Theme Workspace - Privacy Policy
Last updated: August 31, 2026
Theme Workspace ("the App") is a Shopify application built and operated by Ecommerce Pro ("we", "us", "our"). This Privacy Policy explains what information the App accesses, what we store, how we use it, and how it is protected and deleted. It applies solely to the Theme Workspace app and not to any other Ecommerce Pro product or service.
By installing or using Theme Workspace, the merchant ("you") agrees to the practices described here.
1. What the App does
Theme Workspace is a documentation and governance layer for Shopify themes. It lets a merchant's team attach context (status, owner, purpose), notes, and warnings to the themes in their store, and it keeps an automatic activity log of theme and team changes. The App is designed to help teams understand why each theme exists, who owns it, and what is safe to publish or delete.
2. Information the App accesses
Theme data (read-only). The App requests the read_themes scope. It reads theme metadata and theme files from your store in order to display your themes and detect changes (for example, when a theme is published, edited, renamed, or deleted). The App has read-only access to themes and never modifies, publishes, or deletes any theme or theme file in your store.
Store information. The App accesses basic store information provided by Shopify at install, such as your store domain, store name, plan, primary locale, and timezone. This is used to operate the App, deliver notifications at an appropriate local time, and provide support.
The App does not access or request customer data, order data, product data, payment or financial information, or any personal information belonging to your store's customers.
3. Information we store
We store only the data required for the App to function:
- Theme context and notes that you and your team members create within the App — including theme status, owner, purpose ("why it exists"), notes, warnings, and custom status labels.
- Team member records — the display name and, where provided, the email address of the people on your team who use the App. Team members are identified by their Shopify user ID (assigned by Shopify at sign-in); we do not create separate passwords or logins.
- Activity log entries — automatically generated records of theme events (created, edited, published, unpublished, renamed, deleted) and team/settings events (people joining, role changes, settings changes, exports), each attributed to the responsible user where applicable.
- Notification recipient settings — email addresses you choose to receive alerts, weekly digests, or scheduled exports. These recipients may include people who are not App users (for example, a client contact) and are stored only to deliver the notifications you configure.
We do not store your customers' personal information, order details, product data, payment information, or the contents of your theme files. Theme files are read on demand to detect changes and are not retained.
4. How we use the information
We use the stored information solely to:
- Provide the App's core features — displaying themes with their context, notes, warnings, and activity history.
- Attribute actions to the correct team member in the activity log.
- Send the notifications you enable (publish/unpublish alerts, @mention emails, weekly digests) and deliver scheduled exports, to the recipients you specify.
- Provide support and respond to messages you send us through the App.
- Maintain the security and integrity of the App.
We do not sell, rent, or share your information with third parties for marketing purposes, and we do not use it for advertising.
5. Sub-processors and infrastructure
The App is hosted on Gadget (gadget.dev), which provides the App's backend infrastructure, database, and Shopify integration on our behalf. Data is processed and stored through Gadget's infrastructure. We use an email delivery provider to send the notification emails you enable. These providers process data only as necessary to run the App and are bound by their own security and privacy obligations.
We do not transfer your data to any other third parties except as required to operate the App or as required by law.
6. Data retention and deletion
We retain your App data for as long as the App is installed on your store, so that your context, notes, and history remain available to your team.
When you uninstall the App, we stop all processing (no further reads, webhooks, or emails) and mark your store's data for deletion. In accordance with Shopify's requirements, if you reinstall within 48 hours your data is restored. If the App is not reinstalled, we permanently delete all data associated with your store.
Shopify mandatory compliance webhooks. The App implements Shopify's required data-protection webhooks:
-
shop/redact— on receipt (sent by Shopify 48 hours after uninstall), we permanently delete all data associated with your store. -
customers/redactandcustomers/data_request— the App stores no customer personal information, so there is no customer data to erase or return; these requests are acknowledged accordingly.
You may also request deletion of your data at any time by contacting us (see Section 9).
7. Data security
We take reasonable technical and organizational measures to protect your information. Access to the App requires authentication through your Shopify session, and communication between Shopify and the App is verified and encrypted in transit. Only the data described in this policy is stored, minimizing exposure. While no method of transmission or storage is completely secure, we work to protect your information using industry-standard practices.
8. Your rights
Depending on your jurisdiction (including under the GDPR and CCPA), you may have the right to access, correct, export, or delete the data we hold about your store and team. Because the App does not store your customers' personal data, these rights relate to the merchant and team information described above. To exercise any of these rights, contact us at the address in Section 9. You can also export your workspace data at any time from within the App using the Export feature.
9. Contact
For any questions about this Privacy Policy or your data, or to make a data request, contact:
Ecommerce Pro Email: support@ecommercepro.com Website: https://ecommercepro.com
10. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated through the App or by email where appropriate. Continued use of the App after changes take effect constitutes acceptance of the updated policy.
This policy applies to the Theme Workspace Shopify app, operated by Ecommerce Pro. It does not cover other Ecommerce Pro services.
