Privacy policy
Last updated: July 18, 2026
Last updated: July 18, 2026
Effective date: July 18, 2026
This Privacy Policy describes how Loger Labs (“Loger,” “we,” “us,” or “our”) collects, uses, discloses, and protects information when you use the Loger Shopify embedded app, our website at https://loger.io, any standalone Loger web application, and related services (collectively, the “Services”).
By installing Loger, creating an account, or using the Services, you agree to this Privacy Policy. If you do not agree, do not use the Services.
Important notices
Business customers. If you use Loger on behalf of a company or Shopify store, you represent that you have authority to bind that organization. The organization is responsible for accounts, connected integrations, and content submitted by its authorized users.
Merchant data vs. customer data. Loger processes merchant staff information, store configuration, and product/catalog content you submit or authorize us to access. Under its current Shopify app permissions, Loger does not collect or store Shopify customer personal data (such as buyer names, emails, or order history).
Your customers. If you process personal data of your end customers outside Loger (for example in Shopify admin or other tools), you remain responsible for that processing under applicable law.
1. Who we are
Controller / Operator:
Loger Labs
Djupedalsvägen 27
54136 Skövde, Sweden
Contact (privacy inquiries):
Email: hi@loger.io
2. Scope
This Policy applies to:
Merchants and authorized staff who install and use the Loger Shopify embedded app
Visitors to our marketing site
Users of the standalone Loger web product, where still offered
It does not govern third-party websites, apps, or platforms you link to from the Services (for example, Shopify admin, Dropbox, Google account settings, or migration platforms). Those services have their own policies.
3. Information we collect
We collect information in the following categories. Not every user will provide every category; it depends on which surface and features you use.
3.1 Account and identity information
Shopify embedded app
Shop domain, store display name, and install / connection timestamps
Shopify staff session verified through Shopify App Bridge (we do not issue a separate Loger password for embedded access)
Staff name and email from your Shopify session, used for account metadata and optional product-activity notifications
Onboarding profile you provide (e.g. display name, company name)
Onboarding survey answers and optional free-text notes
Legal acknowledgement records, including acceptance of Terms and this Policy
An internal tenant identifier mapped to your shop (a synthetic backend account used only for data isolation)
Standalone web product (where offered)
Name, email address, and authentication identifiers
Password or authentication tokens when you use email/password or OAuth (e.g. Google Sign-In)
Profile, workspace, and team settings you choose to save
3.2 Billing and subscription information
Plan tier, subscription status, trial status, and billing-related metadata
Shopify App Billing subscription identifiers when you subscribe inside the Shopify app
Stripe billing metadata when you subscribe through the standalone web product
Payment card and bank details are processed by Shopify or Stripe. We do not store full card numbers on Loger’s own servers. Shopify’s and Stripe’s privacy policies and terms govern payment data they handle on our behalf.
3.3 Product usage and content you submit (“Customer Content”)
To provide the Services, we process data you upload, import, connect, or generate, including but not limited to:
Catalog and product data (e.g. SKUs, titles, descriptions, prices, inventory, variants, tags, images, handles, and Shopify product/variant identifiers)
Files and spreadsheets from uploads, local folders, Dropbox, URL imports, or connected sources
Supplier / wholesale data you choose to import, sync, or update
Integration credentials and configuration needed to connect third-party platforms (e.g. Shopify OAuth tokens, Dropbox tokens, migration platform API credentials), stored so the Services can perform actions you request
Brand voice preferences, import mapping profiles, and storefront scan results from optional analysis of your public storefront
Chat, prompts, or instructions you send through in-product assistants
Logs of operations you perform (e.g. imports, publishes, updates, sync runs, rollbacks) for reliability, security, billing enforcement, and support
You should not submit special categories of personal data (e.g. health, biometric data) or government ID numbers through the Services unless doing so is strictly necessary and lawful for your use case—and we do not design the Services for those purposes.
3.4 Technical, device, and log data
IP address, approximate location derived from IP, browser type, device type, operating system
Dates/times of access, pages or screens viewed, referring URLs, and diagnostic logs
Cookies, local storage, and similar technologies (see Section 10)
Optional heartbeat / last-seen timestamps for operational reliability
3.5 Communications
Messages you send to us (support tickets, email)
Records of transactional emails (e.g. import notifications, security notices) sent via our email providers
3.6 Inferred or generated data
Metrics derived from your use of the Services (e.g. import counts, publish counts, aggregated analytics) to operate, secure, and improve the product
Where you use AI-assisted features, we may send relevant portions of Customer Content and prompts to our AI subprocessors (see Section 6) to generate outputs you request
4. How we use information
We use personal information for the following purposes:
Purpose
Examples
Provide the Services
Authenticate Shopify staff sessions; store and display your catalog; run imports, AI structuring, reviews, publishes, updates, migrations, and scheduled jobs; connect to Shopify, Dropbox, and other platforms you direct
Billing and plan enforcement
Process subscriptions, trials, entitlements, and usage limits
Security and abuse prevention
Detect fraud, unauthorized access, and violations of our terms
Improvement and analytics
Understand usage patterns; debug errors; develop new features
Communications
Send service-related messages, responses to support, and (where permitted) product updates
Legal compliance
Comply with law, respond to Shopify mandatory compliance webhooks, enforce our terms, and defend legal claims
We do not sell your personal information in the conventional sense of “selling” for money. We use service providers (subprocessors) who process data on our instructions, as described below.
Legal bases (EEA / UK / similar jurisdictions): Where required, we rely on one or more of: performance of a contract (providing the Services you requested); legitimate interests (security, improvement, analytics balanced against your rights); consent (where we ask for it, e.g. certain cookies or marketing); legal obligation.
5. How we share information
We may share information with:
5.1 Service providers (subprocessors)
Categories of providers we use include:
Shopify — embedded app authentication, Admin API access, App Billing, and mandatory compliance webhooks
Hosting and infrastructure (e.g. Vercel) — serving the application and related infrastructure
Database and authentication (e.g. Supabase) — tenant storage, application data, and file storage
Payments — Shopify App Billing (Shopify app); Stripe (standalone web product)
Email delivery (e.g. Resend, SMTP providers) — transactional and operational email
AI / machine learning (e.g. OpenAI) — processing prompts and content you submit to AI features
Analytics (e.g. Vercel Analytics) — aggregated usage and performance metrics
Dropbox — when you connect Dropbox for imports, Dropbox processes data according to your Dropbox account settings and Dropbox’s privacy policy
Google APIs — when you use Google Sign-In and/or Google Drive on the standalone web product, Google processes data according to your Google account settings and Google’s API Services User Data Policy as applicable
Pexels — optional experimental stock-image features, when enabled
We enter into agreements that require subprocessors to protect personal data and use it only for the purposes we specify.
5.2 Integrations you enable
When you connect third-party platforms (e.g. Shopify, Dropbox, WooCommerce, PrestaShop, BigCommerce, Squarespace, Wix), we exchange data with those platforms as necessary to perform actions you request (e.g. publish products, import folders, migrate catalogs). Those platforms process data under their own terms and privacy policies.
5.3 Legal and safety
We may disclose information if we believe in good faith that disclosure is necessary to:
Comply with law, regulation, legal process, or governmental request
Protect the safety, rights, or property of Loger, our users, or the public
Detect, prevent, or address fraud, security, or technical issues
Enforce our Terms of Use or other agreements
5.4 Business transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction. We will take steps to require the successor to honor this Policy or notify you of changes.
6. AI processing
Certain features use artificial intelligence models hosted by third parties (e.g. OpenAI). When you use those features:
Input you provide (including portions of Customer Content) may be transmitted to the AI provider to generate a response
Outputs are returned to you within the Services
You should avoid submitting highly sensitive personal data in AI prompts unless necessary. AI outputs may be inaccurate; you remain responsible for reviewing outputs before relying on them in your business (e.g. before publishing to live stores).
We configure services to minimize unnecessary retention where the provider allows, but AI providers may have their own retention and safety policies. Review their documentation for details.
7. Shopify-specific practices
7.1 App permissions
The Loger Shopify app requests permissions needed to manage products, inventory, and store locations in your Shopify store. It does not request access to Shopify customer records under its current configuration.
7.2 Mandatory compliance webhooks
Shopify requires apps to handle certain compliance webhooks:
Webhook
Our handling
customers/data_request
We do not store Shopify customer PII to export. We acknowledge valid requests.
customers/redact
We do not store Shopify customer PII to delete. We acknowledge valid requests.
shop/redact
We erase Loger data associated with the shop, including stored content, integration tokens, and the internal tenant record, subject to backup and legal retention limits described below.
app/uninstalled
We revoke Shopify API access and end Shopify billing entitlement. Catalog data may be retained to support reinstallation until a shop/redact request or other lawful deletion request.
8. International transfers
We may process and store information in the United States and other countries where we or our subprocessors operate. Those countries may have different data protection laws than your country.
Where required (e.g. EEA/UK), we implement appropriate safeguards such as Standard Contractual Clauses or other mechanisms approved by regulators, in addition to technical and organizational measures.
9. Retention
We retain information as long as necessary to:
Provide the Services and maintain your account or shop tenant
Comply with legal, tax, and accounting obligations
Resolve disputes and enforce agreements
Shopify uninstall. When you uninstall Loger, we revoke API access and clear Shopify billing entitlement, but we may retain Your Content and shop metadata for a period so you can reinstall without losing work.
Shop redact / deletion. When Shopify sends a shop/redact request, or when you request deletion as permitted by law, we delete or anonymize associated personal data and Customer Content within a reasonable period, subject to backup cycles and legal holds. Some residual copies may persist in encrypted backups for a limited time.
When you delete a standalone web account or specific content (where the product supports deletion), we follow a similar process.
You may contact us for more detail about retention for your account or shop.
10. Security
We implement technical and organizational measures designed to protect personal information (e.g. access controls, encryption in transit, secure hosting). No method of transmission or storage is 100% secure. You use the Services at your own risk to that extent.
You are responsible for:
Maintaining the confidentiality of your Shopify and Loger credentials
Revoking integrations you no longer trust
Ensuring your own compliance when processing personal data of your customers through connected stores and other tools
11. Cookies and similar technologies
We and our partners may use cookies, local storage, and similar technologies to:
Keep you signed in (session / authentication), including embedded Shopify sessions
Remember preferences
Measure traffic and performance (e.g. Vercel Analytics)
You can control cookies through browser settings. Blocking essential cookies may break login or core functionality.
Where required by law, we will obtain consent before non-essential cookies or similar tracking.
12. Your rights and choices
Depending on where you live, you may have rights to:
Access a copy of your personal information
Correct inaccurate data
Delete certain data
Restrict or object to certain processing
Data portability (receive data in a structured format)
Withdraw consent where processing was based on consent
Lodge a complaint with a supervisory authority (EEA/UK)
How to exercise rights: Email hi@loger.io. We may need to verify your identity or shop authorization before fulfilling requests.
California residents (CCPA/CPRA): You may have the right to know, delete, and correct personal information, and to limit use of sensitive personal information (if applicable). We do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined under CPRA, based on our current practices.
Do Not Track: There is no consistent industry standard; we do not respond to all DNT signals.
13. Children
The Services are not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take steps to delete it.
14. Third-party links
The Services may contain links to third-party sites. We are not responsible for their privacy practices. Read their policies before providing information.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version with a new “Last updated” date. If changes are material, we will provide additional notice as required by law (e.g. email or in-app notice). Continued use after the effective date constitutes acceptance of the updated Policy, except where prohibited.
16. Contact
Questions about this Privacy Policy or our data practices:
Loger Labs
Email: hi@loger.io
Address: Djupedalsvägen 27, 54136 Skövde, Sweden