Privacy & data processing
How Darjuro handles your product data — especially relevant for merchants and agencies in the EU/EEA.
Last updated: September 2026 · This is a product summary, not legal advice.
Free homepage evaluator
When you use the free evaluator on the homepage, evaluation runs entirely in your browser. Your product JSON or CSV is not uploaded to our servers for scoring. We cannot see your catalog during a free evaluation.
Anonymous usage may still be subject to basic rate limiting at the network edge (IP-based) to prevent abuse. No product content is stored from free evaluations.
Signed-in accounts (web app)
When you create an account and run evaluations, we store evaluation results, mapped product data, findings, and catalog metadata so you can return to reports, compare versions, and export fixes.
Data is isolated per user with row-level security in our database. Other users cannot access your evaluations.
Controller: The entity operating Darjuro. Contact darjurosupport@gmail.com for privacy requests.
Legal bases (GDPR): Contract performance (providing the service you signed up for) and legitimate interest (security, abuse prevention, product improvement via aggregated analytics).
Shopify App
When you install Darjuro from the Shopify App Store, we process store data to score and help fix catalog quality for AI discovery. This channel is separate from the signed-in web app: Shopify installs use a shop-scoped tenant (not a Clerk login) unless you later link accounts in a future release.
What we access: Product catalog fields via the Shopify Admin API using the scopes you approve (read_products, write_products, write_inventory for variant weight). We do not request protected customer data (no customer, order, or checkout scopes).
What we store:
- An encrypted offline access token so scheduled and on-demand scans can run
- Synced product/catalog snapshots, evaluation scores, and findings
- Webhook delivery IDs for idempotency (uninstall and privacy topics)
Webhooks: We subscribe to app/uninstalled and Shopify compliance topics (customers/data_request, customers/redact, shop/redact). Customer compliance webhooks are acknowledged only — we do not store customer personal data. On shop/redact, we erase the shop connection, credentials, catalog sources, evaluations, and the shop-scoped profile when nothing else remains.
Uninstall: Uninstall clears credentials and marks the connection uninstalled. Full shop erasure follows Shopify’s shop/redact timeline.
Product titles or descriptions may incidentally contain personal data if merchants put it there. Do not store customer PII in product fields you sync to Darjuro.
Subprocessors
We use the following categories of service providers:
- Authentication — Clerk (identity, session management) for the signed-in web app
- Database & storage — Supabase (PostgreSQL, row-level security)
- Hosting & analytics — Vercel (application hosting, performance analytics)
- Commerce platform — Shopify (App Store distribution, Admin API, session tokens)
Enterprise customers in the EU may request a Data Processing Agreement (DPA) and confirmation of data region choices before production use.
Retention
Evaluation data is retained while your account or Shopify install is active. You may delete catalog sources and associated evaluations from the web workspace. Shopify merchants: uninstall plus shop/redact removes shop connection data as described above. Account deletion or privacy requests remove associated personal data subject to legal retention requirements.
Your rights (EU/EEA)
Where GDPR applies, you may have the right to access, rectify, erase, restrict, or port your personal data, and to object to certain processing. Contact darjurosupport@gmail.com to exercise these rights. You may also lodge a complaint with your local supervisory authority.
Product catalog content
Product feeds and Shopify catalogs are typically business data rather than consumer personal data. If your uploads or product fields include personal data (e.g. customer-linked records), ensure you have a lawful basis to process it. Do not upload unnecessary personal data.
Related
See also our terms of service, support, product scope, and the FAQ section on data privacy.