Privacy Policy
A1 Image Gallery collects the minimum merchant data needed to operate the app and does not collect shopper data from storefront galleries.
Last updated: 20 July 2026
1. Who we are
A1 Image Gallery is published by A1 Local, an Australian sole trader operated by Bob Jones in Western Australia. The data controller can be reached at extensions@a1local.com.au.
2. Data stored in Shopify
Gallery images are stored in your Shopify Files library. Gallery configuration, including layout, captions, links, and image order, is stored in shop.metafields.a1_gallery.galleries. You retain ownership of this data, and it remains in your Shopify account after uninstall unless you remove it.
3. Merchant data we process
- Shop domain, shop name, merchant contact email supplied by Shopify, install timestamps, plan, billing status, granted scopes, expiring Shopify OAuth access token, refresh token, and token expiry timestamps.
- Gallery configuration backups used for version history and restore.
- Feature usage events keyed by shop, such as galleries saved or images uploaded.
- Cozy migration job state, scan results, errors, and completion details.
- Support correspondence you choose to send by email.
OAuth state values expire after 10 minutes. Cached Cozy scan state is deleted when the app is uninstalled.
4. Data we do not collect
The storefront extension does not call A1 Local servers, set A1 Local cookies, or send shopper events to us. We do not collect shopper names, emails, IP addresses, orders, customer records, payment card details, browser fingerprints, or device identifiers.
5. How we use merchant data
We use merchant data to authenticate Shopify API requests, operate the gallery editor, save and restore galleries, process Shopify Billing, run merchant-requested migrations, provide support, enforce plan limits, secure the service, and understand aggregate feature usage. We do not sell personal information, use it for targeted advertising, or train AI models with it.
6. Service providers
- Shopify provides the commerce platform, Admin API, Files, metafields, theme extension delivery, and billing.
- Cloudflare provides Worker hosting, D1 database storage, KV storage, and network security.
- Google Workspace processes support email sent to our published support address.
7. Retention and deletion
We retain merchant app data while the app is installed. On app/uninstalled, the OAuth token is immediately cleared and billing access is disabled. When Shopify sends shop/redact, normally 48 hours after uninstall, we delete all database and KV records keyed by the shop. Service backups may retain deleted records until their normal rotation completes. Verified earlier-deletion requests are handled within five business days where practical.
8. Shopify privacy webhooks
Because we hold no storefront customer data, customers/data_request and customers/redact are acknowledged without storing their payloads. shop/redact triggers the full merchant-data purge described above.
9. Your rights
Depending on your location, you may request access, correction, deletion, portability, restriction, or objection. Email extensions@a1local.com.au. We may verify shop ownership before acting and aim to respond within 30 days.
10. Security and international processing
Traffic is encrypted with HTTPS, Shopify webhooks are HMAC-verified, and expiring OAuth access and refresh tokens are available only to the Worker service. Shopify, Cloudflare, and Google may process data in countries where they operate. Their contractual and data residency terms apply.
11. Changes and governing law
Material changes will be notified through available merchant contact channels before they take effect. This policy is governed by the laws of Western Australia, subject to any non-excludable rights under applicable privacy law.
Contact
A1 Local, Bob Jones
Western Australia
extensions@a1local.com.au