Last updated: September 2026
SchemaAgent is a Shopify application developed and operated by Apps Alchemy. This privacy policy explains what data we collect, how we use it, and how we protect your information when you use SchemaAgent to publish Product schema on your storefront, score catalog fields that search engines need, copy aggregate review ratings, and apply tag mapping rules from your Shopify admin.
Section 01
Information We Collect
SchemaAgent collects data necessary to authenticate your store, write product schema, and show catalog readiness in the app.
Those catalog reads are used to show the score in your admin. SchemaAgent does not keep a separate copy of your product catalog.
Merchant and store data
- Your Shopify store domain, shop name, shop email, and Shopify shop identifier
- Your OAuth access token, and staff session details Shopify provides when you use the embedded app (for example name, email, user id, and locale where Shopify supplies them)
- Schema settings you choose, such as whether schema injection is on, brand fallback (vendor or shop name), and whether a missing GTIN may fall back to SKU
- Mapping rules you create, including the source (product tag or metafield), the schema field, the value to write, and whether the rule is enabled
- Which review app we detect on the store (Judge.me, Loox, or Yotpo), a sample product title, and the aggregate rating value and review count for that sample
- A sync cursor and count of products whose aggregate ratings have been copied, so a rating backfill can resume without starting over
- Shop and product metafields the app writes so the theme embed can include your settings, active tag rules, and aggregate ratings in Product JSON-LD
Catalog data read to score readiness
- Published product fields needed for the catalog score: title, handle, vendor, description, featured image, variant SKU, barcode, and price
- Theme files, only to check whether the Product schema app embed is enabled
Those catalog reads are used to show the score in your admin. SchemaAgent does not keep a separate copy of your product catalog.
What we do not collect
We do not use SchemaAgent to collect customer names, email addresses, mailing addresses, order contents, or payment card data. Individual reviews and reviewer identities stay in your review app. Payment processing for Shopify checkout and for app billing is handled entirely by Shopify and your payment providers.Section 02
How We Use Your Data
We use the data we collect solely to operate SchemaAgent:
The Product schema embed runs in your theme. It builds JSON-LD from product data already on the storefront page. It does not send shopper activity back to SchemaAgent.
We do not sell, rent, share, or trade merchant or customer personal data with third parties for advertising, marketing, or unrelated commercial purposes.
- Authenticate your store and keep a secure embedded-app session
- Save schema settings and mapping rules, and publish them to shop metafields the storefront embed reads
- Read aggregate star ratings and review counts from the review app already installed on your store, and write those totals onto product metafields as aggregateRating
- Score published products so you can see which schema fields are still missing
- Check whether the Product schema theme embed is turned on
- Send our team a short operational notice when a store installs or opens the app, so we can support new merchants
- Fulfil Shopify’s mandatory privacy webhooks (customer data requests, customer redaction, and shop redaction)
The Product schema embed runs in your theme. It builds JSON-LD from product data already on the storefront page. It does not send shopper activity back to SchemaAgent.
We do not sell, rent, share, or trade merchant or customer personal data with third parties for advertising, marketing, or unrelated commercial purposes.
Section 03
Email and communications
SchemaAgent does not send email to your customers. Subscription and receipt emails for app billing are handled by Shopify according to Shopify’s policies.
Support
If you contact us by email, or through the in-app chat, we use your message and contact details only to respond to your request. We do not add you to marketing lists solely because you wrote to support. In-app chat is provided by Crisp. Messages you send there are processed by Crisp to deliver the conversation to us.Section 04
Data storage and security
Application data is stored in PostgreSQL databases on secure cloud infrastructure. We implement industry-standard measures including:
We do not store customer payment information. Billing for the app is handled through Shopify. Aggregate ratings written to product metafields, and schema settings written to shop metafields, are stored by Shopify under your store and are readable on the storefront so the schema embed can use them.
- Encrypted connections (HTTPS/TLS) between clients and our servers
- Secure OAuth and API access through Shopify
- Environment-based management of secrets and credentials
- Database access limited to the application services that require it
We do not store customer payment information. Billing for the app is handled through Shopify. Aggregate ratings written to product metafields, and schema settings written to shop metafields, are stored by Shopify under your store and are readable on the storefront so the schema embed can use them.
Section 05
Data retention and deletion
We retain your shop record, schema settings, mapping rules, review-connection status, and sessions for as long as SchemaAgent remains installed and your store remains active in our system.
When you uninstall the app, we delete the OAuth sessions for that store. When Shopify sends the mandatory shop data erasure webhook (typically 48 hours after uninstall), we delete the remaining app-held data for that store, including the shop record, schema settings, mapping rules, review-connection data, and any sessions still on file. Metafields SchemaAgent wrote on your shop or products remain in Shopify until you remove them or Shopify removes app-owned data as part of uninstall.
SchemaAgent does not store customer personal data. When Shopify sends a customer redaction request, there are no customer records in our database to delete.
You may request assistance with deletion or data questions by contacting us at
[email protected]
Section 06
GDPR and Shopify compliance webhooks
SchemaAgent is designed to meet Shopify’s mandatory privacy requirements. We subscribe to Shopify’s compliance webhooks, including:
Where the GDPR applies, merchants remain the data controller for their customers’ personal data. SchemaAgent processes merchant and store data to provide the app. Product schema on the storefront is rendered by your theme from data Shopify already shows on the product page.
- customers/data_request — we do not store customer personal data, so there are no customer records to return. We acknowledge the request
- customers/redact — we do not store customer personal data, so there are no customer records to delete. We acknowledge the request
- shop/redact — we delete data associated with the store, including the shop record, schema settings, mapping rules, review-connection data, and sessions
Where the GDPR applies, merchants remain the data controller for their customers’ personal data. SchemaAgent processes merchant and store data to provide the app. Product schema on the storefront is rendered by your theme from data Shopify already shows on the product page.
Section 07
Third-party services
SchemaAgent relies on:
These providers process data only as needed to host the service, read ratings you already collect, deliver support, or notify our team of new installs.
- Shopify APIs — to authenticate, read products and themes, and write product metafields, shop metafields, and metaobjects within the scopes you grant
- Your review app — Judge.me, Loox, or Yotpo, only to read aggregate rating totals for products. We do not receive reviewer names, emails, or review text through this step
- Cloud hosting — to run the application and databases
- Crisp — to deliver in-app support chat if you open it
- Telegram — to deliver an operational install and app-open notice to the Apps Alchemy team. That notice can include store name, domain, owner name, shop email, store country, currency, Shopify plan, and app plan
These providers process data only as needed to host the service, read ratings you already collect, deliver support, or notify our team of new installs.
Section 08
Cookies and tracking
The embedded SchemaAgent admin experience runs inside Shopify. Session and security cookies follow Shopify’s practices as described in Shopify’s documentation. If you open in-app chat, Crisp may set cookies needed to keep that conversation working inside the embedded app.
This standalone policy page does not set marketing cookies or third-party tracking scripts. The storefront schema embed does not set cookies and does not track shoppers.
This standalone policy page does not set marketing cookies or third-party tracking scripts. The storefront schema embed does not set cookies and does not track shoppers.
Section 09
Your rights and controls
As a merchant, you can:
- Turn schema injection on or off, and edit brand and GTIN fallbacks, from the app at any time
- Add, disable, or delete mapping rules
- Stop review-rating sync by disconnecting or uninstalling the review app, or by uninstalling SchemaAgent
- Uninstall SchemaAgent to stop future data processing associated with the app
- Contact us for privacy questions or assistance with data subject requests that involve our records
Section 10
Changes to this policy
We may update this privacy policy to reflect changes in our practices, technology, or legal requirements. We will revise the “Last updated” date on this page when we do. Continued use of the app after updates constitutes acceptance of the revised policy where permitted by law. We may notify you of material changes through the app or by email when appropriate.
Section 11
Contact
If you have questions about this privacy policy or SchemaAgent data practices, contact:
Apps Alchemy
[email protected]
We aim to respond to privacy-related inquiries promptly.
Apps Alchemy
[email protected]
We aim to respond to privacy-related inquiries promptly.