1. Who we are
SLS ("we", "our", "us") operates the SLS.sh website and the SLS Shopify app (the "Service"). This policy explains what data we collect, why we collect it, and how we protect it.
Questions? Email us at privacy@sls.sh.
2. Data we collect
Data you provide
- Shopify store domain and access tokens (obtained via OAuth during installation)
- Pairing codes used to link two stores together
- Billing plan selection
Data we receive from Shopify
When you authorise the app, we receive read and write access to your store's products, collections, and pages. We use this access only to power the comparison and deploy features. We do not sell or share this data with third parties.
Usage data
We log deploy jobs (resource type, status, timestamps) so you have an audit trail and so we can detect errors. We do not track individual page views or build marketing profiles.
3. How we use your data
- Authenticate your Shopify sessions and keep them secure
- Fetch and compare resources between your paired stores
- Execute deploy jobs you initiate
- Enforce plan quotas and process billing via Shopify Billing API
- Respond to support requests
We will never use your store data to train machine learning models.
4. Data storage and security
Your Shopify access tokens are encrypted at rest using AES-256-GCM before being stored in our database. Our infrastructure runs on Railway (EU region) with a Supabase-managed PostgreSQL database. We use TLS for all data in transit.
We retain session and job data for as long as your store remains connected. When you uninstall the app, we delete your session and pairing data within 48 hours.
5. Third-party services
We use the following sub-processors:
- Shopify — merchant authentication and billing
- Railway — application hosting
- Supabase — database hosting
- Cloudflare — marketing site hosting and CDN
Each provider is subject to their own privacy policy and security practices.
6. Your rights
You can request a copy of the data we hold about your store, or request deletion, by emailing privacy@sls.sh. We will respond within 30 days. You may also uninstall the app at any time from your Shopify admin — this revokes our access tokens immediately.
7. Cookies
The SLS app uses a single session cookie to maintain your authenticated state inside the Shopify admin. The marketing site (SLS.sh) does not set any analytics or tracking cookies.
8. Changes to this policy
If we make material changes, we will update the "Last updated" date at the top of this page. For significant changes we will notify you via the app or email.