Privacy
Dash is a Shopify app that lets your AI assistant write landing pages for your store. This page describes exactly what it stores, why, where it runs, how long things are kept, and how to have them deleted.
Who we are
Dash is operated by the publisher of the Dash app on the Shopify App Store. For anything in this policy — questions, access requests, deletion requests, complaints — write to support@dash-mcp.com. We answer data requests from this address.
For the data described below, the merchant who installs Dash is generally the controller and Dash acts as a processor on their behalf under the Shopify Partner Program terms. Where Dash decides on its own account — for example, keeping an audit record of the mandatory Shopify privacy webhooks — it acts as a controller.
What Dash stores
Dash keeps as little as it can and still work. Everything it holds falls into one of these categories.
Your store
- Your
myshopify.comdomain and your Shopify shop ID. - When Dash was installed, and when it was uninstalled.
Access to your store
-
The access token Shopify issues so Dash can act on your store, its expiry, and the
permissions it covers. The token is issued for two permissions only:
write_files(upload images and other assets to your Shopify Files) andwrite_app_proxy(serve pages on your own storefront domain).
Who may drive the AI connection
- The email address Shopify verifies for the staff account that opens the AI connection screen, and the Shopify staff user ID that goes with it. This is what a connection is keyed to, and it is how Dash decides which stores a given connection may reach.
- A secret connection token — the URL you paste into your assistant — with the times it was created and last used.
- For each store a connection reaches: when access was first observed, when it was last confirmed, when it was last used, and when it was revoked, if it was.
Your landing pages
- Page title, URL handle, locale, SEO title and description, status, theme header and footer setting, and any scheduled publish or unpublish times.
- The full content of every version, as Liquid, together with its version number, size, checksum, validation result, a note, whether it was written by your assistant or by hand, and when it was created. Version history is append-only: earlier versions are kept until you delete the page.
- For uploaded assets: the filename, media type, size and the resulting Shopify CDN URL. The files themselves are stored in your own Shopify Files, not by Dash, which is why they stay visible in your admin and survive uninstalling the app.
Compliance records
-
Shopify requires apps to handle three privacy webhooks —
customers/data_request,customers/redactandshop/redact. Dash records each one it receives, with the payload Shopify sent, so there is an auditable trail that it was handled. Dash holds no customer records of its own, so these requests are logged and answered rather than acted on.
What Dash never stores
- Customer records. No names, addresses, emails or accounts of your shoppers. Dash does not request the permission that would let it read them.
- Orders, carts, payments or payouts. Same reason.
- Product or inventory data, beyond whatever you asked your assistant to put into a page.
- Shopper analytics or behavioural profiles. Dash does not track visitors to the pages it serves; your theme's own analytics keep working exactly as they did.
This website
dash-mcp.com sets no cookies and runs no analytics. There are no tracking pixels, no advertising tags and no third-party scripts. Fonts are served from this domain rather than from a font CDN, so loading this page does not disclose your visit to anyone else.
Our hosting provider processes standard server request data (IP address, time, requested URL, user agent) to deliver the page and to defend against attacks. It is not combined with anything else and not used to build a profile.
The Dash admin inside your Shopify store does not use cookie-based sessions either — it authenticates each request with a token Shopify issues on the spot.
Where it is processed
Dash runs on Cloudflare's global network. Structured data (the records listed above) lives in Cloudflare D1, and the Liquid content of page versions lives in Cloudflare R2. Data may therefore be processed outside the European Economic Area. Transfers rely on the Standard Contractual Clauses in Cloudflare's data processing addendum.
Sub-processors
- Shopify — your store platform. It issues the access tokens, hosts the files your assistant uploads, and renders published pages through its app proxy.
- Cloudflare — hosting, database and object storage for the app and for this website.
Dash does not sell data, does not share it for advertising, and adds no other sub-processor without updating this page first.
Your AI assistant
When you connect an assistant — Claude, ChatGPT, Cursor, or anything else that speaks MCP — that assistant is operated by its own vendor under its own privacy policy and terms. Dash has no control over it. Anything you type into it, and anything it reads back from your store through Dash, is handled by that vendor.
Treat the connection URL as a password: anyone holding it can act on the stores it covers. You can regenerate it from the AI connection screen at any time, which immediately breaks every client configured with the old one.
Preview links
A preview link renders one version of a page inside your live theme without publishing
it. The link carries a signed ticket rather than a login, so
anyone who has the link can open it — that is what makes it shareable
with someone who has no Shopify account. Preview responses are never cached and are
marked noindex so search engines skip them, and the ticket stops working 24
hours after it is issued. Tickets cannot be revoked individually before then; if a link
has gone somewhere it shouldn't, unpublishing or deleting the page removes what it
points at.
How long it is kept
- Access tokens and sessions — until they expire, are replaced, or you uninstall the app.
- Landing pages and their version history — until you delete the page. Deleting a page removes every version and its stored content permanently, and cannot be undone.
- Connection memberships — a staff account's access to a store expires 90 days after it was last confirmed. Shopify sends no notification when someone loses access to a store, so the grant lapses on its own rather than waiting to be revoked.
- Revocations — when you revoke an account, Dash records the revocation rather than deleting the row, so that a later visit cannot silently re-grant access.
- Compliance records — kept as an audit trail for as long as we are required to demonstrate that privacy requests were handled.
-
Uninstalling — ends Dash's access to your store immediately. Write to
support@dash-mcp.com to have the remaining
records erased, or wait for Shopify's
shop/redactrequest, which arrives 48 hours after uninstall.
Pages you publish
Dash renders the page you publish and nothing more. If a page you publish collects personal data from shoppers — a signup form, an embedded third-party widget, a tracking script your assistant added at your request — then you are the controller for that collection, and your own store privacy policy has to cover it. Dash neither adds nor removes anything of that kind on its own.
Your rights
If you are in the EU or UK, the GDPR gives you the right to access the personal data held about you, to have it corrected or erased, to restrict or object to its processing, and to receive it in a portable form. Write to support@dash-mcp.com and we will respond within 30 days.
If you are a shopper rather than a merchant, note that Dash holds no data about you — requests about a specific store's customers should go to that store, which can pass them to us through Shopify's built-in data request flow.
You also have the right to complain to a supervisory authority in the country where you live or work.
Security
- All traffic is served over TLS.
- Shopify access tokens are requested with an expiry rather than indefinitely, and are refreshed as needed.
- Incoming webhooks are verified by HMAC signature before they are read, and requests from the Shopify admin are verified as signed session tokens.
- Connection tokens are secret, per account, revocable and rotatable. Preview tickets are signed and short-lived.
- Access to a store is checked on every call and re-confirmed periodically rather than granted once.
No system is perfect. If you find a security problem, please report it to support@dash-mcp.com before disclosing it publicly.
Changes
When this policy changes, the date at the top of the page changes with it. Changes that materially affect what is collected or who processes it are announced in the app before they take effect.
