About this policy
This Privacy Policy explains how Innovative Hospitality Marketing Inc. (“IHM,” “we,” “us,” or “our”) processes information when a merchant installs or uses IHM Catalog Studio, our embedded Shopify application.
Information we process
To operate the application, we may process and store:
- Shopify shop domains, shop identifiers, and installation or uninstallation lifecycle metadata.
- Server-side Shopify authentication and session information, including access or refresh tokens, granted scopes, expiration information, and staff or account metadata Shopify may include in an authenticated session.
- Catalog titles, source settings, collection identifiers, templates, field selections, presentation configuration, Shopify product GIDs, and catalog ordering.
- Product information retrieved from Shopify, including information used to display products and render catalogs.
- Immutable CatalogSnapshot data used to reproduce a historical catalog.
- Merchant-provided display name, accent color, contact email, website, phone number, footer text, and uploaded PNG or JPEG logo.
- Operational error logs and limited privacy-webhook metadata such as topic, shop domain, outcome, whether data existed, and safe failure category.
- Information a merchant voluntarily includes in an email to support.
How information is used
We use this information to authenticate the Shopify installation, provide and secure IHM Catalog Studio, create and manage catalogs, generate requested PDF outputs, reproduce historical catalogs, diagnose technical problems, respond to support and privacy requests, and comply with applicable obligations.
Shopify product data
Shopify is the source of current live product data. IHM Catalog Studio uses the Shopify Admin GraphQL API, and its current Shopify access is limited to the read_products scope. Product identifiers and catalog ordering may be stored locally, while complete product information is hydrated from Shopify when needed.
Product information may also be captured in an immutable CatalogSnapshot so that a historical catalog can be reproduced even if the live Shopify product later changes.
PDFs, branding, and logos
PDF catalogs are generated server-side on demand from catalog snapshot data. The current production architecture does not permanently store the resulting PDF bytes, but the CatalogSnapshot used to render a PDF remains stored until removed through supported deletion or lifecycle behavior.
Merchant branding and current logo bytes are stored to provide branded catalogs. A version 2 snapshot may contain an immutable copy or representation of branding and logo information. Replacing or removing current branding does not modify prior immutable snapshots.
Shopify customer data
IHM Catalog Studio does not currently request Shopify customer scopes or intentionally collect or store Shopify customer records, customer addresses, order histories, checkout information, or other customer-specific personal information. It does not create advertising or marketing tracking profiles.
Service providers
Shopify provides authentication, the embedded-app framework, App Bridge, Admin GraphQL product data, product-image delivery, and privacy and lifecycle webhooks. Replit provides production application hosting and Replit-managed PostgreSQL database infrastructure.
Retention and deletion
Uninstalling the application removes applicable Shopify sessions and marks the Shop uninstalled, but it does not immediately delete all merchant-created catalogs, snapshots, branding, or historical data. Merchant-created data may remain after uninstall until removed through supported deletion mechanisms or Shopify’s authenticated shop/redact process. We do not currently promise a fixed numeric post-uninstall retention period.
When a valid authenticated shop/redact webhook is received, locally retained data for that shop is deleted. Repeated redaction requests are handled safely. Shopify customers/data_request and customers/redact requests are handled based on the fact that IHM Catalog Studio does not currently store customer-specific records.
Security
We use technical and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No system can guarantee absolute security, and we do not represent that the service will be free from every security risk.
Contact us
Privacy questions may be sent to support@ihmloyalty.com.
Innovative Hospitality Marketing Inc.2501 W Sunflower Ave
Santa Ana, CA 92704
United States