2.1 Information from Shopify OAuth
When you install Sketch Audit, Shopify provides us with:
- Shop ID (unique identifier for your store)
- Shop name and shop domain
- Admin email address (from your Shopify account)
- Timestamp of installation and authorization
We use this information to:
- Create and manage your account
- Process your subscription and billing
- Contact you for critical account issues (e.g., GDPR data deletion requests)
2.2 Alert email address(es)
When you configure Sketch Audit, you separately provide one or more email addresses where you want to receive security alerts. These can be:
- Your personal email
- A team member’s email
- A shared inbox or group email
- Any external contact of your choice
We store these email addresses only to send security alerts when malware or suspicious code is detected in your store. We do not use these addresses for:
- Marketing or promotional emails
- Customer support (we do not provide email-based support)
- Any purpose other than alert delivery
2.3 SMS alert phone number (Pro)
On the Pro plan, you may optionally provide a mobile number for SMS alerts when a theme scan finds a problem that needs attention. We verify the number with a one-time code and require express consent before sending alerts. We use the number only for those security alerts and for processing STOP/opt-out requests. SMS is not included on Basic.
2.4 Store theme and code
To perform security scans, we collect and analyze:
- Theme HTML, CSS, and JavaScript files from your store’s theme
- SHA256 hashes of theme files (fingerprints to detect changes)
- URLs and domains loaded by scripts on your storefront
- Script code snippets that appear suspicious or unusual
We do not collect:
- Screenshots or visual data
- Customer data (names, emails, payment information)
- Store inventory or product data
- Customer browsing behavior
- Form submissions or user input
- Checkout page visuals
What we do with this data:
- Compare files day-to-day to detect malicious changes
- Analyze suspicious code patterns using an AI analysis service
- Store scan results in our database for 7 days (Basic and Pro)
- Generate alerts when compromises are detected
2.5 Scan results and alerts
We store:
- Scan timestamps (when each scan ran)
- Findings (suspicious files, malicious code snippets, URLs detected)
- Analysis results (AI-generated explanations and fix guidance)
- Alert logs (which alerts were sent, when, to whom)
You can delete this data anytime by uninstalling the App or requesting data deletion (see Section 7).
2.6 Browser extension data
The Sketch Audit Chrome extension is not currently offered on Basic or Pro. We do not collect page HTML or extension tokens for live-page scans as part of the current product. If we reintroduce the extension, we will update this Policy before offering it.
2.7 Support communications
Sketch Audit does not provide email-based support. If you contact us through our website contact form or other channels:
- We store your email address and message content
- We use this to respond to your inquiry and improve our service
- We retain contact messages for up to 30 days after responding
- If there is a dispute or suspected abuse, we may retain messages longer for investigation purposes
- Otherwise, all contact messages are permanently deleted after 30 days
We recommend consulting our help documentation or dashboard resources for common questions.