Privacy Policy
Last updated: 20 September 2026
Understory Threat Intelligence ("Threat Intelligence") helps Shopify merchants monitor their published theme for suspicious code and unexpected changes.
We have designed the app to collect as little information as possible. This policy explains what the app can access, what information we keep, why we keep it, and how it can be deleted.
What the app can access
Threat Intelligence requests one Shopify permission: read_themes
This allows the app to read the files that make up your Shopify themes so that it can scan them for suspicious code, external connections and unexpected changes.
The app cannot use this permission to modify, delete, overwrite or publish your theme files.
Threat Intelligence does not request access to your customers, orders, products, payments or checkout information.
Because theme files are created and controlled by merchants and third party apps, they could occasionally contain information that has been manually added to the theme. Threat Intelligence only processes this information as part of the theme scan and does not intentionally collect customer information.
What we store
To operate the service, Threat Intelligence may store:
- Your store's
myshopify.comdomain - Shopify credentials issued to the app
- Theme names and theme identifiers
- Theme file names, file sizes and content types
- File checksums or fingerprints used to detect changes
- Security findings generated during a scan
- A short section of code associated with a security finding
- The severity and location of a finding
- External domains referenced by your theme
- Domains you have marked as trusted
- Scan history
- Detected theme changes
We do not retain complete copies of your theme files. Theme files are read while a scan is running and are then discarded. We retain only the information needed to detect changes and explain security findings, such as file metadata, checksums and short code excerpts associated with a finding.
Email alerts
Email alerting is not enabled in the current version of the app. The app does not ask you for an email address and does not send email.
If email alerting is enabled in a future version, the app would store the alert address you choose to provide and a record of the alerts sent to it. Alerts would only ever be sent to the address you configure, and this policy would be updated before that happens.
Why we process this information
We use this information only to provide the Threat Intelligence service, including:
- Scanning Shopify themes
- Detecting suspicious code
- Identifying unexpected theme changes
- Identifying external domains used by a theme
- Showing previous scans and findings
- Maintaining the security and reliability of the app
We do not use merchant or theme information for advertising. We do not sell merchant information. We do not use merchant information or theme code to train machine learning models.
Sharing information
Security findings and theme information are not sold or shared for advertising purposes.
Information may be processed by service providers that are necessary to operate the app, such as hosting, database and infrastructure providers. These providers are only permitted to process information as needed to provide those services.
Security
Application data is stored in the app's database and is available only to the systems and people who need access to operate and support the service.
Shopify access credentials are stored securely and are not stored in the application database as plain text.
We use reasonable technical and organisational safeguards intended to protect information against unauthorised access, loss or misuse. No internet service can guarantee absolute security.
Data retention
We retain information only for as long as it is needed to operate the service or meet legal and security requirements.
When a merchant uninstalls Threat Intelligence, the app's access to the Shopify store is revoked and scanning stops. We then delete the remaining information associated with the store in accordance with Shopify's required data deletion process. This includes, where applicable:
- Store settings
- Theme information
- File checksums
- Scan history
- Findings
- Trusted domains
- Alert settings and alert history, if email alerting has been enabled
A merchant can also ask us to delete their information at any time.
Your choices
Merchants may contact us to:
- Ask what information we hold about their store
- Correct inaccurate information
- Request deletion of their information
- Ask questions about how their information is used
Depending on where you are located, you may also have additional privacy rights under applicable law.
Changes to this policy
We may update this Privacy Policy when the app, our infrastructure or applicable requirements change. When we make changes, we will update the date shown at the top of this page.
Contact
For privacy questions, access requests or deletion requests, contact support.understory@gmail.com.