Privacy Policy
Last updated: April 20, 2026
Introduction
AltShot ("we", "our", or "us") operates the AltShot application for Shopify. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you install and use our app.
Information We Collect
When you install and use AltShot, we collect the following information from your Shopify store:
- Shop domain — your Shopify store URL, used to identify your account
- Product data — product titles, images, and tags, used to generate AI alt text and optimize images
- Usage metrics — how many images you scan, optimize, and compress, used to track plan limits
We do NOT collect customer personally identifiable information (PII). We do not access your customers' names, emails, addresses, or payment details.
How We Use Your Information
We use the information we collect to:
- Generate AI-powered alt text for your product images
- Compress and optimize your product images
- Score and report on your store's image SEO health
- Track usage against your plan limits (free or paid tier)
- Improve and maintain the AltShot service
Third-Party Services
We use the following third-party services to operate AltShot:
- Google Gemini API— product images are sent to Google's Gemini API for AI analysis and alt text generation. Google's privacy policy applies to their processing of this data.
- DigitalOcean — our application infrastructure is hosted on DigitalOcean.
- Shopify— AltShot operates as a Shopify embedded app and communicates with Shopify's APIs to access and update your store data.
Shopify Data Access
AltShot only accesses data permitted by the OAuth scopes you grant during installation. We request the minimum scopes necessary to provide our service. You can review the permissions granted to AltShot in your Shopify admin under Settings → Apps and sales channels.
Data Retention
We retain your store data for as long as the app is installed. When you uninstall AltShot, all associated shop data is deleted from our systems within 30 days.
GDPR Compliance
AltShot complies with GDPR requirements and handles Shopify mandatory privacy webhooks:
- customers/data_request — we respond to requests for customer data. Since we do not store customer PII, these responses confirm no data is held.
- customers/redact — we process customer data deletion requests. Since we do not store customer PII, no action is required beyond acknowledgment.
- shop/redact — when a shop uninstalls our app and the erasure period elapses, we delete all shop-related data.
Cookies
AltShot does not use cookies. Authentication is handled entirely through Shopify session tokens, which are managed by the Shopify platform.
Data Security
We take the security of your data seriously and implement the following measures:
- All data is encrypted in transit using TLS
- Data is encrypted at rest on our servers
- Access to your data is limited to authorized systems only
- We regularly review and update our security practices
California Residents (CCPA)
If you are a California resident, please note that we do not sell personal information. We collect and use information solely to provide and improve the AltShot service as described in this policy.
Children's Privacy
AltShot is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13, we will take steps to delete it promptly.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes, we will notify you via the AltShot app dashboard and update the "Last updated" date at the top of this page. We encourage you to review this policy periodically.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at [email protected].