Privacy Policy
Effective: 2026-08-24 · TabsBy (“we”, “us”, “our”)
Summary
TabsBy is a display-only Shopify app. We read your product descriptions and product metafields so we can render them as tabs on your storefront. We do not collect, store, or share buyer data. We do not access orders, customers, or checkout.
What we collect
- Shop identity — your
.myshopify.comdomain and an OAuth access token, so the app can call Shopify on your behalf. - Shopify session information — session identifiers, access and refresh tokens, requested scopes, expiry times, and, when Shopify supplies them, the logged-in user's ID, name, email, locale, account-owner status, collaborator status, and email verification status. We use this information to authenticate the app and keep its Shopify session working.
- App configuration — the tab templates, per-product overrides, default content, and styling preferences you create inside the app. Stored in our database.
- Product data (read-only) — product descriptions and product metafields, fetched on demand from Shopify when a storefront page is rendered. We do not persist product data.
What we do not collect
- Buyer or customer personal data.
- Orders, carts, checkouts, or payment data.
- Buyer advertising profiles or storefront tracking pixels.
Scopes we request
read_products — required to render the product description and metafields as tabs. Nothing else.
Third parties
- Shopify — hosts the OAuth flow and serves the Admin API we read from. Subject to Shopify's privacy terms.
- Neon — Postgres database for tab configuration.
- Vercel — application hosting and server logs. Error diagnostics and ordinary request metadata may be processed there; no buyer profiles are created and no buyer data is sent to a separate third-party error-tracking service.
Retention & deletion
We retain app configuration and Shopify session records while the app is installed. When Shopify delivers an app/uninstalled orshop/redact webhook, our handler deletes the shop record, its session records, and related configuration. We have no buyer data to redact, so the customers/data_request and customers/redact webhooks return 200 with no data.
Security & incident response
Data is encrypted in transit (TLS 1.2+) and at rest by our database provider. Webhooks are HMAC-verified. Production access is limited to the app operator. If we become aware of a security incident affecting your data, we will contact affected merchants using the contact details available to us and make any notices required by applicable law or Shopify's policies.
Your rights
Email danny@8thorigin.com from the store-owner email on file to request export or deletion outside the uninstall flow. We respond within 5 business days.
Changes
We may update this policy. Material changes will be announced in-app before they take effect.
Contact
danny@8thorigin.com