Privacy policy
Last updated 19 July 2026.
This policy describes what the Mendvale Shopify app collects, where it is stored, how long it is kept, and what happens when you uninstall. It is written to be read, not skimmed past, and it describes what the software actually does.
What we collect, and why
- Your shop domain and an API access token, provided by Shopify when you install the app. This is how the app talks to your store at all.
- Storefront scan results: the pages our crawler tested, the accessibility rules that failed, and short HTML snippets of the failing elements, so we can show you exactly where each problem is.
- Product catalog metadata: product titles, image URLs, and existing image alt text, read through Shopify's Admin API, so we can find images with no alt text.
- Drafted and approved alt text: the descriptions our vision model drafts, any edits you make, and the record of what was approved and published. Nothing is written to your store without your explicit approval, one image at a time.
- Accessibility statement details: if you generate a statement, we store the business name and contact email you type, and the exact rendered document, as a dated record that is never edited after the fact.
- An email preference: whether you have opted out of operational email.
What we never collect
The app never requests access to your customers or orders. Its Shopify permissions cover products, files, and reading themes. Your customers' personal data is not visible to Mendvale at all.
This website sets no cookies and runs no analytics or trackers.
Product images and the vision model
To draft an image description, the product image is sent to Anthropic's Claude API for processing. Our instructions to the model explicitly forbid transcribing personal data visible in an image, and an automated gate rejects drafts containing email addresses or long digit sequences before a human ever sees them. Drafts that fail this gate are retried or abandoned; abandoned images are shown to you for a human-written description instead.
Operational email
The app emails your shop's contact address about events on your store: first scan results, a detected regression, or a check we could not complete. Never marketing. Every email carries a one-click unsubscribe link, and opting out stops all of it. Email is delivered through Resend and processed in the EU.
Where your data lives
Application data is stored in a PostgreSQL database hosted by Neon in Frankfurt, Germany, and the application runs on Fly.io in Frankfurt. Data is processed in the European Union.
Retention and deletion
When you uninstall the app, Shopify sends us a deletion request, and everything we hold for your shop is erased in a single transaction: statements, scans and their findings, catalog audits, alt text drafts, preferences, and access tokens. This is the mandated GDPR flow and it is tested against the real database.
Your rights
You can ask us what we hold about your shop, ask for it to be corrected, or ask for it to be deleted without uninstalling, by writing to support@mendvale.com. Uninstalling the app triggers deletion automatically as described above.
Changes
If this policy changes, the date at the top changes with it, and material changes will be announced inside the app before they take effect.