Privacy Policy
Last Updated: August 12, 2026
ParticleSearch ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains what data we collect, how we use it, and what rights you have. We've written this in plain language because we believe you deserve to understand exactly what's happening with your data. By installing or using ParticleSearch, you agree to this policy.
01. 1. Who This Policy Covers
This policy covers three groups of people:
- Merchants: Shopify store owners who install and use ParticleSearch.
- End Customers: Shoppers who use the search bar on a ParticleSearch-powered Shopify store.
- Website Visitors: People who browse particlesearch.com, contact us, or request email updates.
We handle these groups according to how they interact with us. Merchants use the application, end customers use a merchant's storefront search, and website visitors choose whether to contact or subscribe. We treat end-customer data with strict minimalism.
02. 2. What Data We Collect
2.1 Merchant Data
When you install ParticleSearch via Shopify OAuth, we collect and store the following:
- Store URL and Shopify domain
- OAuth access token and approved Shopify permission set
- Catalogue data: products, variants, titles, descriptions, prices, SKUs, barcodes, images, tags, selected metafields and metaobjects, and inventory status
- Email address (if you contact support or subscribe to updates)
- Permission and installation state for optional product capabilities
- Required: read_products, read_inventory, and read_metaobjects for catalogue search
- Optional: read_content for page and article search; read_orders, read_customer_events, and write_pixels for Shopify-verified revenue attribution
We do not collect your Shopify admin password or customer payment-card details. Optional revenue attribution uses limited completed-order evidence described below; it does not request customer names, email addresses, phone numbers, or postal addresses.
2.2 End Customer Data (Shoppers on Your Store)
When a shopper uses the ParticleSearch widget on your store, we process and log:
- Search queries (the words they type into the search bar)
- Search results, impressions, clicks, product actions, filters, refinements, and exits
- Storefront surface, locale or market context, timestamps, and a store-scoped pseudonymous session identifier
- Recent-search and in-progress search state stored in the shopper's browser session
- When revenue attribution is enabled: a pseudonymised order identifier, order totals and currency, discount, tax and shipping totals, purchased product and variant line items, checkout time, and the eligible ParticleSearch touchpoints connected to that checkout
Search analytics are provided to the merchant that operates the store. Before persistence, ParticleSearch replaces raw browser session and order identifiers with store-scoped, non-reversible identifiers and redacts high-confidence email, phone, payment-card, and URL patterns from free-text search data. ParticleSearch does not request customer contact fields for analytics and does not use the identifier to track a shopper across different merchants. The storefront uses sessionStorage and, when attribution is enabled, limited localStorage to preserve search context.
2.3 Website and Contact Data
When you browse particlesearch.com or send the contact form, we may process:
- Standard network, request, device, and security metadata used to deliver and protect the website
- Your name, email address, message, and any optional phone, store, catalogue-size, or current-provider details you submit
We use contact-form data only to respond, provide requested support or commercial context, protect the form from abuse, and retain appropriate business records.
2.4 Technical & Usage Data
We collect standard technical data to operate and improve the service:
- API request metadata and error logs used for service reliability, security, debugging, and incident response
- Error logs (to diagnose issues)
- Search analytics and pseudonymous session evidence linked to the merchant's store for reporting and service operation
- Limited completed-order evidence when the merchant enables Shopify revenue attribution
- Performance metrics (query response times, sync latency) are aggregated, anonymised, and retained.
- Search analytics are linked to your store and provided to you for reporting purposes through store-scoped pseudonymous identifiers. We may aggregate and anonymise search analytics across multiple stores for service improvement, industry benchmarking, and research purposes.
2.5 Optional Email Updates
If you choose to receive ParticleSearch updates, we collect your email address, the date and status of your consent, and the page or signup location where you submitted it. We use the page context to understand which content is useful and to keep future communication relevant.
We use double opt-in: an email address is not added to the confirmed update list until you click the confirmation link. Unconfirmed addresses are not used for marketing communications.
03. 3. How We Use Your Data
We use merchant data for the following purposes:
- To sync your Shopify product catalogue with our search index
- To deliver search results to your customers as requests are received
- To process product update notifications for inventory or price changes
- To provide search analytics to merchants
- To respond to support requests
- To send service-related communications (billing, security notices, updates)
- To send optional email updates when you confirm your subscription
We do NOT sell your data. We do NOT use your data to train AI models. We do NOT share your data with advertising networks.
04. 4. How We Store and Protect Your Data
4.1 Security Standards
- Data transmitted over public networks is protected using TLS
- Shopify OAuth tokens are stored securely in an encrypted database with access restricted to authorized systems only
- Access to production systems is restricted to authorized personnel
- We use anti-abuse rate limiting to prevent unauthorized access
4.2 Data Location
Your product catalogue data is stored and indexed on our infrastructure. Search queries are processed as requests arrive and are aggregated by store for analytics purposes. We use third-party infrastructure providers (including cloud hosting and Typesense for our search engine, Supabase for application data, and Resend for transactional email delivery). These providers are contractually bound to protect your data and process it only on our instructions.
4.3 Retention
- Product catalogue data: retained while your account is active, deleted within 30 days of account termination
- Service and security logs: retained under the applicable operational and security retention schedules, then deleted or anonymised, subject to legal and backup exceptions
- Contact messages: retained as needed to respond, provide support, maintain appropriate business records, and meet legal obligations
- Search analytics: retained while your account is active. Aggregated, anonymised analytics may be retained indefinitely for service improvement, industry benchmarking, research, and other purposes.
- Email addresses: retained until you unsubscribe or request deletion
- Email signup page context and consent records: retained with the associated email address
- OAuth tokens: deleted immediately upon uninstall
05. 5. Shopify Integration
ParticleSearch connects to your Shopify store via OAuth 2.0. Core catalogue search uses required permissions, while optional capabilities require separate permission approval:
- read_products, read_inventory, and read_metaobjects: catalogue and availability data used by search
- read_content: optional page and article search
- write_pixels and read_customer_events: optional Shopify Web Pixel installation and completed-checkout events
- read_orders: optional verification of order totals and purchased line items used for revenue attribution
We do not request write access to products, inventory, orders, or customers. The optional write_pixels scope is limited to registering and managing ParticleSearch's own Shopify Web Pixel. We cannot modify products, orders, or customers and do not process payments. The optional order query requests commercial order and line-item evidence, not customer contact or payment details. When you uninstall ParticleSearch from your Shopify store, your OAuth token is immediately invalidated and deleted from our systems. Your product data is removed within 30 days.
6. Third-Party Services
We use third-party services to operate ParticleSearch. A current list of sub-processors is available at particlesearch.com/subprocessors. Key sub-processors include:
- Typesense: Our search engine. Product catalogue data is indexed in Typesense to power search queries. Typesense processes data only on our instructions and does not use it for any other purpose.
- Oracle Cloud: We use Oracle Cloud for primary application infrastructure, hosting, and storage.
- Supabase: We store email subscription records and signup page context in our application database.
- Resend: We deliver subscription confirmation emails and other transactional email messages.
- Axiom: We use operational telemetry and application logs for service reliability, security monitoring, and incident response.
- Cloudflare: We use Cloudflare to host, deliver, and protect the public ParticleSearch website.
- Payment Processing: Shopify billing system or other authorized payment processors
We do not use advertising networks or share your data with third parties for their marketing purposes.
You may object to new sub-processors by contacting support@particlesearch.com within the notification period.
7. Your Rights
You have the following rights regarding your data:
Access
You can request a copy of the data we hold about you and your store.
Correction
If any data we hold is inaccurate, you can ask us to correct it.
Deletion
You can request deletion of your data at any time. Uninstalling the app triggers automatic deletion of OAuth tokens and initiates product data deletion within 30 days.
Portability
You can request an export of your data in a machine-readable format.
Objection
You can object to specific uses of your data (e.g., analytics, communications).
To exercise any of these rights, contact us at: support@particlesearch.com. We will respond within 5 business days.
8. GDPR & International Data Transfers
If you are located in the European Economic Area (EEA), United Kingdom, or Canada, you have additional rights under applicable data protection laws (including GDPR). Our legal basis for processing merchant data is:
- Contract performance : processing your product catalogue is necessary to deliver the service you've purchased.
- Legitimate interests : for service improvement, security monitoring, and abuse prevention.
- Consent : for optional communications (you can withdraw consent at any time).
For end customers, the search, browser-session, and optional attribution evidence described above may be personal data under applicable law even though ParticleSearch does not request customer contact fields. We minimise free text and replace raw session and order identifiers with store-scoped pseudonymous values before persistence. The storefront uses browser storage rather than advertising cookies to preserve the search context described in section 2.2. If you have questions about international data transfers, contact us at support@particlesearch.com.
9. Children's Privacy
ParticleSearch is a B2B service designed for Shopify merchants. We do not knowingly collect any data from individuals under the age of 18. If you believe a minor has provided us with personal information, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the 'Last Updated' date at the top of this document
- Make reasonable efforts to send an email notification to merchants with an active account at least 14 days before changes take effect
- We may make changes immediately without advance notice if required for security, legal compliance, or to prevent abuse. In such cases, we will notify merchants as soon as reasonably practicable after the change.
For non-material changes (such as clarifications or corrections), we will update the 'Last Updated' date only. Your continued use of ParticleSearch after changes are posted constitutes your acceptance of the updated policy.
11. Contact
If you have questions, concerns, or requests related to this Privacy Policy:
Email: support@particlesearch.com
Website: particlesearch.com
We take privacy seriously and will respond to all inquiries within 5 business days.