Shopify Ecom

Policies

Privacy Policy

How Shopify Ecom handles newsletter data, browser-local Store Launch Checklist sessions, analytics exclusions, and ordinary edge request logs.

Last updated: September 13, 2026

Scope

This policy covers the newsletter and the Shopify Store Launch Checklist on shopify.ecom-store.pro. Browsing articles, using the checklist, or downloading public files does not require an account. Site delivery and analytics services may still process ordinary request or usage data as described below.

Newsletter data we collect

When you subscribe to the newsletter, we collect:

  • Your email address — required, used as the unique identifier for the subscription and as the address we send updates to. The email is normalized to lowercase before storage.
  • Category preferences — optional. If you don't pick categories, the subscription defaults to all available topics.
  • A management token — a random, unguessable identifier generated server-side at sign-up. It is the key that lets you (and only you) view, update, or cancel your subscription without logging in.

We do not collect names, IP addresses for marketing purposes, browsing history, advertising identifiers, or any payment information through the newsletter form.

Why we use newsletter data

  • To send you the newsletter you explicitly signed up for, limited to the categories you selected.
  • To let you change your category preferences or unsubscribe at any time, via the management token.
  • To honor unsubscribe requests permanently — once you unsubscribe, the address is recorded so we don't accidentally email it again.

The legal basis is your consent, given by submitting the subscription form. You can withdraw consent at any time by unsubscribing.

Where newsletter data is stored

Subscription records are stored in our managed backend database (Lovable Cloud, powered by Supabase). Access is restricted by row-level security policies and limited to the operator of this site.

The management token issued to you at sign-up is also saved in your browser's localStorage on the device you subscribed from, under the key newsletter-manage-token. That is what allows the site to recognize your subscription on subsequent visits and show the management UI without requiring a password. Clearing site data in your browser removes that token locally — it does not delete the subscription itself.

Store Launch Checklist session

The checklist keeps its tick marks in your browser's localStorage under the key shopify-launch-checklist:steps:v1. It also remembers three view choices, each under its own key: the “What are you selling?” filter you last chose (shopify-launch-checklist:model:v1), the path you picked (shopify-launch-checklist:pace:v1), and the phase you were last viewing (shopify-launch-checklist:phase:v1). These records hold only step, model, path, or phase IDs — no answers, no personal data, no result. They are written on your device, are never sent to a server, and the steps record is removed by “Clear all marks” on the page or by clearing site data in your browser. If localStorage is blocked or unavailable, the checkboxes and the filter still work for the current page view and nothing is stored.

Printing is user-initiated and uses your browser's local print dialog. If you choose “Save as PDF,” the file is created on your device and is not uploaded anywhere. A printed or saved copy can reflect commercially sensitive planning, so protect it as you would other business-planning material.

The checklist has no server-save feature, does not require or collect an email address, and does not create a personal or shareable link. Its code does not send your tick marks or your selected filter to analytics or error-reporting endpoints.

How emails are sent

Outgoing newsletter campaigns are sent through a third-party email service provider (ESP). Your address and category preferences are synchronized to that provider for the sole purpose of delivering the newsletter you signed up for. Transactional system emails (for example, an unsubscribe confirmation) are processed through our managed backend email infrastructure. We do not sell, rent, or share your address with third parties for their own marketing.

If a message permanently bounces or is reported as spam, the address is added to a suppression list to prevent further sending.

Retention

We keep active subscription records for as long as the subscription is active. When you unsubscribe, the record is marked inactive and retained as a suppression entry so the address is not re-added by mistake. You can request full deletion of any remaining record by emailing us (see below).

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict processing. To exercise any of these rights:

  • Unsubscribe — use the unsubscribe link in any newsletter email, or the “Unsubscribe” button in the subscription widget on the site.
  • Update preferences — use the “Manage” button in the subscription widget on any page where it appears.
  • Access or delete — email shopify@ecom-store.pro from the address you subscribed with.

Site analytics, provider services, and edge logs

The newsletter feature itself does not set tracking cookies. The only client-side storage it uses is the localStorage entry described above, which exists solely to recognize your own subscription on your own device.

On both /tools/shopify-store-readiness and its canonical trailing-slash path, route-specific controls exclude Microsoft Clarity. The clean assessment artifact and delivery response are also checked for the provider analytics observed elsewhere on the site: /~flock.js, /~api/analytics, Cloudflare browser analytics through static.cloudflareinsights.com and /cdn-cgi/rum, and Google/DoubleClick advertising analytics. These exclusions are specific to the checklist paths. Other pages on the site may use Clarity and may receive hosting-provider, performance, or advertising-measurement requests.

Cloudflare and the hosting provider can retain ordinary HTTP delivery and security logs, such as the request time, IP address, user agent, requested path and query, response status, and security signals. The checklist never puts your tick marks or filter selection into the path, query, hash, or a shareable link, so that state is not included in those edge request logs. Page code cannot remove infrastructure-level request logging.

The site search sends a quiet request when you use it, so we can see what people search for and whether they find it. Your search text travels in that request's path — this is deliberate for search, unlike the checklist above. A search that contains an email address, or a run of six or more digits in a row (which could be an order number, phone number, or card number), is never sent. These requests land in Cloudflare's ordinary delivery logs described above, and Cloudflare — not this site — sets how long they are kept.

Children

The newsletter is intended for adult Shopify merchants and operators. We do not knowingly collect personal data from children under 16. If you believe a child has subscribed, contact us and we will remove the record.

Changes to this policy

If we materially change how the newsletter, checklist, or site analytics handle data, we will update this page and revise the “Last updated” date above. If a substantive change affects newsletter subscribers, active subscribers will be notified by email.

Contact

Questions about this policy or your data? Email shopify@ecom-store.pro or use the contact page.