Privacy Policy

Last updated: 20 September 2026

Understory Threat Intelligence ("Threat Intelligence") helps Shopify merchants monitor their published theme for suspicious code and unexpected changes.

We have designed the app to collect as little information as possible. This policy explains what the app can access, what information we keep, why we keep it, and how it can be deleted.

What the app can access

Threat Intelligence requests one Shopify permission: read_themes

This allows the app to read the files that make up your Shopify themes so that it can scan them for suspicious code, external connections and unexpected changes.

The app cannot use this permission to modify, delete, overwrite or publish your theme files.

Threat Intelligence does not request access to your customers, orders, products, payments or checkout information.

Because theme files are created and controlled by merchants and third party apps, they could occasionally contain information that has been manually added to the theme. Threat Intelligence only processes this information as part of the theme scan and does not intentionally collect customer information.

What we store

To operate the service, Threat Intelligence may store:

We do not retain complete copies of your theme files. Theme files are read while a scan is running and are then discarded. We retain only the information needed to detect changes and explain security findings, such as file metadata, checksums and short code excerpts associated with a finding.

Email alerts

Email alerting is not enabled in the current version of the app. The app does not ask you for an email address and does not send email.

If email alerting is enabled in a future version, the app would store the alert address you choose to provide and a record of the alerts sent to it. Alerts would only ever be sent to the address you configure, and this policy would be updated before that happens.

Why we process this information

We use this information only to provide the Threat Intelligence service, including:

We do not use merchant or theme information for advertising. We do not sell merchant information. We do not use merchant information or theme code to train machine learning models.

Sharing information

Security findings and theme information are not sold or shared for advertising purposes.

Information may be processed by service providers that are necessary to operate the app, such as hosting, database and infrastructure providers. These providers are only permitted to process information as needed to provide those services.

Security

Application data is stored in the app's database and is available only to the systems and people who need access to operate and support the service.

Shopify access credentials are stored securely and are not stored in the application database as plain text.

We use reasonable technical and organisational safeguards intended to protect information against unauthorised access, loss or misuse. No internet service can guarantee absolute security.

Data retention

We retain information only for as long as it is needed to operate the service or meet legal and security requirements.

When a merchant uninstalls Threat Intelligence, the app's access to the Shopify store is revoked and scanning stops. We then delete the remaining information associated with the store in accordance with Shopify's required data deletion process. This includes, where applicable:

A merchant can also ask us to delete their information at any time.

Your choices

Merchants may contact us to:

Depending on where you are located, you may also have additional privacy rights under applicable law.

Changes to this policy

We may update this Privacy Policy when the app, our infrastructure or applicable requirements change. When we make changes, we will update the date shown at the top of this page.

Contact

For privacy questions, access requests or deletion requests, contact support.understory@gmail.com.