described below, but is not stored on the order record. Line items are stored as title, SKU, quantity, price, discount, refunded quantity and the cost snapshotted when the order was placed. An order may also retain its country and province code solely to classify its tax jurisdiction; it never retains the rest of that address. Fulfilment records linked to the order retain shipment and Shopify source-update timestamps, carrier, service, location, item count and configured costs; tracking numbers and destination addresses are not retained.

Because a shopper email address is among the fields read and stored,MyMeridian’s access to orders falls under Shopify’s protected customer data requirements at the level that covers customer email. If Shopify approves read_all_orders, it remains read-only, and MyMeridian continues to apply the applicable data-handling undertakings and least-privilege limits described in this policy.

What The Merchant Gives Us Directly

Cost assumptions shown in Costs & Connections - payment processing rates, shipping and pick-and-pack estimates, and fixed monthly overhead. MyMeridian supplies visible install defaults until the merchant reviews or replaces them; reviewing a fallback does not turn it into a measured cost. A merchant may also connect Meta Ads, Google Ads, TikTok Ads or ShipStation. Google Ads access and refresh tokens, and a ShipStation API key, are encrypted at rest. Meta Ads and TikTok Ads authorization is completed directly with the provider-managed connection service, so MyMeridian stores the connection reference and imported campaign-spend records, not those provider credentials. Disconnecting removes local credentials or connection references and requests remote revocation where the provider supports it. A connection remains unavailable until its provider authorization and first successful sync complete.

How We Protect Data

We use safeguards designed to protect data in transit and at rest, limit access to authorized people and service providers, and keep each merchant’s data separate from other stores.

We minimize the data used to operate and secure MyMeridian, and keep it only for as long as needed to provide the service or meet legal obligations.

Who Else Sees It

MyMeridian does not sell store data, share it with advertisers, or use it to train models. We share information only as needed to operate, secure and support the service; provide the app through Shopify; or enable a connection a merchant chooses. Customer information is not used for advertising.

How Long It Is Kept

Waitlist contact and eligibility data is retained only while MyMeridian is preparing or operating the stated early-access program, then deleted or anonymized when it is no longer needed. Transactional delivery receipts are retained for up to 90 days for reliability and abuse troubleshooting. A waitlist visitor can request access, correction or deletion through the public contact details below.

Store data is retained while the app is installed. On uninstall the store’s sessions are deleted immediately, and the remaining records are removed when Shopify sends shop/redact.

After customers/redact, keyed one-way digests of the Shopify customer id and, when supplied, email remain as pseudonymous erasure guards. The key is held outside the database. These guards are used only to stop a delayed webhook or later historical import from recreating the customer, and they are deleted with the store on shop/redact.

Requests To Access Or Erase Data

MyMeridian implements all three of Shopify’s mandatory compliance webhooks, and acts on each automatically:

A merchant may also request access or erasure directly using the contact details below, without going through Shopify.

International Transfers And Legal Basis

Data is processed on infrastructure that may be located outside the merchant’s country. Processing is carried out to perform the contract with the merchant, and on their instruction in respect of any shopper data.

Changes

Material changes to this policy are announced in the app before they take effect. The date at the top is the last substantive revision.

Contact

support@mymeridian.io