✓ PromiseCheck
Privacy & data use
Effective September 19, 2026
PromiseCheck is operated by David Gutierrez. It monitors selected customer-facing promises and shopping experiences on connected Shopify stores. This page explains the information used to provide that service.
What we collect and why
- Store domain, name, product and variant information, prices, market information and theme metadata to choose test pages and describe scan conditions.
- Public storefront wording, test results, timestamps, screenshots, saved working references and your settings or notes to explain findings and changes over time.
- Encrypted Shopify access and refresh tokens to keep the app connected. If you supply a storefront visitor password, it is encrypted and used only to access that storefront.
- The notification addresses you choose and delivery status to send enabled email alerts. Email is optional and can be disabled in Settings. Support emails are used to answer your request.
How monitoring works
On your own store, PromiseCheck follows robots.txt rules and crawler delays that name PromiseCheck; on other sites it follows all applicable rules. A disallowed request or an unreadable crawler policy leaves the affected check untested. See crawler identity, access rules and opt-out instructions.
Scans use fresh browser sessions with no customer account, and isolated test carts. Each storefront visit identifies itself to Shopify with a cryptographic signature (Web Bot Auth) that contains no store or personal data: PromiseCheck’s own, or a Shopify crawler access signature if you save one in Setup. A saved signature is stored encrypted and sent only with requests to your own storefront. PromiseCheck does not request Shopify customer or order records, submit payments or create orders. Screenshots mask form inputs and embedded frames; detected email addresses, phone numbers and credentials in text are redacted. Public storefront content can still contain personal information, so avoid placing private information on monitored pages.
Automatic discovery samples pages and supported widgets. The starting destination is a synthetic US address in Austin, Texas, not a customer address. You can change test locations in Setup. Discovery does not verify every product, market, checkout outcome, delivery date or policy.
Services that process information
Shopify provides authentication and authorized store data. Fly.io hosts the app and its database; Tigris stores encrypted recovery backups. Brevo delivers enabled email alerts, including finding summaries, quoted storefront wording and source links. These providers process information to operate the service and may process it outside your country. PromiseCheck does not sell your data or use it for advertising.
Retention and deletion
New screenshots expire after your selected retention period (30 days by default; adjustable from 7 to 90 days). Saved widget references remain until replaced or deleted. Text findings, observations, configuration and scan history remain while the app is installed so you can review past changes.
Uninstalling stops monitoring and deletes the store’s active app records, credentials and screenshots when Shopify’s uninstall notification is received. Shopify’s store-redaction notification provides a second deletion path. Reinstalling starts a new monitoring history.
Encrypted recovery backups are separate from the active app. Up to seven recent successful backup copies are retained and rotated as new copies succeed; an older snapshot can therefore contain data already deleted from the active app until that copy rotates out. Recovery copies are used only for disaster recovery, and restored data must be reconciled with deletion requests before service resumes. Contact us for early removal or a retention question. Email copies already delivered to your inbox are controlled by you and your email provider.
Your choices and requests
You can pause scheduled scans, disable notifications, change screenshot retention, or delete screenshots and saved references in Settings. Uninstall through Shopify to disconnect the app. To request access, correction or deletion of your information, email davidcgutierrez93@gmail.com. Include your store domain and request; never send passwords or access keys. We may need to verify that you control the store before fulfilling a request.
We handle applicable Shopify privacy requests and aim to complete verified deletion requests within 30 days. Material changes to this policy will appear here with an updated effective date.