GMC Fix Map

Privacy Policy

How GMC Fix Map handles Shopify and optional Google Merchant Center data.

Last updated: 21 July 2026

1. Scope

This policy explains how VaultDevLabs processes information when a merchant installs or uses GMC Fix Map. GMC Fix Map is a read-only diagnostic app for Shopify product readiness and optional Google Merchant Center issue mapping.

2. Shopify data we process

The app receives the shop domain and Shopify app session information needed to authenticate the installed shop. With the read-products permission, it reads product and variant data used for diagnostics, including IDs, titles, handles, status, vendor, product type, storefront URL, SEO fields, SKU, barcode, and price.

GMC Fix Map does not request customer, order, payment, checkout, discount, or product-write access. It does not edit Shopify products, themes, feeds, orders, or checkout settings.

3. Google Merchant Center data

A Pro merchant can choose to connect a Google account through OAuth. The app uses the granted Merchant Center scope in a read-only manner to list accessible Merchant Center accounts and import relevant product-status and account-level issues. It does not create, update, or delete Merchant Center data.

Google access and refresh tokens are encrypted server-side and are not exposed to the browser. The app stores the selected Merchant Center account ID, granted scope, token expiry, connection timestamps, import status, and encrypted tokens while the connection is active.

GMC Fix Map's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, used for advertising, or used to train general-purpose artificial intelligence models.

4. App records and purpose

We store the minimum records needed to operate the fix queue and paid features. These can include scan timestamps, issue identifiers, status, mapped product or variant labels, evidence, scheduled recheck status, change and alert history, billing-entitlement cache data, and Google connection metadata.

We use this information to provide requested diagnostics, secure the service, prevent abuse, troubleshoot support requests, and comply with legal obligations. We do not sell merchant or Google user data.

5. Google data sharing and disclosure

We do not share Google user data with independent third parties for their own purposes. Google user data is disclosed only to the following recipients when needed to provide GMC Fix Map:

  • Google processes OAuth requests, Merchant API requests and responses, and token revocation requests.
  • Render, our contracted hosting and managed database provider, processes encrypted OAuth tokens, Merchant Center account metadata, and imported issue records to operate the service.
  • Shopify displays the merchant's mapped diagnostics inside the embedded Shopify Admin app and supplies the merchant's own product data used for matching.
  • Authorized VaultDevLabs staff may access the minimum Google data necessary to resolve a merchant-requested support issue, investigate abuse or a security incident, or comply with law.

Google user data is not routinely sent to our email provider. If a merchant voluntarily includes Google data in a support email, the email provider processes that message only to deliver and retain the support correspondence. We do not disclose Google user data to advertisers, data brokers, or third-party artificial intelligence model providers, and we do not sell it. A protected business transfer may include app records only where permitted by law and subject to this policy and the Google API Services User Data Policy.

6. Retention and deletion

App records are retained only while needed to provide the service, support the merchant, resolve disputes, prevent abuse, or meet legal requirements. Disconnecting Merchant Center deletes the stored Google connection and queues token revocation. Uninstalling the app or an applicable Shopify redaction request deletes Shopify sessions, Google connection data, and related shop records.

After redaction, a minimal lifecycle tombstone containing only a one-way hash of the shop domain, a random generation value, and the deletion timestamp can be retained to prevent an in-flight request from recreating deleted app data. It contains no readable shop domain. A later authorized reinstall replaces that generation before new app data can be written.

If Google is temporarily unavailable during deletion, encrypted token revocation material can be retained under a random, de-identified retry reference only until Google confirms revocation. It is not used to reconnect the app or identify the deleted shop. Tokens issued during a connection attempt that cannot be completed use the same de-identified revocation-only process.

Limited security, billing, and legal records may be retained where required by law or needed to resolve a dispute.

7. Security

We use technical and organizational safeguards including encrypted Google tokens, authenticated app routes, least-privilege Shopify access, and access controls. No online service can guarantee absolute security.

8. Your rights and contact

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. For a privacy request, email support@vaultdevlabs.com. You can also use the support page.