Privacy Policy
Path Catalog Health (“the app”, “we”, “us”) is operated by Outsource Experts Ltd, trading as Path, with a registered address at Enterprise Centre, 6 David Lane, Nottingham, NG6 0JU. This policy explains what information we access from your Shopify store, which permission each type of data maps to, why we need it, how and when we access it, how long we keep it, and the rights available to you.
We build for apparel merchants who care about their catalog, and we know that installing an app with this many permissions deserves a clear explanation. Our guiding principle is data minimisation: we request only what we need to find and fix the images that affect your revenue, and we deliberately avoid your customers’ personal details.
At a glance
- We never see your customersNo names, emails, phone numbers, or addresses — we filter order data down to products, quantities, and totals only.
- You approve changesWe only edit product images, alt text, and gallery order to apply fixes you review, or edits you order. We never change pricing, inventory, or customer records.
- We never sell your dataYour data is used solely to run the app for you, and is never sold or used for advertising.
- Your data doesn’t train AIImages we send to our AI provider are not used to train any AI model and are held only transiently.
Permissions we request and why
When you install the app, Shopify asks you to grant a set of access permissions (“scopes”). Here is exactly what each one lets us access and why we need it. We chose each permission so we can surface the changes most likely to improve revenue — starting with your best-selling, highest-traffic, and most-returned products.
| Permission (as shown at install) | What it lets us access | Why we need it |
|---|---|---|
read_orders, read_returns | Product IDs, quantities, prices, order totals, discounts, and order/return status — never customer names, emails, addresses, or phone numbers. | To rank your best-selling and most-returned products, so we prioritise fixes on your most revenue-impactful items first, and measure whether a change improved sales or reduced returns. |
read_customer_events, write_pixels | Anonymous storefront interactions (product and image views, add-to-cart, checkout) via Shopify’s privacy-gated web pixel. | To find high-traffic products that convert poorly, so we can improve that imagery first, and to prove the impact of the changes you make. |
read_inventory, read_locations | Variant stock levels and which store locations sell and ship online. | To only measure conversion during periods a product was actually in stock, so a stockout doesn’t get mistaken for a bad image. |
write_products, write_files | Product images, image alt text and filenames, gallery order, and variant-to-image mapping. | To apply the image and SEO fixes you approve, and to publish professionally edited images from Path Edits back to your catalog. |
read_themes | Your live theme’s identifier only. | To deep-link you to the right place in the theme editor to enable the storefront gallery. We never read or modify your theme code. |
We also read basic store profile information (store name, domain, contact email, currency, timezone, country, and plan) to set the app up correctly and send service notifications, and account details (name and email) for the staff who use the app. Billing and subscription metadata is handled through Shopify to manage your plan and any professional editing orders, and we keep records of your support requests and correspondence with our team.
What we deliberately don’t collect
- No customer personal data. We use Shopify’s field allow-lists so order and refund webhooks deliver only product, money, date, and status fields. Customer names, emails, phone numbers, and shipping/billing addresses are never sent to us or stored.
- No return or refund free text. We store return status and returned quantities, but not the customer- or merchant-written reason for a return or refund.
- No changes to your commerce data. We do not read or write product pricing, inventory quantities, discounts, or your customer list.
- No cross-site tracking or data sale. Storefront analytics is anonymous and used only to measure your imagery; it is never sold or used for advertising.
When and how we access data
- At install and first setup: you grant the permissions above; we read your store profile, install the analytics web pixel, and identify your recent best-sellers to get you started.
- Continuously, via Shopify webhooks: when a product, order, refund, return, or inventory level changes, Shopify notifies us so your insights stay current — each notification is limited to the specific fields listed above.
- When you take an action: we read a product’s images to audit it, and write changes only when you apply a fix or place a professional editing order.
- On a schedule: a routine daily reconciliation keeps product availability and performance metrics accurate.
Storefront analytics
To measure how your product imagery performs, the app installs a Shopify web pixel, which is enabled automatically when the app is first set up after installation. Together with our theme extension, it records anonymous storefront interactions for the products you monitor with the app:
- An anonymous visitor identifier provided by Shopify’s web pixel — not a name, email, or account, and not used to identify individuals
- Product, variant, and image interactions: product views, variant selections, image thumbnail clicks, gallery image views, add-to-cart, and checkout started and completed events
- Context for each event: the page path, the referring site (host only), the image’s position in the gallery, and the cart or checkout value and currency
The pixel is registered as analytics-class only, so it stays subject to Shopify’s customer-privacy and consent controls. We deliberately strip query strings from page paths and keep only the host of referrers so this data cannot capture coupon codes, affiliate tags, or other identifiers. Depending on your plan, storefront analytics may not be collected, and events are only recorded for the products you actively monitor.
Visitors to our website
When you visit our public website (as distinct from the app itself), we use a privacy-friendly analytics tool to understand how the site is used — for example, which pages are viewed, how visitors arrive (including from links in our emails), and general information such as approximate location, device, and browser. This analytics tool does not use cookies, does not store data on your device for tracking, and does not collect information that identifies you personally or tracks you across other websites. Because of this, we do not display a cookie consent banner for these measurements. This website analytics is separate from the storefront analytics described above.
How we use your information
- To audit product images and compute catalog health scores
- To generate recommendations and apply the fixes you approve
- To fulfil professional editing orders you place with Path Edits
- To measure how your images and the changes you make affect storefront engagement and conversion
- To process billing and manage your subscription through Shopify
- To provide support and send service-related notifications
- To maintain the security, integrity, and performance of the app and to meet our legal obligations
Who is responsible for your data
Outsource Experts Ltd is the data controller for the merchant account data described in this policy. For data we process on your behalf to deliver the app’s features — product content drawn from your store, and storefront-analytics events collected from your shoppers — we act as your processor and handle that data only as needed to provide the service. As the merchant, you remain the controller for your storefront visitors’ data and are responsible for the privacy notices and any consent your storefront requires. This policy does not cover Shopify’s own privacy practices or the wider privacy notices you provide to your own customers.
Legal bases for processing
Under UK data protection law, we rely on the following legal bases:
- Performance of a contract — to deliver the features you install the app for and to fulfil orders you place.
- Legitimate interests — to operate, secure, and improve the app, and to produce the anonymous storefront analytics that show how your imagery performs, where this is not overridden by the rights of the individuals concerned.
- Legal obligation — to keep records required for tax, accounting, and compliance purposes.
Who we share data with
We do not sell your data. We share it only with the service providers (sub-processors) that help us deliver the app, and only to the extent needed for them to perform their function:
| Provider | Purpose |
|---|---|
| OpenAI | AI analysis of product images to generate audit findings, recommendations, and alt text. Content is not used to train AI models. |
| Supabase | Database and image storage hosting for your app data. |
| Trigger.dev | Runs audits, fixes, and editing workflows in the background. |
| Resend | Sends transactional service and order-related emails. |
| Vercel | Application hosting and privacy-friendly, cookieless analytics for our public website. |
| Shopify | The platform through which the app is installed, authenticated, billed, and through which storefront pixel events are delivered. |
This list may change as our service evolves; we will keep it current and update the “last updated” date when we do. We may also disclose information where required by law, or to protect our rights, users, or the security of the service.
International transfers
Some of our service providers process data outside the United Kingdom and the European Economic Area. Where that happens, we rely on appropriate safeguards recognised under UK data protection law, such as the UK International Data Transfer Agreement or Standard Contractual Clauses, to protect your information.
Retention and deletion
We retain your information for as long as the app is installed and for a reasonable period afterwards to meet legal, accounting, and billing requirements. Storefront-analytics events are retained for up to 90 days and then purged automatically. When you uninstall the app, we honour Shopify’s mandatory data-redaction webhooks (customers/redact, shop/redact, and customers/data_request) and anonymise or delete store-identifying data — including stored storefront events — within the timeframes Shopify mandates. Working copies of images uploaded to our AI-analysis provider are held only transiently and expire automatically. We follow Shopify’s Protected Customer Data requirements in how we handle store and order data.
How we protect your data
We use appropriate technical and organisational measures to protect your information, including encryption in transit, access controls, and tenant isolation so that each merchant’s data is kept separate. No method of transmission or storage is completely secure, but we work to protect your data and to respond promptly to any incident.
Your rights
Subject to applicable law, you have the right to access, correct, or erase your personal data, to restrict or object to certain processing, and to request a copy of your data in a portable format. To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe we have not handled your data properly.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the “last updated” date above and, where appropriate, notify you through the app or by email.
Contact us
Questions about this policy or your data? Email us at hello@pathcataloghealth.com or write to Outsource Experts Ltd, Enterprise Centre, 6 David Lane, Nottingham, NG6 0JU.