Last updated: 28 August 2026
DataBay is a Shopify app operated by DataBurst ("we", "us"). It syncs a merchant's store data into a private analytics warehouse and renders dashboards on top of it. This policy explains what we collect, why, and how a merchant or their customers can have it deleted.
The merchant who installs DataBay is the data controller for their store's data. We act as a data processor on their behalf: we only process store data to provide the analytics service the merchant asked for.
Only what the granted access scopes allow, and only for the data streams the merchant enables:
read_products — products, variants, inventory levelsread_orders — orders, line items, refunds, transactionsread_customers — customer records attached to those orders
(name, email, address, order history)read_inventory — inventory items and locationsread_shopify_payments_payouts — payout and balance recordsWe do not collect payment card numbers, and we do not receive Shopify customer passwords.
To load your store and advertising data into your isolated warehouse, to compute the metrics shown in the dashboards, to answer your natural-language queries, to send you sync and pipeline alerts, and to secure and support the service. We do not sell your data and we do not use it to train third-party models.
Store data is loaded into a ClickHouse warehouse, isolated per organisation, hosted on our servers in the European Union. Access is restricted to the merchant's own users and to DataBurst staff who need it for support and operations. Subprocessors we use are limited to our hosting provider, Shopify itself, and any advertising platform you explicitly connect.
We keep synced data for as long as the app is installed. When the app is
uninstalled, Shopify sends us a shop/redact request and we delete
the store's warehouse data and configuration.
We implement Shopify's mandatory compliance webhooks:
customers/data_request — we export the data we hold about
that customer and return it to the merchant.customers/redact — we erase that customer's personal fields
from the warehouse.shop/redact — we drop the store's data 48 hours after
uninstall, as required by Shopify.Merchants can also request access, correction, export, or erasure at any time by emailing us. We respond within 30 days.
Depending on where you live (GDPR, UK GDPR, CCPA/CPRA), you may have the right to access, correct, delete, or port your personal data, to object to or restrict processing, and to lodge a complaint with a supervisory authority. Merchants should route their customers' requests through Shopify so the compliance webhooks above are triggered.
Data is encrypted in transit (TLS) and connector credentials are encrypted at rest. Access to production systems is restricted and authenticated.
We will update this page when our processing changes, and update the "last updated" date above.
DataBurst — info@databurst.tech