Combined Listings — Privacy Policy
Last updated: September 28, 2026
This Privacy Policy explains what information the Solora: Combined Listings app (“Combined Listings”, by Solora Commerce) processes when you install it on your Shopify store, and how we protect it. By installing Combined Listings you agree to this policy.
1. Information we process
- Store information — your
.myshopify.comdomain, store name, contact email, currency, timezone, country, primary storefront domain, and Shopify plan, all provided by Shopify. - App configuration — the groups you create (title, option name, and for each member product its ID, handle, option value and swatch colour or image), your auto-group rules, your variant-to-image mappings, your swatch appearance, and your card-per-variant settings.
- CSV imports — when you import a CSV file, its contents are processed to create groups and are not stored. We keep only a summary of each import: how many rows succeeded and the line numbers and messages of the rows that failed.
- Authentication tokens — a Shopify access token used to call the Shopify API on your behalf. It is encrypted at rest. Combined Listings uses store-level (offline) tokens only, so a session identifies your store, not a person.
- A storefront token — to show stock and prices on swatches, the app creates a Shopify Storefront API token named
solora-cl. It can read only what your storefront already shows to every visitor (product availability and prices). We store it in our database and in your store’ssolora_cl.settingsmetafield, which your storefront can read. - Feature requests — if you post to the Roadmap board inside the app, we store the title and description you write and which stores voted. Requests we approve are shown to other Combined Listings merchants with your store name attached, so please do not post anything confidential.
2. What we do NOT collect
Combined Listings requests access to products only. It cannot read orders, customers, or checkouts, and stores no customer names, emails, phone numbers, or addresses.
What the app writes into your store is limited to three metafields in the solora_cl namespace — group and variant_images on the products you group or map, and settings on your shop — plus the storefront token above and whichever Combined Listings blocks you turn on in your theme. These metafields are readable by your storefront, which is how swatches render. They are ordinary metafields: you can see, edit, or delete them under Settings → Custom data.
3. How we use information
- To provide the app’s functionality — showing swatches, combined listings and variant images on your storefront.
- To run the in-app Roadmap board and decide what to build next.
- To operate, maintain, secure, and support the service.
We do not sell your data or use it for advertising.
4. Sharing & sub-processors
We share data only with providers strictly necessary to run the service, and never for their own purposes:
- Shopify — the platform the app runs on.
- Hugging Face — application and database hosting.
- Object storage (S3-compatible) — holds our automated database backups, uploaded over HTTPS to a private bucket. Access tokens remain encrypted inside those backups.
- Upstash— runs background jobs such as CSV imports, when enabled. An import’s CSV contents pass through it while the job is queued.
- Sentry — error monitoring, when configured. Reports carry technical context and, for some errors, your store domain — never customer data.
5. Protected customer data & GDPR
We honor Shopify’s mandatory compliance webhooks:
customers/data_request— acknowledged; we hold no customer data to return.customers/redact— acknowledged; no customer data is stored, so there is nothing to erase.shop/redact— your store’s data is deleted (see below).
6. Data retention & deletion
We keep your configuration for as long as the app is installed. When you uninstall, we immediately delete your Shopify sessions and access token and mark the store inactive; your groups and settings are held a little longer so that reinstalling restores your setup.
When Shopify sends the shop/redactrequest that follows an uninstall — or when you ask us to delete sooner — we erase your store’s record together with your groups, rules, variant-image mappings, appearance and card-per-variant settings, import summaries, storefront token record, feature requests and votes, Shopify sessions, our webhook de-duplication records, and our internal support-action log.
The metafields the app wrote stay in your store after an uninstall, because an uninstalled app can no longer reach it. To remove them first, use Settings → Remove app data in the app before uninstalling: it deletes the three metafield definitions and every value they hold, and revokes the storefront token.
Database backup snapshots are retained for up to 30 days, so deleted data may remain in a backup until that snapshot ages out.
7. Security
All traffic is served over HTTPS. Shopify access tokens are encrypted at rest with AES-256-GCM. Internal access to store data is restricted to authorized operators, and the actions they take are recorded in an audit log.
8. Cookies & local storage
The embedded admin app sets a first-party locale cookie — and a companion localeManualflag recording whether you chose the language yourself — that remembers your admin language for a year. Because the app runs inside Shopify Admin’s iframe, these are set as SameSite=None; Secure; Partitioned. Your browser’s local storage remembers whether you dismissed the setup checklist.
On your storefront, the Combined Listings script sets no cookies and does no tracking. It reads stock and prices from your own store’s Storefront API and keeps the answer in the shopper’s session storage for one minute.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
10. Contact
Questions about privacy or a data request? Email us at [email protected].
