Privacy Policy
Last updated 23 August 2026
MyMeridian is a profitability dashboard for Shopify stores. It reads a store’s order, product, inventory and fulfilment records, combines them with recorded costs and clearly identified configured assumptions, and estimates the profit of each order and product. This policy describes every category of data it touches and what happens to it, including the public waitlist and merchant-store service.
Service And Support
The public service is available at mymeridian.io. The current support contact appears in the Contact section below.
Waitlist
A visitor may join the MyMeridian waitlist with an email address and, optionally, a Shopify store URL. We also retain campaign attribution supplied in the link they used (such as UTM source, medium and campaign), solely to understand which marketing generated interest. We do not collect names, passwords, Shopify access tokens, customer data or other unnecessary personal information in this flow.
A successful signup creates an email-bound waitlist record and may create an eligibility record for an offer communicated at signup. We send the transactional waitlist confirmation regardless of marketing consent once the configured sender is verified. Product/newsletter mail is sent only to people who separately opt in, includes an unsubscribe link, and does not suppress necessary account or service notices.
Who This Policy Is For
The merchant who installs MyMeridian is our customer. Their store’s shoppers are not - we hold shopper data only as a processor acting on the merchant’s instructions, and the merchant remains the controller of it.
What We Read From Shopify
MyMeridian requests these access scopes at install, and no others. Each is requested because a specific figure cannot be computed without it.
read_orders- order totals, discounts, taxes, shipping charged, line items and refunds. This is the revenue side of every profit number. A Shopify order also carries the customer who placed it, so this scope - and not any customer scope - is how the two fields selected from Shopify’s customer object, listed under Personal data specifically below, reach MyMeridian.read_all_orders- extends that read-only order history beyond Shopify’s default 60-day window when Shopify approves it for the production installation. It does not add any write access. Until then, MyMeridian identifies the available history window rather than implying that it has a complete record.read_products- products and variants, so line items can be grouped by what was actually sold.read_inventory- the per-variant unit cost recorded on the inventory item. Without it, cost of goods is incomplete and MyMeridian marks the affected margin as needing COGS rather than treating the missing cost as $0.00.read_fulfillments- when each order shipped, used for fulfilment capacity and shipping cost.read_reports- Shopify Shipping label-cost reports by order, carrier and service. Shopify separately gates those reports behind Level 2 protected-customer-data approval covering name, address, phone and email. This is a ShopifyQL access gate: MyMeridiandoes not query or persist shopper name, phone, street, city or postal address from those reports, and the connection stays paused until Shopify grants the approval. MyMeridian does not query, retain or use those fields merely because approval is available.
MyMeridian requests no write scope. It cannot change a price, an order, or anything else in the store. Accepted pricing recommendations are recorded inside MyMeridian only; applying them remains a manual action the merchant takes in Shopify.
read_customers is not requested. Customer identity used by MyMeridian is limited to the id and email carried on orders, as described below.
Personal Data Specifically
Shopper personal data does reach MyMeridian, through read_orders. Exactly two fields are selected from Shopify’s customer object and stored:
- the Shopify customer id carried on the order - the stable identifier used to link that store’s repeat orders and to match access or erasure requests; and
- the email address on that customer record. It is stored so that a
customers/data_requestorcustomers/redactnaming a shopper can be matched to the right rows and answered, and it is included in the export handed to the merchant for a data request.
No other field from that customer object is selected for use or persistence. Shopify may include more fields in an order webhook, but before recovery data is written MyMeridian projects the authenticated payload onto the exact fields listed here. It does not retain shopper name, phone number, or a full billing or shipping address such as street, city or postal code, nor an IP address, payment card details or passwords.
From those fields and the orders themselves, MyMeridian stores per customer: the date of their first order, the channel and campaign that acquired them, their order count, and their lifetime revenue and profit. Per order it stores the order number, its processed and Shopify source-update timestamps, currency, the money totals above, financial and fulfilment status, the marketing channel, any UTM parameters, and the landing page URL of the visit the order is attributed to. Marketing URLs can contain personalized query values and are therefore treated as potentially personal data: matching landing, UTM and campaign values are cleared on customer redaction. The referring URL is used to classify that channel and may remain briefly in the minimized recovery copy described below, but is not stored on the order record. Line items are stored as title, SKU, quantity, price, discount, refunded quantity and the cost snapshotted when the order was placed. An order may also retain its country and province code solely to classify its tax jurisdiction; it never retains the rest of that address. Fulfilment records linked to the order retain shipment and Shopify source-update timestamps, carrier, service, location, item count and configured costs; tracking numbers and destination addresses are not retained.
Because a shopper email address is among the fields read and stored,MyMeridian’s access to orders falls under Shopify’s protected customer data requirements at the level that covers customer email. If Shopify approves read_all_orders, it remains read-only, and MyMeridian continues to apply the applicable data-handling undertakings and least-privilege limits described in this policy.
What The Merchant Gives Us Directly
Cost assumptions shown in Costs & Connections - payment processing rates, shipping and pick-and-pack estimates, and fixed monthly overhead. MyMeridian supplies visible install defaults until the merchant reviews or replaces them; reviewing a fallback does not turn it into a measured cost. A merchant may also connect Meta Ads, Google Ads, TikTok Ads or ShipStation. Google Ads access and refresh tokens, and a ShipStation API key, are encrypted at rest. Meta Ads and TikTok Ads authorization is completed directly with the provider-managed connection service, so MyMeridian stores the connection reference and imported campaign-spend records, not those provider credentials. Disconnecting removes local credentials or connection references and requests remote revocation where the provider supports it. A connection remains unavailable until its provider authorization and first successful sync complete.
How We Protect Data
We use safeguards designed to protect data in transit and at rest, limit access to authorized people and service providers, and keep each merchant’s data separate from other stores.
We minimize the data used to operate and secure MyMeridian, and keep it only for as long as needed to provide the service or meet legal obligations.
Who Else Sees It
MyMeridian does not sell store data, share it with advertisers, or use it to train models. We share information only as needed to operate, secure and support the service; provide the app through Shopify; or enable a connection a merchant chooses. Customer information is not used for advertising.
How Long It Is Kept
Waitlist contact and eligibility data is retained only while MyMeridian is preparing or operating the stated early-access program, then deleted or anonymized when it is no longer needed. Transactional delivery receipts are retained for up to 90 days for reliability and abuse troubleshooting. A waitlist visitor can request access, correction or deletion through the public contact details below.
Store data is retained while the app is installed. On uninstall the store’s sessions are deleted immediately, and the remaining records are removed when Shopify sends shop/redact.
After customers/redact, keyed one-way digests of the Shopify customer id and, when supplied, email remain as pseudonymous erasure guards. The key is held outside the database. These guards are used only to stop a delayed webhook or later historical import from recreating the customer, and they are deleted with the store on shop/redact.
Requests To Access Or Erase Data
MyMeridian implements all three of Shopify’s mandatory compliance webhooks, and acts on each automatically:
customers/data_request- everything held about the named customer is assembled into an export and made available to the merchant, who is the controller and responds to the shopper. The export includes every normalized customer, linked order, line-item and fulfilment field, including derived cost and profit fields, plus any still-pending minimized recovery payload that names the customer or belongs to one of their linked orders. The authenticated Privacy requests screen receives metadata only and shows every uncollected obligation; collected history is paginated. The full report is returned only from a shop-scoped, no-store download after the merchant explicitly asks for it, and that same transaction records the first collection time. This handoff remains available without an active subscription. The export expires 31 days after the request whether or not it is collected and is removed by an hourly sweep (and by the startup catch-up sweep after downtime). If erasure has already completed, the response is an empty, de-identified record: it retains neither the supplied customer id nor email and does not recreate erased data.customers/redact- the customer record is deleted and its link is removed from every order; the orders retain their own Shopify order id and economic history but no customer link or Shopify customer identifier. Stored landing URLs, UTM values and campaign strings are cleared from those linked orders, and customer and attribution URLs are removed from matching pending order recovery payloads. A different Shopify customer id is not affected merely because it shares an email address. The current redaction delivery may retain only its customer id until completion is durably recorded, so a crash cannot suppress the legal action. The keyed erasure guards described above then prevent in-flight webhooks and later imports from recreating the customer. Deleting the orders outright would silently rewrite the merchant’s own historical revenue.shop/redact- every record belonging to that store is deleted, including sessions, orders, products, cost rules and connectors.
A merchant may also request access or erasure directly using the contact details below, without going through Shopify.
International Transfers And Legal Basis
Data is processed on infrastructure that may be located outside the merchant’s country. Processing is carried out to perform the contract with the merchant, and on their instruction in respect of any shopper data.
Changes
Material changes to this policy are announced in the app before they take effect. The date at the top is the last substantive revision.