1. Who we are
GMC Guardian (the "Service") is operated under United States jurisdiction. References to "we", "our", "us" mean GMC Guardian acting as the data controller. Full corporate identification of the operating entity is available on written request to [email protected]. MerchantRescue is the sister consulting agency - same ownership, distinct legal entity.
2. What we collect
When you install GMC Guardian on your Shopify store or use this website, we process the following categories of personal data:
- Account data: shop owner email, shop owner name, country, currency, time zone - provided by Shopify when you install the app.
- Authentication tokens: encrypted Shopify access tokens and Google Merchant Center OAuth tokens, used to perform the actions you've requested. Stored encrypted at rest using libsodium AEAD.
- Scan metadata: results of compliance scans you trigger, including findings, audit logs, and timestamps.
- Lead capture: if you submit our newsletter form, your email address, the source of submission, the locale, your IP address, and your user agent.
- Usage data: standard server logs (IP, request paths, user agent, timestamps) retained 30 days for security and debugging.
We do not collect personal data of your end customers (the shoppers buying from your store). The product operates on merchant-side metadata only.
3. Why we process it
The legal bases for processing under GDPR Article 6:
- Contract performance (6.1.b): account data and tokens, used to deliver the service you've subscribed to.
- Legitimate interest (6.1.f): server logs, analytics, fraud and abuse prevention.
- Consent (6.1.a): newsletter subscription. Withdrawable any time via the unsubscribe link in every newsletter.
4. Who we share it with
We use the following sub-processors (full list maintained at /trust):
- Infomaniak (Switzerland) - application hosting and database
- Cloudflare R2 (EU + global CDN) - blob storage for PDFs and reports
- Postmark (US, EU+US DPA) - transactional email and newsletter delivery
- Anthropic (US) - AI models for feed rewrites and concise narratives
- Google (US + global) - Merchant API and Google Ads API integrations on your behalf
We do not sell, rent, or trade personal data. The current list is published on the Trust & security page and is updated before a new sub-processor begins processing.
5. How long we keep it
| Data category | Retention |
|---|---|
| Account data while account is active | Until uninstall + 48 hours grace |
| Encrypted access tokens | Deleted on uninstall + 48 hours grace |
| Scan archives - Free | 90 days |
| Scan archives - Paid plans | 1 year |
| Scan archives - Agency Plus | 3 years |
| Audit log entries | 3 years (compliance retention) |
| Newsletter subscription | Until unsubscribed; logs retained 90 days after |
| Server logs | 30 days |
6. Your rights
Under GDPR you have the right to access, rectify, erase, restrict, port, and object to processing of your personal data. To exercise any of these rights, email [email protected]. We respond within 30 days, often faster.
For Shopify-installed merchants, the GDPR customers/data_request, customers/redact, and shop/redact webhooks are implemented and tested. Triggering these from your Shopify admin produces the same effect as a direct request.
You also have the right to lodge a complaint with your national supervisory authority - the CNIL (France), the ICO (UK), the data protection authority of your EU member state, or the Federal Trade Commission and your State Attorney General if you are a US resident. California residents have additional rights under the CCPA/CPRA: right to know, delete, correct, opt-out of sale (we don't sell), and limit use of sensitive personal information. Email [email protected] to exercise any CCPA right.
7. International transfers
The operating entity is US-based. Hosting infrastructure is primarily Switzerland (Infomaniak) and the EU. For users in the EEA, UK, or Switzerland whose personal data is transferred to the US (operating entity, Postmark, Anthropic, Google), transfers occur under Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework. We've concluded SCCs with each US-based sub-processor.
8. Security
All authentication tokens are encrypted at rest. TLS 1.3 in transit. Append-only audit log. No customer (shopper) PII stored. SOC 2 Type II is on our roadmap; we are not audited yet.
9. Changes
Material changes to this Privacy Policy are posted on this page with a new effective date before they take effect.
10. Contact
For privacy questions, please email [email protected]. For other inquiries, see our contact page.