Privacy Policy
Last Updated: September 2026
Introduction
Welcome to ProfitPilot.
ProfitPilot is a Shopify application operated by Purple IT that helps merchants understand product profitability before launching marketing campaigns. By tracking product costs, pricing, and promotional strategies, ProfitPilot provides merchants with profit simulations and decision support.
We respect your privacy and are committed to protecting your business information.
This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
Shopify Scope and Data We Access
ProfitPilot requests the following Shopify Admin API scopes: read_products, write_products, read_inventory, and write_inventory.
With those permissions, ProfitPilot may access the following Shopify data as needed to provide the service:
- Product ID
- Product title
- Product status
- Product variants and variant IDs
- Product/variant selling prices
- Featured image URL and alt text (when available)
- Inventory item IDs associated with variants
- Inventory item cost / Cost per item (
unitCost) when available - Store currency (
shop.currencyCode)
Product titles, images, status, variant details, and inventory cost information are retrieved as needed for display and decision support and are not persistently stored as a full product catalog. Product IDs and selected variant IDs for products you choose to track are stored as described below.
ProfitPilot does not automatically modify Shopify products, variants, or inventory costs. Shopify modifications occur only when you explicitly use and confirm the Apply to Shopify feature. When confirmed, ProfitPilot may update only the selected or resolved Shopify variant's selling price and the associated inventory item's product cost.
Information We Do NOT Access or Store from Shopify
Through Shopify Admin APIs, ProfitPilot does not access or store:
- Customers
- Orders
- Draft orders
- Checkouts
- Inventory quantities or stock levels
- Shopify discounts or price rules
Customer and order data are not part of ProfitPilot's Admin API access. ProfitPilot does not collect customer names, addresses, phone numbers, payment information, or credit card information as part of its product functionality.
Merchant-Provided Data We Store
Merchants manually enter costing and pricing information in ProfitPilot. The following merchant-provided data is stored in our PostgreSQL database:
- Product cost
- Cost items (including packaging, shipping, payment / transaction fees, and other custom costs)
- Selling price
- Optional notes associated with a cost profile
Product IDs and Shopify variant IDs are also stored for tracked products and associated cost profiles so the app can reconnect your entered costs to the correct Shopify products and variants.
Selling prices and cost data used in simulations are entered by you in ProfitPilot. They are written back to your Shopify catalog only when you explicitly confirm Apply to Shopify. That action updates the selected Shopify variant using values already available in the app (the confirmed selling price and saved product cost) and does not create simulation records or otherwise rewrite CostProfile or CostItem data as part of the Apply flow.
Strategy Simulation Inputs
Pricing and promotion strategy simulation inputs are processed client-side for decision support. They are not permanently stored as strategy records.
Authentication and Session Data
To authenticate your store and keep the app connected to Shopify, ProfitPilot stores:
- Shopify store domain
- Shopify session information
- Shopify access tokens
- API scope information
- Session metadata
How We Use Information
Information is used only to:
- Authenticate your Shopify store
- Provide ProfitPilot features
- Save your product costing and selling price information
- Display tracked products and generate profitability simulations
- Apply merchant-confirmed selling price and product cost updates to the selected Shopify variant
- Improve application stability
- Maintain application security
- Comply with Shopify privacy requirements
Infrastructure and Data Storage
ProfitPilot is hosted on Vercel. Persistently stored merchant and session data is kept in a PostgreSQL database hosted on Neon.
This includes Shopify shop and session authentication information, tracked product references (product IDs and selected variant IDs), and merchant-entered cost and selling price information.
Reasonable administrative and technical safeguards are used to protect stored information. No method of electronic storage is completely secure; however, we take reasonable measures to reduce risk.
Data Sharing
ProfitPilot does not sell personal information or merchant data.
We only share information when required to:
- Operate the application (including infrastructure providers such as Vercel and Neon)
- Comply with applicable law
- Respond to lawful government requests
ProfitPilot does not sell or share merchant data with advertisers or unrelated third parties for their marketing purposes.
Uninstall and Data Deletion
Merchants may stop using ProfitPilot at any time by uninstalling the application from Shopify.
When the app is uninstalled, the app/uninstalled webhook deletes Shopify session and access-token records for the store.
Cost profiles, cost items, and tracked product data are removed when Shopify sends the shop/redact compliance webhook, rather than necessarily at the exact moment of uninstall. There is no separate fixed retention period coded into the application beyond this Shopify-driven process.
Shopify Privacy Compliance Webhooks
ProfitPilot registers and authenticates Shopify's required privacy compliance webhooks:
customers/data_request— acknowledges the request. Because ProfitPilot does not store customer records, it does not search for or export customer records in response.customers/redact— acknowledges the request. Because ProfitPilot does not store customer records, there are no customer records to delete.shop/redact— deletes store-related application data currently stored by ProfitPilot, including CostProfile records (with CostItem cascade), TrackedProduct records, and remaining Session records.
Customer information that may appear in Shopify privacy webhook payloads is not stored by ProfitPilot as customer records.
Your Rights
Merchants may:
- Request information regarding stored data
- Request deletion where applicable
- Stop using the application at any time by uninstalling it from Shopify
Security
We work to protect merchant information using industry-standard security practices appropriate to the nature of the data we store.
Changes to This Policy
This Privacy Policy may be updated as ProfitPilot evolves.
Material changes will be reflected by updating the "Last Updated" date above.
Contact
If you have questions regarding this Privacy Policy, please contact:
Company
Purple IT