Security & Privacy
How we handle data.
Shoplist treats customer data with care and is built from public signals. Here’s how we handle security and privacy — stated plainly, without overclaiming.
Your data stays yours
Shoplist never resells or trains models on customer data. All enrichment runs in isolated workspaces.
Encrypted transport and storage
Customer data is handled with encrypted transport and storage controls appropriate to the product surface.
Secure integrations
We land and expand via secure, read-only connections. You control scopes, retention, and revocation.
Data handling
What we collect, and what we don’t
Shoplist is a public-data intelligence platform. The privacy story starts with what never enters the system.
Public and productized signals
The catalog is built from public Shopify pages, storefront signals, and productized ecosystem data — never private merchant or partner admin data.
Intentional exclusions
Private merchant or partner admin data, internal scores, and unstable operational fields are kept out of public profiles. Business contact details appear only where a customer surface, plan, and privacy choices support them.
You control your account data
Workspace integrations use scoped, revocable connections. You control scopes, retention, and revocation, and we never resell customer data.
For how data is sourced and labeled, see the data methodology. For how we handle personal data and your choices, see the privacy notice.
Straight talk
What we don’t claim
We won’t list certifications we don’t hold. Rather than imply a specific compliance badge, we’ll tell you exactly where our security and privacy practices stand today — and share documentation and answers for vendor questionnaires on request.
If your procurement process needs specific controls or paperwork, get in touch and we’ll walk through what we can provide.
Vendor review
Reviewing Shoplist for your team?
Request security documentation or answers for a vendor questionnaire and we’ll follow up.