Privacy Policy
How Mindhive LLC collects, uses and protects personal information across our website, our services and our Shopify apps.
Effective date: July 25, 2026
Mindhive LLC ("Mindhive", "we", "us" or "our") is a California limited liability company with its principal place of business in San Diego, California. We build software for the Shopify ecosystem and publish applications on the Shopify App Store.
This Privacy Policy explains what personal information we collect, why we collect it, who we share it with, and the rights you have over it. It applies to our website, our client engagements, and the applications we publish. It does not apply to the websites or applications of our clients, which are governed by their own policies.
1. Information we collect
Information you give us
When you submit our contact form, subscribe to our newsletter, or correspond with us, we collect the information you choose to provide. This typically includes your name, email address, company name, an indication of budget or project scope, and the content of your message.
Information collected automatically
When you visit our website we and our analytics providers may collect technical information sent by your browser or device, including:
- IP address and approximate location derived from it
- Browser type, operating system and device characteristics
- Pages viewed, referring URL, and the dates and times of your visits
- Interaction events such as clicks and scroll depth
Information we process on behalf of clients
When we build or support a client's store, or when a merchant installs one of our applications, we may process personal information belonging to that merchant's customers — for example names, email addresses, shipping addresses and order records. We process this information only on the merchant's instructions and for the purpose of providing the service. For that data the merchant is the controller and we act as a processor or service provider.
Information from third parties
We may receive information about you from Shopify (for example, store and contact details supplied when an app is installed), from our hosting and infrastructure providers, and from publicly available business sources.
We do not knowingly collect payment card numbers. Payments for our services are processed by third-party payment providers, and card details are handled by them rather than by us.
2. How we use information
We use personal information to:
- Respond to enquiries and provide quotes or proposals
- Deliver, maintain and support the services and applications we provide
- Operate, secure, debug and improve our website and applications
- Send administrative messages about changes to our services or terms
- Send marketing communications where you have asked to receive them, or where otherwise permitted by law
- Invoice clients and maintain financial and tax records
- Detect, investigate and prevent fraud, abuse and security incidents
- Comply with legal obligations and enforce our agreements
We do not sell personal information, and we do not share personal information for cross-context behavioural advertising as those terms are defined under California law.
3. Legal bases for processing
If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — to provide services you or your organisation have engaged us for
- Legitimate interests — to operate and improve our business, secure our systems and communicate with prospective clients, where those interests are not overridden by your rights
- Consent — for marketing emails and any non-essential cookies, which you may withdraw at any time
- Legal obligation — to meet accounting, tax and regulatory requirements
5. Data handled by our Shopify applications
Our published applications request only the API access scopes they need to function, and those scopes are disclosed at install time. Where an application processes merchant or customer data, we do so as a processor acting on the merchant's instructions.
- We do not use merchant customer data to train models or to build advertising profiles
- We do not share merchant data with other merchants
- We honour Shopify's mandatory compliance webhooks for customer data requests, customer redaction and shop redaction
- On uninstall, merchant data is deleted or anonymised within the period stated in our retention section, except where we must retain it by law
Merchants who require a data processing agreement should contact us using the details below.
7. Data retention
We keep personal information only as long as necessary for the purposes described in this policy, and then delete or anonymise it. In general:
- Enquiry and contact form submissions — up to 24 months from the last contact
- Newsletter subscriber records — until you unsubscribe, plus a suppression record so we do not contact you again
- Client project records and correspondence — for the duration of the engagement and up to 7 years afterwards, for contractual, tax and audit purposes
- Application data — for the duration of the installation and up to 90 days after uninstall, unless a longer period is legally required
- Server and security logs — typically up to 12 months
8. Security
We maintain administrative, technical and physical safeguards appropriate to the sensitivity of the information we hold. These include encryption in transit, access controls and least-privilege permissions, credential management, logging, and review of the code we ship.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator where required by law.
9. International transfers
We are based in the United States and our service providers may process information in the United States and elsewhere. Where we transfer personal information out of the EEA or the UK, we rely on an appropriate safeguard such as the European Commission's Standard Contractual Clauses, together with any additional measures required.
10. Your privacy rights
EEA and UK residents
You have the right to access your personal information; to correct inaccurate information; to request erasure; to restrict or object to processing; to data portability; and to withdraw consent at any time. You also have the right to lodge a complaint with your local supervisory authority.
California residents
Under the CCPA as amended by the CPRA, you have the right to know what personal information we collect and how we use and disclose it; to request deletion; to request correction; and to be free from discrimination for exercising these rights. Because we do not sell personal information or share it for cross-context behavioural advertising, there is no need to opt out of those activities.
How to exercise your rights
Email us at privacy@mindhive.dev. We will verify your request, usually by confirming control of the email address concerned, and respond within the timeframe the applicable law requires. An authorised agent may submit a request on your behalf with proof of authorisation. If your request concerns data we process for a client or merchant, we will refer you to them and assist them in responding.
11. Children's privacy
Our website and services are intended for businesses and are not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
12. Third-party sites
Our website links to sites we do not control, including Shopify and social platforms. We are not responsible for their content or privacy practices, and we encourage you to read their policies.
13. Changes to this policy
We may update this policy from time to time. We will change the effective date at the top of this page, and for material changes we will provide additional notice — by email or a prominent notice on the website — before the change takes effect.
14. Contact us
Questions, requests or complaints about this policy can be sent to privacy@mindhive.dev, or by post to:
Mindhive LLC[Street address], San Diego, CA [ZIP], United States