Permissions and privacy

Designed to inspect stores, not access private business data

Chrome asks you to approve a set of permissions before ShopGrade can do anything. This page explains what each one is for, in plain language, and what ShopGrade does not do with it.

The short version

What ShopGrade can and cannot see

  • Public storefront contentVisible text, page structure, URLs, resource timing and performance signals, on pages confirmed to be Shopify storefronts.
  • Form values and passwordsNever read. Not from a store, and not from any other site.
  • Orders, customers and paymentsThese live behind the Shopify admin, which ShopGrade has no access to and never asks for.
  • Your browsing historyNot collected. ShopGrade only ever acts on the tab you explicitly run it on.
  • Network request and response bodiesNever read. Resource timing is measured, but the contents are not.
  • Any ability to change a storeShopGrade only reads. It never writes to a store, edits a theme, installs anything or submits a form.
Permission by permission

What Chrome asks you to approve

These are the exact permissions in the extension manifest, and why each one is there.

Access to sites you visit over HTTPS

This is the broadest permission ShopGrade requests, and the one worth the most scrutiny. It exists because ShopGrade cannot know in advance which addresses are Shopify stores. Any domain can be one: most stores run on their own custom domain, not on a myshopify.com address, so there is no narrower pattern that would still let the extension work on your clients' stores.

What the extension actually does with it is much narrower than what it is allowed to do. It stays dormant until you consent. It then checks whether a page is a Shopify storefront, using domain, asset and theme markers. On anything that is not one, it stops there and the popup tells you the page does not appear to use Shopify. A full audit only ever runs on the tab you explicitly click Grade this store on.

Scripting

Used to run the audit inside the storefront tab so that page structure, headings, images, links and performance timings can be measured the way a real visitor's browser experiences them. Measuring from the outside would produce a different, less honest answer.

Storage

Holds your settings, your branding and your local audit history in the browser. On an individual plan this stays on your device. On an Agency workspace, the client data you choose to sync is shared with the seats on that workspace.

Identity

Powers Sign in with Google, so you can create an account without inventing another password. It gives ShopGrade your basic profile for sign-in and nothing else.

Context menus

Adds the ShopGrade entries to the right-click menu so you can start an audit without opening the popup first.

How the report is handled

Reports are generated server-side and tied to your account, so your plan and your remaining generations survive a reinstall. A report is private to you unless you share it. Free reports are owner-only and cannot be shared at all. Every report expires automatically 15 days after generation, and you can delete one immediately from your account at any time.

A person you share a report with sees the findings, the evidence, the scores and your branding. They do not see your account, your other reports or anything else about your workspace.

Website analytics

This website loads Google Analytics only if you accept it in the banner. The extension itself does not load analytics at all. You can change your choice at any time from the cookie settings link in the footer.

Auditing stores you do not own

ShopGrade works on any publicly accessible Shopify storefront, which is what makes prospect audits possible. That capability comes with a responsibility that stays with you: you are responsible for using reports lawfully and for respecting each store's terms and rights. The full terms are in the Terms of Service.