A1 Image Gallery

Privacy Policy

A1 Image Gallery collects the minimum merchant data needed to operate the app and does not collect shopper data from storefront galleries.

Last updated: 20 July 2026

1. Who we are

A1 Image Gallery is published by A1 Local, an Australian sole trader operated by Bob Jones in Western Australia. The data controller can be reached at extensions@a1local.com.au.

2. Data stored in Shopify

Gallery images are stored in your Shopify Files library. Gallery configuration, including layout, captions, links, and image order, is stored in shop.metafields.a1_gallery.galleries. You retain ownership of this data, and it remains in your Shopify account after uninstall unless you remove it.

3. Merchant data we process

OAuth state values expire after 10 minutes. Cached Cozy scan state is deleted when the app is uninstalled.

4. Data we do not collect

The storefront extension does not call A1 Local servers, set A1 Local cookies, or send shopper events to us. We do not collect shopper names, emails, IP addresses, orders, customer records, payment card details, browser fingerprints, or device identifiers.

5. How we use merchant data

We use merchant data to authenticate Shopify API requests, operate the gallery editor, save and restore galleries, process Shopify Billing, run merchant-requested migrations, provide support, enforce plan limits, secure the service, and understand aggregate feature usage. We do not sell personal information, use it for targeted advertising, or train AI models with it.

6. Service providers

7. Retention and deletion

We retain merchant app data while the app is installed. On app/uninstalled, the OAuth token is immediately cleared and billing access is disabled. When Shopify sends shop/redact, normally 48 hours after uninstall, we delete all database and KV records keyed by the shop. Service backups may retain deleted records until their normal rotation completes. Verified earlier-deletion requests are handled within five business days where practical.

8. Shopify privacy webhooks

Because we hold no storefront customer data, customers/data_request and customers/redact are acknowledged without storing their payloads. shop/redact triggers the full merchant-data purge described above.

9. Your rights

Depending on your location, you may request access, correction, deletion, portability, restriction, or objection. Email extensions@a1local.com.au. We may verify shop ownership before acting and aim to respond within 30 days.

10. Security and international processing

Traffic is encrypted with HTTPS, Shopify webhooks are HMAC-verified, and expiring OAuth access and refresh tokens are available only to the Worker service. Shopify, Cloudflare, and Google may process data in countries where they operate. Their contractual and data residency terms apply.

11. Changes and governing law

Material changes will be notified through available merchant contact channels before they take effect. This policy is governed by the laws of Western Australia, subject to any non-excludable rights under applicable privacy law.

Contact

A1 Local, Bob Jones
Western Australia
extensions@a1local.com.au