Privacy Policy
Last updated 18 September 2026
1. Summary
We collect the minimum needed to run App Market Gap: an account (name, email, password hash), a record of your purchase, and basic, cookieless usage statistics. We do not sell personal data and we do not run advertising trackers. Contact us at hello@appmarketgap.com.
2. What we collect and why
- Account data: your name, email address and a hashed password, so you can sign in. Legal basis: performance of our contract with you.
- Purchase data: the Stripe checkout session and payment identifiers, amount, currency and date of your purchase, and your Stripe customer id. We use these to grant and prove your access and to handle refunds. Legal basis: contract and our legal obligation to keep accounting records.
- Billing details: your billing address and, if you provide one, your VAT number are collected by Stripe during checkout to calculate tax. We receive the country and tax status but not your card number.
- Saved apps and settings: apps you save to your watchlist and preferences you set inside the Service, so the Service works the way you left it. Legal basis: contract.
- Usage statistics: aggregate page views measured with a cookieless analytics service (Plausible). It does not use cookies, does not store your IP address and cannot identify you across sites. Legal basis: our legitimate interest in understanding how the site is used.
- Technical logs: standard server logs (IP address, browser, pages requested, errors) kept for security and debugging and deleted on a rolling basis. Legal basis: legitimate interest in keeping the Service secure.
- Email: we send transactional email only: password resets, purchase confirmation, and notices about your account or material changes to the Service. We do not send marketing email without a separate opt-in.
3. Data about Shopify apps and reviews
The Service displays information about Shopify apps, including merchant reviews, that is publicly available on the Shopify App Store. Reviews may include the reviewer's store name and country as published there. We process this public information to provide market research. If you are a reviewer and want a review removed from our Service, email us and we will remove it.
4. Cookies
We use only strictly necessary cookies: a session cookie to keep you signed in, a CSRF token to protect forms, and an optional "remember me" cookie if you tick that box. Our analytics are cookieless, so we do not show a cookie banner.
5. Who we share data with
- Stripe processes payments. Their handling of your data is covered by Stripe's privacy policy.
- Hosting and email providers store our database and deliver transactional email on our behalf under data-processing agreements.
- Error monitoring (Sentry) receives error reports that may include your user id and the page that failed, so we can fix bugs.
- AI provider: review text from the public App Store is sent to an AI API to generate summaries. No account data of yours is included.
We disclose personal data to authorities only where the law requires it.
6. International transfers
Some of the providers above are located outside your country, including in the United States. Where personal data leaves the EEA or UK we rely on standard contractual clauses or an adequacy decision.
7. Retention
Account data is kept while your account exists. Purchase records are kept for as long as tax and accounting law requires (typically 7 to 10 years). Server logs are deleted within 30 days. If you delete your account we remove your personal data within 30 days, except purchase records we are legally required to keep.
8. Your rights
Depending on where you live you may have the right to access, correct, export or delete your personal data, to restrict or object to its processing, and to complain to your data protection authority. To exercise any of these rights, or to delete your account, email hello@appmarketgap.com from the address on your account. We respond within 30 days.
9. Security
Passwords are stored hashed, connections are encrypted with TLS, and access to production systems is restricted. No system is perfectly secure; if we learn of a breach affecting your data we will notify you as the law requires.
10. Changes
We will post any changes to this policy here and update the date at the top. Material changes will also be announced by email.