Skip to content
ShopGrade logo ShopGrade
Menu Product For agencies For brands Sample report Pricing Sign in Add to Chrome
Sign in Add to Chrome
Legal

Privacy Policy

Last updated: September 30, 2026 · Applies to shopgrade.in and the ShopGrade Chrome extension

On this page
  1. Who controls your data
  2. Prominent disclosure and your consent
  3. How storefront analysis works
  4. Optional screenshots and AI analysis
  5. What data we collect
  6. Passwords and account credentials
  7. How we use the data we collect
  8. How and where your data is stored
  9. Website analytics and cookies
  10. How and with whom your data is shared
  11. How we protect data
  12. Legal bases, how long we keep your data, and international transfers
  13. Your privacy rights
  14. Children
  15. Deleting data
  16. Chrome Web Store Limited Use disclosure
  17. Grievance contact
  18. Changes and contact
The short version

ShopGrade stays dormant until you consent. It checks HTTPS pages for Shopify markers and deeply analyzes only confirmed, publicly accessible Shopify storefronts. On those stores it processes public page text and structure, URLs, resource timing, and performance signals. It never reads what you type into other websites, including passwords entered on the sites you visit, and it never reads private messages or network request and response bodies. Your ShopGrade account password is a separate thing: you type it into ShopGrade's own sign-in form, and Passwords and account credentials below sets out in full what is collected, how it is handled, who it is shared with and how long it is kept. Individual audit data is local by default; optional AI, sharing, monitoring, and Agency workspace features send the data described below. The sections that follow set out exactly what we collect, how we use it, where it is stored, who it is shared with, how long it is kept, and how to get it deleted. ShopGrade never sells your data. Extension and audit data are never used for advertising. Separately, the website offers optional Meta advertising measurement, described below.

Who controls your data

ShopGrade, operated by Yuvaraj, an individual based in Bangalore, India, provides the ShopGrade Chrome extension, shopgrade.in, and related services, and is the controller of personal data described in this policy. Contact support@shopgrade.in for privacy questions or requests.

Prominent disclosure and your consent

Before ShopGrade collects anything, it tells you what it will collect and asks you to agree. On first run the extension is dormant and shows a disclosure headed Choose what ShopGrade can analyze. That screen names the data involved: HTTPS pages are checked for Shopify markers, and only on a confirmed public Shopify storefront does ShopGrade process the current URL, visible public text and DOM metadata, resource timing and performance signals. It states that the values you type into the pages you visit, including passwords entered on those pages, along with private messages and request and response bodies, are never read, that live audits run in your browser, and that generating a shareable report sends the store URL, the audit data and your report settings to ShopGrade's servers. It links to this policy. No storefront data is collected until you choose Agree and enable Shopify audits.

Consent is recorded per install and is versioned, so a material change to what is collected asks for a fresh agreement instead of reusing the old one. Two further activities each require their own separate, affirmative opt-in and stay off until you give it: optional visual AI analysis, which asks you to confirm a second time before any screenshot or audit context is sent to OpenAI, and website analytics on shopgrade.in, which does not load until you select Accept analytics. You can withdraw storefront-analysis consent at any time from Storefront analysis consent in the extension's settings, which turns automatic Shopify detection and audits back off, and you can withdraw analytics consent from Cookie settings in the site footer.

How storefront analysis works

After you choose Agree and enable Shopify audits, the extension can run on HTTPS pages so it can recognize Shopify storefronts on custom domains. On unconfirmed pages it performs only the checks needed to determine whether Shopify markers are present. Deeper analysis starts only after a page is confirmed as a public Shopify storefront.

On a confirmed store, ShopGrade processes the current URL and hostname; visible public text; titles, meta tags, links, buttons, images and alt text; structured data; Shopify theme and app indicators; page structure counts; resource URLs, sizes and timing; and browser performance signals such as LCP, CLS, INP, FCP, TTFB and long tasks. This is website content and web-browsing activity under Chrome Web Store terminology, even though it concerns a public storefront.

The extension does not read form-field values, passwords or private messages on the pages you visit, browser history outside pages where it runs, payment-card data, or network request and response bodies. This holds for every site, including the store being audited: ShopGrade has no access to a Shopify admin and never asks for one. The only password ShopGrade ever receives is the one you deliberately type into its own sign-in, sign-up or password-reset form, which the next section describes in full. It does not sell data or use it for advertising.

Optional screenshots and AI analysis

Visual AI analysis runs only after you confirm the disclosure. ShopGrade asks Google PageSpeed to render the audited store's public homepage and optional product page in an isolated server-side browser without your Chrome cookies. It then sends those rendered screenshots together with the store URL, measured audit metrics, industry, and any monthly revenue you entered to OpenAI. It never captures or sends your normal-profile session.

Other AI report features may send the audited store URL, measured storefront findings, report settings, industry, currency and optional monthly revenue to OpenAI when you request the feature. AI output and modeled revenue opportunities are advisory estimates, not guarantees.

What data we collect

In addition to the storefront data described in the two sections above, ShopGrade collects the following:

  • Account and authentication: name, email address, account identifiers, verification/recovery state, the password you choose for your ShopGrade account (when you sign up with email rather than Google), authentication session tokens, and Google OAuth data if you choose Google sign-in. Passwords are covered in full in Passwords and account credentials below.
  • Preferences and report inputs: persona, agency/store name, logo, brand color, prepared-by name, audit focus, thresholds, excluded domains, industry, currency, and optional monthly revenue.
  • Usage and anti-abuse: plan, billing period, report quota, report credits, a per-install identifier, a coarse client-provided SHA-256 device marker, and keyed one-way request/network markers derived from the client IP that Appwrite supplies to our function. These signals enforce free-quota and hosted-report request limits, not advertising; ShopGrade does not store the raw IP in these records.
  • Billing records: Paddle customer/subscription identifiers, plan and status. Paddle, our Merchant of Record, handles card and payment details; ShopGrade does not receive card numbers.
  • Monitoring: store URL, last score, change thresholds, schedule, and alert destination when you explicitly enable a monitor.
  • Team and client workspace: team membership, roles, invite email addresses, client/store names, notes, stages, folders, tags, scores, dates, LCP/CLS/INP values, and audit history for Agency workspace collaboration.
  • User-generated reports: audit data and eligible branding uploaded when you generate a secure server-hosted report, plus the short-lived job record that carries that generation's result back to the extension.
  • Technical and log data collected automatically: when the extension or the website contacts our backend, our hosting provider Appwrite records an execution and request log containing the timestamp, requested path, response status, duration, error diagnostics, and the client IP address and user-agent string its edge receives. ShopGrade's own code writes only error diagnostics to these logs. They exist for operations, debugging and security, are readable only by the operator named above, are never used for advertising or profiling, and are discarded after a limited operational period.

Passwords and account credentials

ShopGrade offers email-and-password accounts, so it collects a password. This section states exactly what is collected, what it is used for, how it is handled and stored, who it is shared with, and how long it is kept.

What is collected, and where you enter it. If you create a ShopGrade account with an email address, you choose a password (10 to 256 characters) and type it into a ShopGrade form. There are four such forms and no others: the sign-up and sign-in form in the extension's popup; the sign-in form in the account dashboard at dashboard.shopgrade.in; the Choose a new password form on the password-reset page reached from an emailed reset link; and the change-email and change-password forms in the account dashboard, which ask for your current password to confirm it is you. Password managers may fill these forms for you. ShopGrade collects a password at no other moment and from no other source, and it never collects passwords for Shopify, Google, or any other service.

If you use Sign in with Google, ShopGrade receives no password at all. Google authenticates you and returns an authentication result; you can still choose to set a ShopGrade password later, and only then is one collected.

What it is used for. Your password is used for one purpose: proving that you are the account holder. Concretely, it creates your account, signs you in, re-confirms your identity before an email or password change, and lets you set a new password after a reset. It is never used for any other purpose. It is never used for advertising, personalization, profiling, analytics or scoring, is never sold, is never given to a data broker, is never included in an audit, report, monitor alert or export, and is never sent to any AI system.

How it is handled and stored. Your password is transmitted only over HTTPS. From the extension popup and the account dashboard it goes directly from your browser to Appwrite, our authentication provider, which is the only party that stores it and stores it as a salted cryptographic hash rather than in readable form. The one exception is the password-reset page: the new password you type there is posted to ShopGrade's own reset function, which holds it in memory for the length of that single request purely to pass it to Appwrite, and then discards it. That function does not write it to any database, log line, error report or analytics event. ShopGrade keeps no plain-text copy of your password anywhere, at any point, and the operator cannot read your password. After sign-in, what is retained on your device is a session token, not your password: the extension keeps it in the extension's own storage in Chrome and the website keeps it in your browser. Resetting your password revokes every existing session, so anyone else signed in to your account is signed out.

Who it is shared with. Only Appwrite, acting as our authentication processor under contract and storing account records in its Frankfurt (EU) region. Your password is not shared with anyone else, and specifically is not shared with OpenAI, Google, Paddle, Resend, jsDelivr, any advertiser, or any other third party. When you ask for a password reset, our email provider Resend receives your email address and a single-use reset link so it can deliver the message; it does not receive your password, and neither the old nor the new password ever appears in an email.

How long it is kept. Appwrite keeps the hash of your current password for as long as your account exists. Setting a new password replaces it. Deleting your account deletes it along with your other authentication records, as described under Deleting data. The plain-text password you type is never retained beyond the request that authenticates or sets it.

What ShopGrade does not do with passwords. It does not read, capture, intercept, autofill or store passwords on any website you visit, including Shopify storefronts it audits. The content script that runs on a storefront never reads form-field values of any kind. Passwords are not part of the storefront data described earlier in this policy.

How we use the data we collect

ShopGrade uses each category above only for the purpose it was collected for:

  • To run the audit you asked for: storefront page data is turned into scores, findings and prioritized recommendations and shown to you in the extension and your report.
  • To build and host reports you generate: audit data, report settings and eligible branding are used to render the report document and serve it at its capability link.
  • To provide optional AI analysis: when you request it, storefront findings and, for visual analysis, server-rendered screenshots are sent to OpenAI so it can return the written analysis and modeled opportunities.
  • To run your account: your name, email and account identifiers identify you, your password (or your Google sign-in) authenticates you, and the resulting session token keeps you signed in. These also let you recover access and let us send account-security and service email. Authentication data is used for authentication and nothing else.
  • To operate the features you switch on: monitoring records schedule the checks and deliver change alerts; Agency workspace records let the team you invite collaborate on shared client data.
  • To take payment and manage your plan: Paddle identifiers and plan state determine your quota, entitlements, renewals, cancellations and refunds.
  • To enforce quotas and prevent abuse: plan counters, the per-install identifier, the device marker and the keyed network markers stop free-quota and hosted-report limits from being bypassed.
  • To keep the service secure and working: log and error data is used to debug faults, investigate abuse and protect accounts.
  • To meet legal obligations: billing and tax records are retained, and lawful requests answered, where the law requires it.
  • To measure the website, only if you consent: Google Analytics 4 reports aggregate visits on shopgrade.in and on the account portal at dashboard.shopgrade.in. It is not part of the extension.

ShopGrade does not sell your data or share it with data brokers. Extension, audit and workspace data are never used for advertising, personalized advertising or advertising profiles. ShopGrade does not use your data for credit, lending or insurance decisions or for purposes outside this policy. Data sent to OpenAI travels through its business API, which excludes that content from training OpenAI's models by default. No human at ShopGrade reads your audit or workspace data except with your consent, where it is necessary for security or to resolve a support request you raised, or where the law requires it.

How and where your data is stored

  • Individual workspace: settings, leads and audit history are stored in Chrome extension storage on your device by default.
  • Agency workspace: client records and audit history are synchronized to ShopGrade's Appwrite backend so authorized team members can collaborate across devices.
  • Reports: generation uploads the report and eligible branding to the backend, where it is private to your account and readable only by you. If you open a public link, anyone holding that link can read the report for 15 days, after which it returns to being private automatically; each report can be shared twice. A report is kept until you delete it, and deleting it removes it permanently and immediately.
  • Audit results while a generation is running: when you start a report, the server-side result (the Google PageSpeed data and any AI output) is held in a short-lived job record so the extension can collect it. The extension deletes that record as soon as it reads the result, and a scheduled cleanup removes any record left behind after one hour.
  • Account, quota, monitoring and team records: stored with Appwrite in its Frankfurt (EU) region.

Website analytics and cookies

shopgrade.in and the account portal at dashboard.shopgrade.in offer optional Google Analytics 4 to measure aggregate visits, viewed pages, referrals, and device/browser information, including which pages led to creating an account or completing a purchase. Google Analytics is not loaded until you select Accept analytics, on either address. Essential site functions remain available if you choose Essential only. The extension itself does not include Google Analytics.

Google Analytics is used to measure the website in aggregate, and Google Signals is switched off, so Google Analytics data is not used to build advertising audiences, personalise ads, or track you across devices.

Optional Meta advertising measurement. If you choose Accept analytics & ads, the website also loads Meta Pixel. It sends page visits, pricing views, sample-report opens, clicks to the Chrome Web Store, checkout starts and completed purchases (amount, currency and a transaction event identifier). Meta also receives the page URL, browser/device information, IP address and advertising cookie identifiers, which it can use to attribute conversions, optimise ad delivery and match activity to Meta accounts. A store-listing click is not a confirmed extension installation. We do not install Meta Pixel in the extension or send audit content, passwords, form-field values or payment-card details. Automatic advanced matching and automatic event detection are disabled.

Campaign attribution and account outcomes. If you accept analytics, or analytics & ads, the website remembers where your first visit came from (the campaign tags in the link, whether it came from a Meta or Google ad click, the referring website's address and the page you landed on) in a first-party sg_attr cookie for up to 90 days. We do not record a direct visit. When you use the account portal, that record is attached to your ShopGrade account together with your current consent choices, so we can tell which campaigns lead to verified accounts, first reports and purchases. Three outcomes are recorded on our own servers: your account's email address being verified, your first report being generated, and each completed purchase. Your first report is only ever counted in our own records and is never sent to Google or Meta. With analytics permission, a verified account and each completed purchase (amount, currency and transaction identifier) are also sent from our servers to Google Analytics under your existing Google Analytics identifier, without your name or email address. With advertising permission they are also sent to Meta, with the same Meta cookie identifiers, IP address and browser information Meta Pixel would receive, and never your email address or phone number. Withdrawing consent deletes the sg_attr cookie, and the next time you open the account portal the matching identifiers are removed from your account and nothing further is sent. Plan renewals are not reported as purchases.

Accept analytics enables Google Analytics without Meta. Essential only declines both. Previous Google Analytics consent does not enable Meta: advertising permission is stored separately and must be explicitly granted. Meta may use first-party _fbp and _fbc cookies (typically up to 90 days). You can withdraw permission through Cookie settings; this stops Meta tracking and clears accessible Meta cookies. Meta handles data already received under its Privacy Policy.

Your choice is recorded in a cookie set on shopgrade.in, so that accepting or declining once covers the website and the account portal rather than asking you again on each. That record is kept for 180 days, and a copy is stored in your browser's local storage as a fallback. You can accept, reject, or withdraw consent at any time through Cookie settings in the site footer. Withdrawing clears accessible ShopGrade analytics cookies and reloads the page to stop analytics. Google's processing is described in the Google Privacy Policy.

How and with whom your data is shared

ShopGrade shares data only with the processors below, only to deliver the feature you used, and only under contract terms that bind them to our instructions. We also disclose data where the law compels it, to protect the rights and safety of users or the service, and to a successor if the service is ever transferred, in which case this policy continues to apply until you are told otherwise. We do not share your data with anyone else.

  • Appwrite: authentication, account, workspace, report, monitoring and quota storage. As our authentication provider it is the only processor that receives your ShopGrade password, which it verifies and stores as a salted cryptographic hash.
  • OpenAI: user-requested AI analysis of storefront audit data and, for visual analysis, screenshots.
  • Meta: optional website advertising measurement, only with your separate consent, as described above.
  • Google: optional Google sign-in, PageSpeed Insights/CrUX lookups using the store URL, and consent-based website analytics. The shopgrade.in website also loads web fonts from Google Fonts (fonts.googleapis.com and fonts.gstatic.com); your browser's IP address and request headers are received by Google to deliver the fonts. Our HTML emails reference the same font, so an email client that chooses to load it will make the same request.
  • jsDelivr (Cloudflare/Fastly CDN): the shopgrade.in website and account portal load the Appwrite JavaScript SDK from cdn.jsdelivr.net; your browser's IP address and request headers are received by the CDN to deliver the script.
  • Paddle: payment processing and subscription administration as Merchant of Record. The checkout page loads Paddle.js from Paddle's domains to run the secure checkout overlay.
  • Resend: all transactional and account email. This includes account-security messages - email-address confirmation links and password-reset links - as well as monitor alerts and team invitations. Your email address, and the single-use link, are transmitted to Resend to deliver these messages.

How we protect data

Traffic between your browser, the extension and our backend travels over HTTPS. Account credentials are handled by our authentication provider, Appwrite, which stores passwords as salted cryptographic hashes rather than in readable form. ShopGrade stores no plain-text password and writes none to its logs; the only point at which a password passes through ShopGrade's own code is the password-reset request, which holds it in memory just long enough to hand it to Appwrite. Passwords must be 10 to 256 characters, and completing a reset revokes every existing session on the account. Server-hosted reports are addressed by unguessable capability links, are refused once expired, and can be deleted immediately from your account. Access to production data is limited to the operator named above. No method of transmission or storage is completely secure, and we do not claim otherwise.

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, as the GDPR requires. Where a breach is likely to result in a high risk to you, we will inform you directly without undue delay. Where other laws that apply to you impose different obligations, we will follow those as well.

Legal bases, how long we keep your data, and international transfers

Where GDPR or similar law applies, we process account, quota, requested reports, sharing, monitoring and team features to perform our contract with you. We use legitimate interests for service security, fraud prevention, debugging and abuse controls. We rely on consent for automatic storefront analysis, optional visual AI capture, website analytics, and optional Meta advertising measurement; you may withdraw consent at any time, without affecting earlier lawful processing.

We keep account and billing records while your account is active and as needed for legal, tax, dispute and fraud-prevention obligations. Server-hosted reports are kept in your account until you delete them, and deletion is immediate and permanent. A report you make public is readable by anyone holding its link for 15 days; access is refused the moment that window closes. Reports generated before this retention change still expire 15 days after generation, and access is refused immediately at expiry even if physical cleanup is delayed. Job records holding the result of a generation are deleted as soon as the extension reads them, and in any case within one hour. Keyed per-minute hosted-report request counters are removed after two days. Monitoring delivery outbox content is removed after completion and a bounded retry/audit window (no more than 60 days). Device and keyed network anti-abuse records expire after two years without activity. Account deletion removes ShopGrade profiles, reports, monitors and their alert outbox rows, workspace data, jobs, usage meters, invitations, and your authentication record with it, including the stored hash of your password and every active session; Paddle invoices, transaction records, and limited dispute or tax records may remain where Paddle or law requires them. Direct ShopGrade account identifiers are removed from retained internal credit bookkeeping. One-way hashes of the former account and Paddle customer IDs are retained for up to two years only to reject or acknowledge delayed billing events without recreating the account. Locally stored data remains until you clear extension storage or uninstall.

Some processors, including OpenAI, Google, Meta, Paddle and Resend, may process data outside your country. Where required, transfers use recognized safeguards such as adequacy decisions or standard contractual clauses provided by the processor.

Your privacy rights

Depending on where you live, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent; and complain to your local data-protection authority. ShopGrade does not make solely automated decisions that produce legal or similarly significant effects. Email support@shopgrade.in from your account address to exercise a right.

Children

ShopGrade is a tool for people who run or work on online stores. It is not directed to children, and you must be at least 18, or the age of majority where you live, to create an account. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email support@shopgrade.in and we will delete it.

Deleting data

Use Reports in the account dashboard to permanently delete an individual report immediately; its link stops working and the action cannot be reversed. Use Delete account to permanently remove your ShopGrade account and backend service data; any active subscription is ended immediately. Email support@shopgrade.in if self-service deletion fails or to make a privacy-rights request. Clear extension storage or uninstall to remove local settings, leads and audit history. Ask an Agency workspace owner to remove shared client data, or contact us.

Chrome Web Store Limited Use disclosure

ShopGrade's collection, use and transfer of all user data, including information received from Google APIs, adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Specifically:

  • Allowed use. User data is used only to provide or improve ShopGrade's single purpose: auditing public Shopify storefronts and turning the findings into a report.
  • Allowed transfer. User data is transferred only to the processors named above, and only where necessary to provide or improve that single purpose, to comply with applicable law, or to protect against security threats, fraud or abuse. It is never sold, and it is never transferred to a data broker or an information reseller.
  • Prohibited advertising. Extension user data, including data received from Google APIs, is never used or transferred for advertising, retargeting, personalized advertising, interest-based advertising, or creditworthiness or lending purposes.
  • Prohibited human access. No human reads user data, except with your affirmative consent for a specific instance, where it is necessary for security purposes or to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.

Grievance contact

For users in India, the Digital Personal Data Protection Act, 2023 requires us to publish a contact who can answer questions about how your personal data is handled. That contact is Yuvaraj, Bangalore, India, reachable at support@shopgrade.in. Put Grievance in the subject line, and we will acknowledge and resolve it within the period the applicable law requires.

Changes and contact

We will update the date above when this policy changes and provide an in-product or email notice before material changes take effect where appropriate. Privacy questions and requests: support@shopgrade.in.

See also: Terms of Service · Refund Policy
ShopGrade logo ShopGrade

A Chrome extension that audits public Shopify storefronts for conversion, trust, SEO, performance and mobile issues, and turns the findings into a prioritized report.

Product

Add to Chrome How it works Sample report Pricing FAQ

Use cases

For agencies For brands Sign in Create account

Trust

Permissions Privacy Policy Terms of Service Refund Policy Support Cookie settings support@shopgrade.in
ShopGrade
ShopGrade is operated by Yuvaraj, an individual based in Bangalore, India. Questions: support@shopgrade.in © 2026 ShopGrade. All rights reserved. Back to top