AppMexa supports merchant and customer data rights through Shopify's required privacy workflows and direct requests.
When an app is uninstalled
Shopify notifies the app of an uninstall. PixelHarbour deletes active sessions, app configuration, Pixel settings, encrypted Conversions API tokens and short-lived event receipts for that store. Security records containing a one-way shop reference may be retained where reasonably necessary.
Shop and customer requests
We process Shopify's mandatory customer-data, customer-redaction and shop-redaction webhooks. Customer identifiers used for Meta matching are not retained as a reusable customer profile by PixelHarbour.
Request confirmation
A store owner can ask us to confirm deletion by using the support form with the store's .myshopify.com domain. We may verify store ownership before disclosing or deleting records.
Timing
Requests are completed within the time required by Shopify and applicable law. Backup copies age out through normal encrypted-backup retention.