Privacy Policy

Ghostlist · Last updated September 20, 2026

Ghostlist does not access, store or share any of your customers' personal data. The app reads your editorial content and your product catalog, nothing else.

What the app can access

The app requests three permissions, all read-only:

PermissionWhat it allows us to read
read_productsYour products' titles, IDs, status and collections
read_contentYour store's blog articles and pages
read_inventoryStock quantities and selling policy

The app requests no write permission and therefore cannot modify any data in your store. It requests no access to customers, orders, payments or shipping data.

What we store

No customer personal data is ever stored.

How long we keep it

Data is kept for as long as the app is installed. When you uninstall, your session is deleted immediately. Shopify then sends us a shop/redact erasure request 48 hours later: on receipt, all data associated with your store is permanently deleted.

You can request that erasure at any time by writing to us.

Sharing with third parties

No data is sold, rented or passed on to any third party. Our only technical subprocessors are our hosting provider (OVHcloud, France) and our database, which runs on that same infrastructure. Your data never leaves the European Union.

Your rights

Under the GDPR you have the right to access, rectify, erase, restrict and port the data concerning you. Residents of California and other jurisdictions with comparable laws have equivalent rights. To exercise them, write to us at the address below.

Security

Traffic to and from Shopify is encrypted in transit. Access tokens are stored encrypted. Every incoming webhook is verified by HMAC signature before it is processed: a request not signed by Shopify is rejected.

Contact

BFF LABZ
306 avenue Henri Deschamps
01700 Miribel, France
SIREN 988 459 707
contact@olance.fr

Changes

Any change to this policy will be published on this page with a new « last updated » date.