Privacy Policy

Run-Done Design (Shopify app). Last updated: 1 September 2026.

Summary

This app builds landing pages for products in your Shopify store. It reads your product data and stores the pages it generates. It does not collect, store, or process personal data about your customers.

What we store

Store identity

Your myshopify.com domain and the OAuth access token issued when you install the app. The token is used only to read products and, with your permission, to create a product you import by link.

Product data

Title, description, price and image URLs of the products you pick for a landing page. This data comes from the Shopify Admin API and stays tied to your store.

Content you create

The brief you type, the generated page text, the accent colour, the chosen layout, and the chat edits you request. Voice input, if you use it, is transcribed to text and the audio is discarded.

Operational records

Webhook payloads Shopify sends us (installation, uninstall, subscription status, privacy topics), page view and click counters, and the number of tokens each generation spent.

What we do not store

Customer data

The app requests no access to orders, checkouts or customer records. It never receives names, emails, addresses or payment details of your buyers.

Payment details

Subscriptions are billed by Shopify through its Billing API. We never see card numbers or bank details.

How the data is used

Generating pages

Product text and your brief are sent to a large language model to write the page copy. Today that is either DeepSeek (api.deepseek.com) or a model we host ourselves; the request carries product and brief text only, never store credentials.

Serving pages

Published pages are delivered through the Shopify App Proxy under your own domain, so visitors never contact our servers directly with their identity.

No advertising

We do not sell data, do not share it with advertisers, and do not use it to train models.

Storage, retention and deletion

Where it lives

Data is kept in an SQLite database on servers we operate in the European Union, reachable only over TLS.

Uninstall

When you uninstall the app, Shopify sends an app/uninstalled webhook, we mark the store inactive and the access token stops working. Store data is erased within 30 days of uninstall.

GDPR requests

The mandatory customers/data_request, customers/redact and shop/redact topics are implemented. Because no buyer data is stored, a data request returns nothing to hand over, and redaction removes the shop record we hold.

Ask us directly

Write to support@run-done.com to get a copy of your data or to have it deleted sooner. We reply within 30 days.

Common questions

Does the app read my customer list?

No. The app asks for read_products only (and write_products in the custom build, so it can create a product you import by link). Customer and order scopes are not requested.

Is my product text sent to a third party?

Yes, to the language model that writes the page. The request contains the product card and your brief. Nothing else about your store is included.

Do landing pages set cookies for visitors?

No. A generated page is static HTML and CSS with no tracking scripts. Only the admin panel uses a session cookie, and only for you.

Who do I contact about privacy?

support@run-done.com — the same address as app support.

Changes

Updates to this policy

If the app starts collecting something new, this page changes first and the date at the top moves with it. Material changes are announced inside the app.