Privacy Policy

Last updated: July 26, 2026

This Privacy Policy describes how Thomas Quan ("we", "us", or "our") collects, uses, and discloses information when you use our Shopify application Meta Flow (the "App"), visit https://meta-flow.fly.dev/, or otherwise communicate with us (collectively, the "Services").

The App is a Shopify developer tool designed to help merchants and developers visualize, inspect, and navigate relationships between Shopify Metafield definitions, Metaobject definitions, and related store configuration. Merchants can explore definitions as an interactive map, search and filter the graph, rearrange nodes, and open definitions in Shopify Admin. It is intended for merchants and developers. It is not a customer-facing application.

By installing or using the App, you agree to the practices described in this Privacy Policy.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our Services, legal requirements, or operational practices. When changes are made, we will update the "Last updated" date above.

Information We Collect

Information You Provide

When you install or interact with the App, we may collect:

  • Shopify store domain
  • Merchant name (if provided by Shopify during authentication)
  • Merchant email address (if provided by Shopify or through support)
  • Information you voluntarily provide when contacting support

We do not require customers of your Shopify store to provide us with information.

Information We Receive from Shopify

After you install the App and grant the required permissions, Shopify provides access to specific resources needed for the App to function.

Depending on the permissions granted, this may include:

  • Metafield definitions (including name, namespace, key, type, validations, and owner type)
  • Metaobject definitions (including name, type, field definitions, validations, and entry counts)
  • Relationships and references between metafield and metaobject definitions
  • App installation and authentication information
  • Store identifiers (such as the shop domain)

The App reads definition-level metadata in order to build and display the Meta Flow canvas. Definition data is fetched from Shopify as needed to render the App and is not permanently stored as a copy of your catalog, except for the limited layout data described below.

The App only accesses the Shopify resources necessary to provide its functionality.

Information We Store

To operate the App, we store a limited amount of data associated with your shop:

  • Authentication / session data required to communicate securely with Shopify (including access tokens and related session fields)
  • Canvas layout preferences — positions of nodes on the Meta Flow map for your shop, so rearrangements persist between visits
  • Optional browser-local layout settings (such as column spacing) stored in your browser's local storage and not sent to our servers as a separate account profile

On uninstall or when Shopify sends a shop redaction request, we delete session data and saved canvas layout data associated with that shop.

Information Collected Automatically

We may automatically collect limited technical information such as:

  • Browser type
  • Device information
  • IP address
  • Operating system
  • App version
  • Server logs and error reports
  • Session information

This information is used solely to operate, secure, and improve the reliability and performance of the App.

Information We Do Not Collect

The App is designed to minimize data collection.

Unless explicitly required by a feature you choose to use, we do not collect or permanently store:

  • Customer names
  • Customer email addresses
  • Customer phone numbers
  • Customer shipping or billing addresses
  • Customer payment information
  • Customer orders or order contents
  • Shopping carts
  • Customer browsing history
  • Metafield values or metaobject entry contents as a permanent dataset on our servers

The App is intended to visualize and navigate store metadata definitions, not to process or retain customer personal information. Although metafield definitions may exist for owner types such as customers or orders, the App uses those definitions only to show how your custom data model is structured.

How We Use Information

We use information to:

  • Authenticate your Shopify store
  • Operate and maintain the App
  • Display and visualize metafield and metaobject definitions and their relationships
  • Persist canvas node positions for your shop
  • Improve performance and reliability
  • Diagnose bugs and technical issues
  • Respond to support requests
  • Protect against abuse or unauthorized access
  • Comply with legal obligations, including Shopify's mandatory compliance webhooks

We do not use your information for targeted advertising.

Data Storage and Retention

The App is designed to minimize long-term data storage.

Store definition metadata retrieved from Shopify is processed as needed to provide the requested functionality and is not retained as a separate permanent copy of your store's metafield or metaobject catalog.

We retain:

  • Session and authentication data for as long as needed to keep the App installed and functional
  • Saved canvas node positions for your shop while the App remains installed (or until deleted via redaction/uninstall handling)
  • Support communications as necessary to resolve issues

The App is hosted on infrastructure provided by Fly.io. Authentication and layout data are stored in an application database used by the App.

Cookies and Similar Technologies

The App and website may use cookies or similar technologies for:

  • Authentication
  • Session management
  • Security

Browser local storage may be used for optional canvas layout settings on the device you use.

These technologies are not used to build advertising profiles.

How We Share Information

We do not sell your personal information.

We may disclose limited information only when necessary to:

  • Cloud hosting providers (including Fly.io)
  • Infrastructure and database providers
  • Professional advisors
  • Government authorities where required by law

These providers receive only the information necessary to perform their services.

Third-Party Services

The App relies on Shopify APIs and uses third-party infrastructure to operate securely and reliably.

Your use of Shopify remains subject to Shopify's own privacy policies and terms.

We are not responsible for the privacy practices of third-party websites or services.

Data Security

We use commercially reasonable administrative, technical, and organizational safeguards to protect the information we process, including HTTPS for App traffic and authenticated access through Shopify's OAuth and session mechanisms.

No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

Data Retention

We retain information only for as long as necessary to:

  • Operate the App
  • Fulfill legal obligations
  • Resolve disputes
  • Enforce our agreements

When the App is uninstalled, or when Shopify sends a shop redaction webhook, we delete session records and saved flow layout data associated with that shop where reasonably possible.

Information that is no longer needed is deleted or anonymized where reasonably possible.

Your Rights

Depending on your jurisdiction, you may have rights including:

  • Access to your personal information
  • Correction of inaccurate information
  • Deletion of personal information
  • Data portability
  • Restriction of processing
  • Withdrawal of consent where applicable

To exercise these rights, contact us using the information below. You may also uninstall the App from your Shopify admin, which ends the App's access to your store through Shopify.

International Transfers

Information may be processed in countries other than your own (including where our hosting provider operates). Where required, we implement appropriate safeguards to protect transferred information.

Children's Privacy

The App is intended for merchants, developers, and businesses. It is not directed toward children under the age of 16, and we do not knowingly collect personal information from children.

Shopify Permissions

The App requests Shopify API permissions required for its functionality, currently including scopes related to products, metaobjects, and metaobject definitions so the App can read definition data used by the canvas and support related Admin workflows.

These permissions are used exclusively to provide the features of the App and are not used for advertising or unrelated purposes.

Changes to App Permissions

If future versions of the App require additional Shopify permissions, those permissions will be requested through Shopify during installation or upgrade.

Mandatory Compliance Requests

The App implements Shopify's mandatory compliance webhooks. Because the App does not store customer personal data, customer data request and customer redaction webhooks do not require deletion of customer records from our systems. Shop redaction requests result in deletion of shop-associated session and layout data.

Contact

If you have questions about this Privacy Policy or our privacy practices, you may contact us at:

Summary

Meta Flow is designed around collecting as little information as possible.

Its primary purpose is to help merchants and developers inspect, visualize, and navigate Shopify Metafield and Metaobject definitions and their relationships. We store only what is needed for authentication and for persisting canvas layout preferences. We do not sell personal information, do not perform targeted advertising, and do not permanently store customer personal data or metafield/metaobject values on our servers.