DC Delete Duplicates
Privacy policy
Last updated October 6, 2026. This policy explains what DC Delete Duplicates reads and stores when you use the app, who processes that data, and how to contact us.
Who we are
DC Delete Duplicates is a Shopify admin app operated by Dream Commerce, based in Poland in the European Economic Area. For privacy questions, write to contact.dcapps@gmail.com.
Roles
You (the merchant) remain the controller of your Shopify store data. We process that data only to provide the app. If you email us, we are the controller of that correspondence.
Data we access
The app uses the Shopify Admin API with the write_products scope. It reads:
- Your shop domain and Shopify shop ID
- Product ID, title, handle, status, created date, and featured image URL and alt text
- Variant ID, title, SKU, barcode, and display name
That is used to group duplicates and to delete products you select. We do not request customer, order, or payment scopes.
Data we store
We store only what we need to run the app:
- Shopify session data (shop domain, access token, and granted scopes) so you stay signed in
- Shopify shop ID
- Which paid plan you approved, if any, so Pro tools stay available
- Short technical billing diagnostics if a charge lookup fails. These do not include payment card numbers
Product data is processed in memory, or through Shopify bulk operations, during a scan or delete. We do not save your catalog in our database.
Data we do not collect
We do not collect:
- Customer names, emails, addresses, or orders
- Payment card details. Shopify bills app charges on your Shopify invoice
- Storefront activity, marketing profiles, or tracking of your buyers
How we use data
We use the data only to run DC Delete Duplicates: find duplicates, delete products you choose, keep you signed in, and remember your plan. We do not sell your data, use it for advertising, or use store data to train public AI models.
Where GDPR applies, we rely on these legal bases:
- Contract (Article 6(1)(b)): providing the app you installed
- Legitimate interests (Article 6(1)(f)): security, debugging, and preventing abuse
- Legal obligation (Article 6(1)(c)): responding to Shopify's mandatory privacy webhooks
Sharing
We share data only with the services that run the app:
- Shopify โ Admin API, app billing, and session tokens
- Cloudflare โ hosting (Workers), database (D1), and operational logs
- Google โ Gmail, if you write to us at contact.dcapps@gmail.com
International transfers
We operate from Poland. Cloudflare and Google may process data in the United States and other countries. Where required, they use Standard Contractual Clauses and, where they participate, the EU-US Data Privacy Framework.
Cookies and tracking
The embedded app uses Shopify session tokens so it can run inside Shopify admin. We do not set our own marketing cookies, ad pixels, or storefront trackers.
Retention
Session data, shop ID, plan, and billing diagnostics are deleted when you uninstall the app, and again when Shopify sends a shop erasure request (usually 48 hours after uninstall). We complete that erasure within 30 days.
Product data is not kept after the scan or delete finishes. Hosting logs may be held by Cloudflare for a limited operational period. Support emails are kept as long as needed to handle your request, then as required by law.
Shopify privacy webhooks
We subscribe to Shopify's mandatory topics customers/data_request, customers/redact, and shop/redact. We do not store customer personal data, so customer requests have nothing for us to return or delete. A shop erasure request deletes all records we hold for that shop.
Security
Traffic to the app uses HTTPS. Access tokens are used only to call the Shopify Admin API with the scopes you granted. We do not put advertising or analytics trackers in the app.
Your rights
You may ask us to access, correct, delete, restrict, or export personal data we hold, or to object to processing. Write to contact.dcapps@gmail.com. We may need to confirm that you act for the shop. You may also lodge a complaint with the Polish data protection authority (UODO) or with your local supervisory authority.
Changes
If this policy changes, we will update the date at the top of this page.
Contact
Privacy questions and support: contact.dcapps@gmail.com.