Privacy Policy
Last updated: August 2026
1. Introduction
Veloxify ("we", "our", "the App") is a Shopify application that helps merchants optimize their store performance. This Privacy Policy explains what data we collect, how we use it, and your rights.
2. Data We Collect
- Store domain and Shopify access token — used to connect and operate the app on your store.
- Your store's primary language — used to generate content in the right language.
- Performance scan results (Core Web Vitals: LCP, CLS, INP, FCP, TTFB) for each page analyzed.
- Image data — URLs, file sizes before and after optimization, and alt text.
- Script data — third-party script URLs detected on your storefront, and which app they belong to, when detectable.
- SEO scan results — score, detected issues, and generated meta title/description suggestions.
- Your subscription plan and billing status.
- Your image-optimization preferences (compression level, WebP, lazy loading).
We do not collect personal data from your customers (names, emails, addresses, payment info).
3. How We Use Your Data
- To provide the core app features (performance scans, image optimization, script analysis, SEO audits).
- To display your performance and SEO history and progress over time.
- To manage your subscription and billing via Shopify Billing API.
4. Data Sharing
We do not sell, rent, or share your data with third parties, except:
- Shopify — to read and update your products and store content, manage files used for image backups, read your store's supported languages, and manage billing.
- Google PageSpeed Insights API — your store URL is sent to Google to retrieve performance metrics.
- Neon (PostgreSQL) — our database provider stores your app data securely.
- Sentry — error monitoring. No personal data is sent.
5. Data Retention
Your data is retained as long as your store is connected to Veloxify. When you uninstall the app, your store data is permanently deleted from our database within 48 hours (via GDPR webhook).
6. Your Rights (GDPR)
If you are subject to GDPR, you have the right to access, correct, or delete your data. To exercise these rights, contact us at the email below.
7. Security
We use HTTPS for all connections, HMAC-SHA256 signed session cookies, and environment-level secrets management. Access tokens are stored in our database with access restricted to the application. Our database provider, Neon, encrypts all data at rest (AES-256) and in transit (TLS).
Veloxify — https://veloxify.app