Privacy Policy

Last Updated: May 19, 2026

Introduction

This Privacy Policy explains how Mapstore ("Mapstore", "we", "us", or "our") collects, uses, shares, and protects information when Shopify merchants install or use the Mapstore store locator application (the "App"), and when visitors interact with a storefront map powered by Mapstore.

Mapstore helps Shopify merchants publish store locations, product availability, map search, lead forms, and usage insights on their storefront. Merchants control the location, contact, product, lead form, and custom content they choose to configure in the App.

Information We Collect

Merchant Account and Shopify Store Information

When a merchant installs or uses Mapstore, we collect information from Shopify that is needed to authenticate the store, provide the App, and manage the merchant account, including:

  • Shopify shop ID and myshopify.com domain
  • Shop name and shop email address
  • Timezone, currency, and Shopify plan name
  • App installation, authentication session, access token, scope, and token expiration information
  • Subscription, billing, plan, trial, and installation status received through Shopify and Mantle

Mapstore currently requests Shopify Admin API access needed for App functionality, including read_products so merchants can connect products with store availability.

Store Location and Map Content

Merchants may manually enter, import, or sync store location records. These records may include:

  • Location name, address, latitude, and longitude
  • Phone number, email address, website URL, notes, and description
  • Business hours, filters, tags, custom fields, and display order
  • Location images, custom marker images, Google Maps URLs, and Google Place IDs
  • Google ratings, rating counts, and opening hours when Google Places features are enabled
  • Product references, such as Shopify product IDs and handles, for product availability features

Store location data is generally intended to be displayed publicly on the merchant's storefront through the store locator or product availability widgets. Merchants are responsible for ensuring they have the right to publish any personal information they enter, such as a location-specific phone number or email address.

Merchant Configuration and Uploaded Data

We store App settings and configuration selected by merchants, including map display settings, lead form configuration, custom field definitions, notification email recipients, Google API keys if supplied by the merchant, Google Sheet or CSV sync URLs, and setup progress.

If a merchant uploads a CSV file or enables Google Sheet syncing, Mapstore processes the contents of that file or sheet to create or update store locations. Temporary import and export files may be created while a job is running and are cleaned up after processing or after a short operational retention period.

Storefront Visitor Interactions

When a visitor uses a storefront map powered by Mapstore, we may process limited interaction data to return map results and provide aggregated insights to the merchant, including:

  • Search terms typed into the store locator
  • Filter selections
  • Store location clicks or "show on map" interactions
  • Product handles used to request product availability
  • Map viewport bounds when the merchant uses view-based loading
  • Postal code or location-style search terms when used to find nearby stores

These insights are associated with the merchant's shop and aggregated by event type, date, and value. They are not designed to identify individual storefront visitors.

Visitor Location Data

If a merchant enables location-based features, a storefront visitor may be asked by their browser to share location access. When the visitor grants permission, the browser provides coordinates that are used to show nearby stores, sort by distance, or display a "you are here" marker. Mapstore does not create visitor profiles from this browser geolocation data.

Depending on the merchant's map loading settings, the map viewport bounds around a visitor's current map view may be sent to Mapstore to return relevant store locations. Browser geolocation permission is controlled by the visitor's browser and device settings.

Lead Form Submissions

If a merchant enables the lead form feature, visitors may submit information through fields configured by the merchant, such as a name, email address, phone number, message, or other custom responses.

Mapstore processes lead form submissions to send them to the merchant's configured email recipients and, when configured, to trigger Shopify Flow. Mapstore does not store lead form submissions permanently in its primary database. Email providers, Shopify, and the merchant may retain those submissions according to their own settings and policies.

The merchant is responsible for its own privacy notices and legal basis for collecting personal information through lead forms on its storefront.

Support, Communications, and Operational Data

If a merchant contacts us for support, uses in-app chat, or receives App emails, we may process the merchant's name, email address, shop domain, Shopify plan, support messages, email delivery information, and related metadata.

Like most web services, our servers, hosting providers, security tools, and application logs may receive technical information such as IP address, browser or device information, request URLs, timestamps, error details, and diagnostic events. We use this information to operate, secure, debug, and improve Mapstore.

Information We Do Not Collect

Mapstore does not intentionally collect:

  • Payment card numbers or full financial account details
  • Shopify customer records, order records, or checkout data
  • Advertising identifiers for cross-site advertising
  • Storefront visitor profiles for behavioral advertising
  • Children's personal information

Mapstore responds to Shopify's mandatory customer data request and customer redaction webhooks. Because the App is not designed to store Shopify customer records, those customer-specific requests generally return no customer data.

How We Collect Information

  • Directly from merchants when they configure the App, upload files, enter locations, or contact support
  • Automatically from Shopify during OAuth installation, authentication, billing, webhooks, and Admin API requests
  • Automatically from storefront visitors when they interact with a Mapstore-powered map or lead form
  • From service providers that help us provide billing, subscription management, support, email delivery, analytics, hosting, geocoding, and map services

How We Use Information

We use information to:

  • Authenticate merchants and provide secure access to the App
  • Create, manage, import, sync, display, and export store locations
  • Show product availability for selected Shopify products
  • Geocode addresses and support map, directions, distance, and postal-code search features
  • Send transactional emails such as welcome messages, import warnings, export notifications, error alerts, and lead form submissions
  • Provide aggregated store locator usage insights to merchants
  • Manage subscriptions, billing status, plan limits, trials, and feature access
  • Provide customer support and in-app chat
  • Monitor, secure, debug, and improve the App
  • Comply with legal obligations, Shopify platform requirements, and enforce our rights

Legal Basis for Processing

Where privacy laws such as the GDPR require a legal basis, we process personal information as necessary to provide the App under our agreement with merchants, to comply with legal obligations, for our legitimate interests in operating and securing Mapstore, and, where required, with consent.

Merchants may act as data controllers for personal information they choose to collect from storefront visitors, including lead form submissions and any personal information included in store location records. Mapstore generally acts as a processor or service provider for that merchant-controlled data.

Third-Party Services and Data Sharing

We share information only as needed to provide, operate, support, secure, and improve Mapstore, or as required by law. We do not sell personal information.

Shopify

Mapstore is a Shopify app and uses Shopify for authentication, app proxy requests, Admin API access, Flow triggers, app webhooks, and platform requirements. Shopify may process merchant and store information according to Shopify's Privacy Policy.

Mantle

We use Mantle for subscription management, billing-related customer identification, plan limits, installation events, and app usage tracking. Mantle may receive merchant account details such as shop domain, shop name, shop email, Shopify shop ID, billing status, plan information, and related App events.

Plunk

We use Plunk to send transactional and onboarding emails, including welcome emails, export notifications, import warnings, error alerts, uninstall follow-ups, and lead form submission emails. Plunk processes recipient email addresses, email content, attachments when applicable, and delivery metadata.

Tawk.to

We use Tawk.to for in-app support chat. When available, we may identify the merchant in Tawk.to using shop name, shop email, shop domain, and Shopify plan so support conversations can be tied to the correct store.

Google Services

If a merchant provides a Google API key or enables Google-related features, we may use Google Maps, Google Geocoding, or Google Places APIs to convert addresses to coordinates, fetch place details, fetch business hours, or show directions links. Addresses, coordinates, place IDs, and related queries may be sent to Google for these purposes. See Google's Privacy Policy.

If a merchant configures Google Sheet syncing, Mapstore stores the sheet or CSV URL provided by the merchant and fetches the sheet contents to import or update store locations.

OpenStreetMap Nominatim and OpenFreeMap

Mapstore may use OpenStreetMap Nominatim to geocode addresses. Address queries are sent to Nominatim to obtain coordinates. See OpenStreetMap Foundation's Privacy Policy.

Storefront maps may load map tiles from OpenFreeMap. A visitor's browser may send standard request metadata, such as IP address and user agent, to the map tile provider when map tiles are loaded.

Hosting, Database, Queue, Cache, and Infrastructure Providers

We use infrastructure providers to host the App, database, cache, queues, logs, and temporary files. These providers process data as needed to run, secure, back up, monitor, and troubleshoot the App.

Legal and Safety Disclosures

We may disclose information if required to comply with law, legal process, Shopify platform requirements, enforce our agreements, protect the security of Mapstore, or protect the rights, property, or safety of users, merchants, visitors, or others.

Cookies and Tracking

Mapstore does not use storefront visitor cookies for advertising or cross-site behavioral tracking. The embedded merchant App may use cookies, local storage, Shopify App Bridge, or similar technologies for authentication, session handling, security, preferences, support chat, billing/subscription analytics, and operational diagnostics.

Third-party services such as Shopify, Mantle, and Tawk.to may set or read cookies or similar technologies when merchants use the embedded App or support chat. Merchants and visitors can control cookies through their browser settings, although disabling certain technologies may affect App functionality.

Data Retention

  • Merchant account and authentication data: retained while needed to provide the App, maintain the merchant account, comply with Shopify requirements, and satisfy legal or operational obligations.
  • Store location, product availability, map configuration, custom field, and sync data: retained while the App installation or merchant account remains active, unless deleted earlier by the merchant or through a verified deletion request.
  • Storefront usage insights: retained for up to 90 days by default, unless a different retention period is configured for the App.
  • Lead form submissions: forwarded to the merchant and not permanently stored in Mapstore's primary database.
  • Temporary import and export files: retained only as long as needed to process the file, deliver the export, or clean up failed jobs.
  • Support, email, billing, security, and application logs: retained as needed for support, accounting, fraud prevention, legal compliance, and service reliability.

When a merchant uninstalls the App, Mapstore removes active app sessions and cancels scheduled jobs. We delete shop data when Shopify sends the relevant shop redaction webhook, when required by Shopify's data protection requirements, or when we process a verified deletion request, subject to any limited retention needed for legal, security, fraud-prevention, accounting, or dispute-resolution purposes.

Security

We use technical and organizational safeguards designed to protect information, including access controls, token protection, encrypted connections where supported, secure database connections, webhook verification, job cleanup, input validation, rate-limit handling, and operational monitoring.

No method of transmission or storage is completely secure. If you believe information in Mapstore may have been compromised, contact us immediately.

International Data Transfers

Mapstore and its service providers may process information in countries other than where a merchant or visitor is located. Those countries may have different data protection laws. Where required, we use appropriate safeguards for international transfers.

Your Rights and Choices

Depending on your location and relationship with Mapstore, you may have the right to request access, correction, deletion, restriction, portability, or objection to certain processing of personal information. You may also have the right to withdraw consent where processing is based on consent.

Merchant Controls

  • Merchants can add, edit, export, or delete store locations in the App.
  • Merchants can remove product availability references from locations.
  • Merchants can disable lead forms, Google Sheet sync, optional Google features, and related settings.
  • Merchants can uninstall the App from Shopify.
  • Merchants can contact us to request account or data deletion.

Storefront Visitor Requests

If you are a visitor to a merchant's storefront and submitted information through a lead form or directly to the merchant, please contact that merchant first. The merchant controls that information. We will assist merchants with valid privacy requests where required.

California Privacy Rights

We do not sell personal information. We also do not knowingly share storefront visitor personal information for cross-context behavioral advertising. California residents may have rights to know, access, correct, delete, and limit certain uses of personal information, subject to applicable exceptions.

EEA, UK, and Similar Privacy Rights

Individuals in the EEA, UK, and similar jurisdictions may have rights to access, rectify, erase, restrict, object to processing, and request data portability. They may also have the right to lodge a complaint with a local data protection authority.

Children's Privacy

Mapstore is a business-to-business application for Shopify merchants. It is not directed to children, and we do not knowingly collect personal information from children under 13 or the equivalent minimum age in the relevant jurisdiction.

Merchant Responsibilities

Merchants are responsible for ensuring that their own privacy policies and storefront disclosures accurately explain how they use Mapstore, what information they collect from visitors, whether lead forms are enabled, and what location, analytics, support, or third-party services are used on their storefront.

Merchants should not enter sensitive personal information into Mapstore unless they have a lawful basis and appropriate safeguards to do so.

Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the "Last Updated" date above. If changes are material, we may provide additional notice through the App, by email, or by another appropriate method.

Contact Us

If you have questions about this Privacy Policy or want to exercise a privacy right, contact us at:

Email: [email protected]

For general support, visit our Help Center.


Summary for Storefront Visitors

If you are visiting a store that uses Mapstore:

  • Mapstore shows store locations and product availability configured by the merchant.
  • Your map searches, filter selections, and store clicks may be counted in aggregated merchant insights.
  • If you allow browser location access, your location is used to show nearby stores or distance information.
  • If you submit a lead form, your submission is sent to the merchant and may also be processed by Shopify Flow and email providers.
  • Mapstore does not sell your personal information or use it for advertising profiles.

The merchant operating the storefront is responsible for its own privacy practices and for any information it collects from you directly.