Privacy policy

Last updated: July 18, 2026

Last updated: July 18, 2026
Effective date: July 18, 2026

This Privacy Policy describes how Loger Labs (“Loger,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the Loger Shopify embedded app, our website at https://loger.io, any standalone Loger web application, and related services (collectively, the “Services”).

By installing Loger, creating an account, or using the Services, you agree to this Privacy Policy. If you do not agree, do not use the Services.


Important notices

  1. Business customers. If you use Loger on behalf of a company or Shopify store, you represent that you have authority to bind that organization. The organization is responsible for accounts, connected integrations, and content submitted by its authorized users.

  2. Merchant data vs. customer data. Loger processes merchant staff information, store configuration, and product/catalog content you submit or authorize us to access. Under its current Shopify app permissions, Loger does not collect or store Shopify customer personal data (such as buyer names, emails, or order history).

  3. Your customers. If you process personal data of your end customers outside Loger (for example in Shopify admin or other tools), you remain responsible for that processing under applicable law.


1. Who we are

Controller / Operator:
Loger Labs
Djupedalsvägen 27
54136 Skövde, Sweden

Contact (privacy inquiries):
Email: hi@loger.io


2. Scope

This Policy applies to:

  • Merchants and authorized staff who install and use the Loger Shopify embedded app

  • Visitors to our marketing site

  • Users of the standalone Loger web product, where still offered

It does not govern third-party websites, apps, or platforms you link to from the Services (for example, Shopify admin, Dropbox, Google account settings, or migration platforms). Those services have their own policies.


3. Information we collect

We collect information in the following categories. Not every user will provide every category; it depends on which surface and features you use.

3.1 Account and identity information

Shopify embedded app

  • Shop domain, store display name, and install / connection timestamps

  • Shopify staff session verified through Shopify App Bridge (we do not issue a separate Loger password for embedded access)

  • Staff name and email from your Shopify session, used for account metadata and optional product-activity notifications

  • Onboarding profile you provide (e.g. display name, company name)

  • Onboarding survey answers and optional free-text notes

  • Legal acknowledgement records, including acceptance of Terms and this Policy

  • An internal tenant identifier mapped to your shop (a synthetic backend account used only for data isolation)

Standalone web product (where offered)

  • Name, email address, and authentication identifiers

  • Password or authentication tokens when you use email/password or OAuth (e.g. Google Sign-In)

  • Profile, workspace, and team settings you choose to save


3.2 Billing and subscription information
  • Plan tier, subscription status, trial status, and billing-related metadata

  • Shopify App Billing subscription identifiers when you subscribe inside the Shopify app

  • Stripe billing metadata when you subscribe through the standalone web product

Payment card and bank details are processed by Shopify or Stripe. We do not store full card numbers on Loger’s own servers. Shopify’s and Stripe’s privacy policies and terms govern payment data they handle on our behalf.

3.3 Product usage and content you submit (“Customer Content”)
To provide the Services, we process data you upload, import, connect, or generate, including but not limited to:
  • Catalog and product data (e.g. SKUs, titles, descriptions, prices, inventory, variants, tags, images, handles, and Shopify product/variant identifiers)

  • Files and spreadsheets from uploads, local folders, Dropbox, URL imports, or connected sources

  • Supplier / wholesale data you choose to import, sync, or update

  • Integration credentials and configuration needed to connect third-party platforms (e.g. Shopify OAuth tokens, Dropbox tokens, migration platform API credentials), stored so the Services can perform actions you request

  • Brand voice preferences, import mapping profiles, and storefront scan results from optional analysis of your public storefront

  • Chat, prompts, or instructions you send through in-product assistants

  • Logs of operations you perform (e.g. imports, publishes, updates, sync runs, rollbacks) for reliability, security, billing enforcement, and support

You should not submit special categories of personal data (e.g. health, biometric data) or government ID numbers through the Services unless doing so is strictly necessary and lawful for your use case—and we do not design the Services for those purposes.

3.4 Technical, device, and log data
  • IP address, approximate location derived from IP, browser type, device type, operating system

  • Dates/times of access, pages or screens viewed, referring URLs, and diagnostic logs

  • Cookies, local storage, and similar technologies (see Section 10)

  • Optional heartbeat / last-seen timestamps for operational reliability


3.5 Communications
  • Messages you send to us (support tickets, email)

  • Records of transactional emails (e.g. import notifications, security notices) sent via our email providers


3.6 Inferred or generated data
  • Metrics derived from your use of the Services (e.g. import counts, publish counts, aggregated analytics) to operate, secure, and improve the product

  • Where you use AI-assisted features, we may send relevant portions of Customer Content and prompts to our AI subprocessors (see Section 6) to generate outputs you request


4. How we use information

We use personal information for the following purposes:

Purpose

Examples

Provide the Services

Authenticate Shopify staff sessions; store and display your catalog; run imports, AI structuring, reviews, publishes, updates, migrations, and scheduled jobs; connect to Shopify, Dropbox, and other platforms you direct

Billing and plan enforcement

Process subscriptions, trials, entitlements, and usage limits

Security and abuse prevention

Detect fraud, unauthorized access, and violations of our terms

Improvement and analytics

Understand usage patterns; debug errors; develop new features

Communications

Send service-related messages, responses to support, and (where permitted) product updates

Legal compliance

Comply with law, respond to Shopify mandatory compliance webhooks, enforce our terms, and defend legal claims

We do not sell your personal information in the conventional sense of “selling” for money. We use service providers (subprocessors) who process data on our instructions, as described below.

Legal bases (EEA / UK / similar jurisdictions): Where required, we rely on one or more of: performance of a contract (providing the Services you requested); legitimate interests (security, improvement, analytics balanced against your rights); consent (where we ask for it, e.g. certain cookies or marketing); legal obligation.


5. How we share information

We may share information with:

5.1 Service providers (subprocessors)
Categories of providers we use include:
  • Shopify — embedded app authentication, Admin API access, App Billing, and mandatory compliance webhooks

  • Hosting and infrastructure (e.g. Vercel) — serving the application and related infrastructure

  • Database and authentication (e.g. Supabase) — tenant storage, application data, and file storage

  • Payments — Shopify App Billing (Shopify app); Stripe (standalone web product)

  • Email delivery (e.g. Resend, SMTP providers) — transactional and operational email

  • AI / machine learning (e.g. OpenAI) — processing prompts and content you submit to AI features

  • Analytics (e.g. Vercel Analytics) — aggregated usage and performance metrics

  • Dropbox — when you connect Dropbox for imports, Dropbox processes data according to your Dropbox account settings and Dropbox’s privacy policy

  • Google APIs — when you use Google Sign-In and/or Google Drive on the standalone web product, Google processes data according to your Google account settings and Google’s API Services User Data Policy as applicable

  • Pexels — optional experimental stock-image features, when enabled

We enter into agreements that require subprocessors to protect personal data and use it only for the purposes we specify.

5.2 Integrations you enable

When you connect third-party platforms (e.g. Shopify, Dropbox, WooCommerce, PrestaShop, BigCommerce, Squarespace, Wix), we exchange data with those platforms as necessary to perform actions you request (e.g. publish products, import folders, migrate catalogs). Those platforms process data under their own terms and privacy policies.

5.3 Legal and safety

We may disclose information if we believe in good faith that disclosure is necessary to:

  • Comply with law, regulation, legal process, or governmental request

  • Protect the safety, rights, or property of Loger, our users, or the public

  • Detect, prevent, or address fraud, security, or technical issues

  • Enforce our Terms of Use or other agreements


5.4 Business transfers

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will take steps to require the successor to honor this Policy or notify you of changes.


6. AI processing

Certain features use artificial intelligence models hosted by third parties (e.g. OpenAI). When you use those features:

  • Input you provide (including portions of Customer Content) may be transmitted to the AI provider to generate a response

  • Outputs are returned to you within the Services

You should avoid submitting highly sensitive personal data in AI prompts unless necessary. AI outputs may be inaccurate; you remain responsible for reviewing outputs before relying on them in your business (e.g. before publishing to live stores).

We configure services to minimize unnecessary retention where the provider allows, but AI providers may have their own retention and safety policies. Review their documentation for details.


7. Shopify-specific practices


7.1 App permissions

The Loger Shopify app requests permissions needed to manage products, inventory, and store locations in your Shopify store. It does not request access to Shopify customer records under its current configuration.

7.2 Mandatory compliance webhooks

Shopify requires apps to handle certain compliance webhooks:

Webhook

Our handling

customers/data_request

We do not store Shopify customer PII to export. We acknowledge valid requests.

customers/redact

We do not store Shopify customer PII to delete. We acknowledge valid requests.

shop/redact

We erase Loger data associated with the shop, including stored content, integration tokens, and the internal tenant record, subject to backup and legal retention limits described below.

app/uninstalled

We revoke Shopify API access and end Shopify billing entitlement. Catalog data may be retained to support reinstallation until a shop/redact request or other lawful deletion request.


8. International transfers

We may process and store information in the United States and other countries where we or our subprocessors operate. Those countries may have different data protection laws than your country.

Where required (e.g. EEA/UK), we implement appropriate safeguards such as Standard Contractual Clauses or other mechanisms approved by regulators, in addition to technical and organizational measures.


9. Retention

We retain information as long as necessary to:

  • Provide the Services and maintain your account or shop tenant

  • Comply with legal, tax, and accounting obligations

  • Resolve disputes and enforce agreements

Shopify uninstall. When you uninstall Loger, we revoke API access and clear Shopify billing entitlement, but we may retain Your Content and shop metadata for a period so you can reinstall without losing work.

Shop redact / deletion. When Shopify sends a shop/redact request, or when you request deletion as permitted by law, we delete or anonymize associated personal data and Customer Content within a reasonable period, subject to backup cycles and legal holds. Some residual copies may persist in encrypted backups for a limited time.

When you delete a standalone web account or specific content (where the product supports deletion), we follow a similar process.

You may contact us for more detail about retention for your account or shop.


10. Security

We implement technical and organizational measures designed to protect personal information (e.g. access controls, encryption in transit, secure hosting). No method of transmission or storage is 100% secure. You use the Services at your own risk to that extent.

You are responsible for:

  • Maintaining the confidentiality of your Shopify and Loger credentials

  • Revoking integrations you no longer trust

  • Ensuring your own compliance when processing personal data of your customers through connected stores and other tools


11. Cookies and similar technologies

We and our partners may use cookies, local storage, and similar technologies to:

  • Keep you signed in (session / authentication), including embedded Shopify sessions

  • Remember preferences

  • Measure traffic and performance (e.g. Vercel Analytics)

You can control cookies through browser settings. Blocking essential cookies may break login or core functionality.

Where required by law, we will obtain consent before non-essential cookies or similar tracking.


12. Your rights and choices

Depending on where you live, you may have rights to:

  • Access a copy of your personal information

  • Correct inaccurate data

  • Delete certain data

  • Restrict or object to certain processing

  • Data portability (receive data in a structured format)

  • Withdraw consent where processing was based on consent

  • Lodge a complaint with a supervisory authority (EEA/UK)

How to exercise rights: Email hi@loger.io. We may need to verify your identity or shop authorization before fulfilling requests.

California residents (CCPA/CPRA): You may have the right to know, delete, and correct personal information, and to limit use of sensitive personal information (if applicable). We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined under CPRA, based on our current practices.

Do Not Track: There is no consistent industry standard; we do not respond to all DNT signals.


13. Children

The Services are not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take steps to delete it.


14. Third-party links

The Services may contain links to third-party sites. We are not responsible for their privacy practices. Read their policies before providing information.


15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new “Last updated” date. If changes are material, we will provide additional notice as required by law (e.g. email or in-app notice). Continued use after the effective date constitutes acceptance of the updated Policy, except where prohibited.


16. Contact

Questions about this Privacy Policy or our data practices:

Loger Labs
Email: hi@loger.io
Address: Djupedalsvägen 27, 54136 Skövde, Sweden