MERQORA
Privacy Policy
Last updated: August 9, 2026
This policy explains how MERQORA processes information when a Shopify merchant installs or uses the MERQORA app. MERQORA is designed to analyze product catalog quality and help merchants review and approve product-content improvements.
Information we process
- Shopify installation and authentication information, including the shop domain, granted product scopes, session records, and access credentials required to operate the installed app. When Shopify supplies them for an online administrator session, the session can also include the administrator's Shopify user ID, name, email, locale, and account flags.
- Product catalog information required by the requested workflow, such as titles, descriptions, SEO fields, product status, images, ALT text, vendor, and product type.
- Operational AI metadata such as model name, status, token usage, latency-related timestamps, and bounded error categories. MERQORA does not store full original or generated product copy in AI generation history.
- Questions and short conversation context submitted to AI Copilot. Copilot history remains in the current browser session and is not persisted by MERQORA.
- Limited technical logs required for security, reliability, and troubleshooting. Logs are designed to exclude API keys, Shopify tokens, raw AI errors, and full product content.
The current MERQORA version does not request or persist Shopify customer or order data, including customer IDs, customer contact details, addresses, orders, payments, or fulfillment records.
How we use information
We process this information to authenticate the installed shop, display product data, calculate rule-based store analyses, create merchant- requested AI suggestions, save changes explicitly approved by the merchant, provide support, and protect the service from misuse. MERQORA does not automatically publish AI-generated changes.
AI processing
Product information is sent to OpenAI only after an explicit AI action. Requests use the OpenAI API with response storage disabled. AI Copilot receives a bounded, structured store-analysis context and does not receive Shopify access tokens or database credentials. Merchants must review suggested content before any supported Shopify update.
Service providers
MERQORA relies on Shopify for app authentication and store APIs, OpenAI for merchant-requested AI processing, and infrastructure providers for application hosting and PostgreSQL persistence. These providers process information only as needed to deliver their respective services and under their own contractual and security obligations.
Retention and deletion
MERQORA keeps installation, session, and operational records only while they are needed to operate, secure, or support the service. When the app is uninstalled, Shopify revokes app access, MERQORA deletes its Shopify sessions, and marks the installation as uninstalled. When Shopify sends a verified shop-redaction request, MERQORA deletes the remaining shop installation and AI-generation metadata for that shop from its primary application database. Merchants may also request deletion of retained app records by contacting support. Legal or security obligations may require limited records to be kept for a longer period.
Security and access
MERQORA derives shop identity from the authenticated Shopify session, keeps secrets on the server, validates external input, and requests only product read and write access. The app does not request order, customer, payment, or inventory scopes in the current release.
Your choices
Merchants can choose whether to request AI content, whether to apply a suggestion, and can uninstall the app at any time. To ask for access, correction, export, or deletion of app-related information, contact us at support@terraforge.no.
Changes to this policy
We may update this policy as MERQORA, applicable law, or our service providers change. The date at the top identifies the current version.