Terminal Commerce Channel
Privacy Policy & Data-Retention Statement
Operator: Ensemble Ventures (Guillaume Racine), Montréal, Québec, Canada.
Contact: gui@ensembl3.xyz
Effective: 2026-08-04.
What this app does
The submitted Shopify UCP Edition is an embedded merchant setup app. It shows the merchant's Shopify-owned UCP endpoint and produces provider-neutral, no-secret connection guidance. Shopify serves catalog, cart, and checkout traffic directly.
Data we process
Data processed by Tilda for the embedded merchant app:
- Shopify shop domain, installation status, approved scopes, and encrypted Shopify installation/session credential.
- Product and publication-readiness fields read transiently when the merchant opens the readiness view.
- Operational health and redacted application-error metadata needed to secure and support the embedded app.
Tilda does not receive or store native UCP shopper traffic. Catalog queries, carts, checkout URLs, customer data, orders, B2B data, addresses, logins, and payment data travel directly between a shopper-controlled client and Shopify in this edition.
How we use it
- Authenticate and render the embedded merchant setup experience.
- Show the correct merchant-owned Shopify UCP endpoint and no-secret configuration.
- Report catalog-readiness information requested by the merchant.
- Operate, secure, and debug the service using redacted operational metadata.
We do not sell data or use it for advertising. The embedded app uses Railway hosting and PostgreSQL storage as infrastructure subprocessors. Tilda does not send Shopify data to a named AI provider in the submitted edition.
How we protect it
- API tokens encrypted at rest (AES-256-GCM) with key rotation.
- HTTPS in transit; server-side Admin/Storefront calls.
- Shopify session-token authentication and merchant-scoped authorization.
- Connector-only relay, Storefront-token, endpoint-token, order-webhook, evidence, and safety routes fail closed in the UCP Edition.
Retention & deletion
- The encrypted installation/session credential and shop record are retained while the app is installed.
- Readiness results are generated on request and are not retained as shopper history.
- On app uninstall, the per-shop app state is deleted.
- We honor Shopify's GDPR webhooks:
customers/data_request, customers/redact, shop/redact.
- Merchants may request deletion at any time via the contact email above.
Your rights
Depending on jurisdiction (GDPR / CCPA / PIPEDA), you have rights to access, correct, delete, or restrict processing. Send requests to the contact email above.
Changes
We'll post changes here and update the effective date.