Zolo Digital
Let’s Connect
PriceToolKit

PriceToolKit Privacy Policy

Last updated: 27 September 2026

PriceToolKit is operated by Zolo Digital. This policy describes what the app stores, why, and for how long. It is written from the database schema rather than from a template: every item below corresponds to something the app actually records.

The short version

PriceToolKit stores no data about your customers. It never requests the read_customers or read_orders scopes, and holds no orders, carts, customer records, addresses or payment details. What it stores is your product catalog, the competitor pages you choose to track, and the prices it reads from those public pages.

What we store about your store

  • Your .myshopify.com domain, plan, and store currency.
  • An access token for the Shopify Admin API, so the app can read your catalog and write prices you have approved. It is kept in the app's private database and is never shown in the interface or shared.
  • Your app settings: repricing mode and caps, digest preferences, channel matching preferences.

What we store about people

  • A contact email for the daily digest. Taken from your store's contact email when you install, and editable in Settings. It is used only to send you the digest you asked for.
  • Shopify staff session details. When a staff member opens the app, Shopify's session record may include their name, email, locale and staff account id. This comes from Shopify's own authentication and is used only to keep them signed in.

That is the complete list of personal data. There is no other.

What we store about your products

Product and variant records synced from your store: title, vendor, product type, tags, status, handle, SKU, barcode, price, compare-at price, unit cost and inventory quantity. Unit cost is used only to enforce the minimum-margin rules you configure.

What we store about competitors

  • The competitor URLs you add, import, or accept from a suggested match.
  • Prices, currency and stock status read from those pages, with timestamps.
  • Learned extraction details per competitor domain (which part of the page holds the price), so repeat checks are cheap and reliable. These describe competitors' public websites rather than your store, and are shared across the app.

All of this is information published openly on those retailers' own websites.

What we store about what the app did

Suggestions with the reasoning behind them, every price change pushed to your store, reverts, and alerts. This audit trail is what lets you see and undo anything the app did.

Third parties

Data leaves our systems only in these cases, and only when you have configured that feature:

  • Shopify receives price updates you approved, to change prices in your store.
  • Resend receives your digest email address and the digest, to deliver the daily email.
  • A scraper-API provider receives a competitor's public URL, to fetch pages that block direct requests.
  • Anthropic receives trimmed HTML of a competitor's public page, to identify where the price sits on unusual pages.
  • A SERP provider receives a product title or barcode, to find retailers selling the same product.

The last three are optional and inactive unless configured. No customer data is sent anywhere, because none is held. The page content sent for selector discovery is a competitor's public product page — never your store's data.

We do not sell data, and we do not use your data to train models.

How long we keep it

  • Price history and everything else: for as long as the app is installed. The app shows the last 90 days of price history.
  • After you uninstall: Shopify sends a shop/redact request 48 hours later, and we erase everything belonging to your store at that point — your catalog, competitors, prices, rules, suggestions, price changes, alerts and sessions. You do not need to ask. Learned extraction details about competitor websites aren't tied to your store and are kept.

You can also email us to have your data erased sooner.

Your rights

You can ask us what we hold about you, ask for a copy, ask for corrections, or ask for erasure. Email privacy@zolodigital.com and we will respond within 30 days.

We respond to Shopify's mandatory customers/data_request, customers/redact and shop/redact webhooks. The two customer topics return nothing, because no customer data exists to return.

Security

Access tokens are kept in the app's private database and never exposed in the interface. All traffic runs over HTTPS. Access to production data is limited to the operator of the service.

If a breach affects your data, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it.

Changes

Material changes will be announced in the app before they take effect. The date at the top of this page always reflects the current version.

Contact: privacy@zolodigital.com