Skip to content
Colin
HomePrivacy PolicyTerms of ServiceHire Colin ↗

Colin for Shopify

Privacy Policy

How Colin collects, uses, stores, and protects information for Shopify merchants.

Privacy Policy

Last updated: August 29, 2026

This Privacy Policy explains how Colin: Collection Intelligence ("Colin", "we", "our", or "us") collects, uses, stores, and discloses information when a Shopify merchant installs or uses Colin. Colin is operated by Rami Apps.

This document describes our current data practices. It is provided for transparency and should be reviewed with qualified legal counsel for the laws that apply to your business and location.

Information Colin processes

Shopify shop and account information

When a merchant installs or opens Colin, Shopify provides information needed to authenticate the app and identify the shop. This can include the shop domain, shop name, Shopify shop identifier, timezone, plan information, installation state, and the name, email address, locale, and account role of an authenticated Shopify staff user.

Colin stores Shopify access and refresh tokens so authorized background work can continue. These credentials are used only to provide Colin and communicate with Shopify on the merchant's behalf.

Catalog, collection, and merchandising information

Colin processes product and collection information needed for collection merchandising. Depending on the features a merchant uses, this can include product identifiers, titles, handles, vendor, product type, category, tags, images, SKU, price, cost, inventory, publication and stock status, selected product metafields, collection membership, product positions, collection conditions, titles, and sort settings.

Colin also stores merchant-created configuration such as Campaigns and Schedules, Colin conditions, Advanced Sort strategies, Catalog presets, Shareable Lists, notification preferences, sync schedules, and onboarding progress.

Order-line and sales information

Colin reads order information to calculate product-level merchandising signals such as units sold, revenue, gross profit, and sales trends. The local order-line records used for these calculations can include Shopify order and line-item identifiers, product and variant identifiers, order status, quantity, price, discounts, and order timestamps.

Colin does not intentionally store customer names, customer email addresses, shipping addresses, billing addresses, or payment-card details in its local sales dataset.

Optional Google Analytics information

If a merchant connects Google Analytics 4, Colin stores encrypted OAuth credentials, the properties available to the connected account, the property selected by the merchant, connection diagnostics, and the time of the last successful import. Colin imports aggregated product-page view totals for supported Shopify product paths and associates those totals with products in the merchant's catalog.

Colin does not use this connection to create advertising audiences or collect visitor profiles.

Agent and assistant access

Merchants can create named Agent Access tokens to connect Colin to compatible assistants such as ChatGPT or Claude. Colin stores a cryptographic hash and short prefix of each token, its name, status, and recent-use metadata. Plaintext tokens are shown only when created and are not stored for later display.

When an assistant requests a supported write, Colin can temporarily store the proposed payload and a human-readable preview so the merchant can review the exact change before it is applied. Shopify Sidekick access is separate, Shopify-authenticated, and read-only.

Communications and operational records

If a merchant enables notifications or contacts us, Colin can store shop and notification email addresses, message preferences, sent-message records, and delivery errors. Colin also keeps operational information such as sync state, execution history, job identifiers, product and collection counts, errors, API-access diagnostics, and timestamps needed to run, secure, troubleshoot, and improve the service.

Public website information

The public Colin website does not use visitor analytics or advertising trackers in its initial release. Standard web-server and hosting logs can still record technical information such as IP address, request time, browser details, requested URL, and error information for security and reliability.

How we use information

We process information to:

  • authenticate merchants and maintain the Shopify app connection;
  • synchronize catalog, collection, inventory, order-line, sales, and optional analytics data;
  • calculate collection membership and product ordering from merchant-configured rules;
  • run Campaigns, Schedules, syncs, notifications, and requested Agent actions;
  • display plan status and enforce product limits verified through Shopify;
  • provide support, diagnose failures, prevent abuse, and protect the service;
  • comply with legal obligations and Shopify's platform requirements.

We do not sell merchant or customer information. We do not use merchant data to train a general-purpose artificial intelligence model.

Service providers and disclosures

We use service providers where necessary to operate Colin. Depending on the merchant's configuration, these can include Shopify for app authentication, APIs, and billing; hosting, database, queue, and infrastructure providers; Resend or a configured SMTP provider for email; Google for an optional Analytics connection; and compatible assistant platforms chosen by the merchant for Agent access.

These providers process information under their own terms and privacy policies. We can also disclose information when required by law, to protect rights or security, during a business reorganization, or with the merchant's direction or consent.

Retention and deletion

We retain information while a shop uses Colin and for as long as reasonably necessary to provide the service, resolve disputes, maintain security, and meet legal obligations.

When Shopify tells us that an app was uninstalled, Colin removes the shop record and app-owned operational data, including sessions, Campaigns, collection configuration, local catalog and sales cache, Agent tokens and previews, Google Analytics credentials, notifications, and related sync state. Limited email-delivery records and records required for legal, security, fraud-prevention, backup, or accounting purposes can be retained for the period reasonably required for those purposes.

Shopify privacy webhooks are available for customer data requests, customer redaction, and shop redaction. Colin does not intentionally store customer profile fields in its local sales dataset, but we still respond to the mandatory Shopify privacy process.

Security

We use administrative, technical, and organizational safeguards appropriate to the information we process. These include encrypted network connections, Shopify authentication, restricted access, hashed Agent tokens, encryption for Google OAuth credentials, and separation of merchant data by shop. No method of transmission or storage can be guaranteed completely secure.

International processing

Colin and its service providers can process information in countries other than the merchant's own. Those countries can have different data-protection laws. Where required, merchants should evaluate whether additional contractual or legal safeguards apply to their use of the service.

Merchant and individual rights

Depending on location, a merchant or individual can have rights to request access, correction, deletion, restriction, portability, or information about how personal data is processed. Requests can be sent to the address below. We can ask for information needed to verify the request and can direct requests involving Shopify-controlled information to Shopify or the relevant merchant.

Changes to this policy

We can update this Privacy Policy when Colin, our providers, or applicable requirements change. We will update the date at the top and provide additional notice when required.

Contact

Questions or privacy requests can be sent to colin@ramiapps.com.

Colin

Your strategy. Colin's tools. Predictable execution.

Legal

Privacy PolicyTerms of Service

For AI

llms.txtFull site guide

Get Colin

Hire Colin on Shopify ↗colin@ramiapps.com
© 2026 Rami AppsBuilt for Shopify collection merchandising.