Ghostify Privacy Policy
Last updated: August 17, 2026
1. Overview
Ghostify is a Shopify app that helps merchants protect storefront content from copy actions, known spy-extension overlays, and suspicious storefront interactions. Ghostify also offers optional visitor controls, which let a merchant see the IP addresses and countries of storefront visits and turn away visits from chosen countries or IP addresses. This policy explains what information Ghostify collects, how it is used, and how it is protected.
2. Information We Collect
To operate Ghostify, we collect and process the following:
- Shopify shop domain — used to identify your store and associate your settings with your installation.
- App installation and session data — OAuth tokens and session records required to authenticate your store and maintain a working connection with Shopify.
- Merchant-selected protection settings — the protection rules you configure in the Ghostify dashboard (for example, which copy-prevention behaviors are enabled).
- Theme app embed activation status — whether the Ghostify embed block has been enabled in your Shopify theme.
- Protection event logs — records of triggered protection rules, including the rule type, timestamp, and shop domain. These logs power the activity dashboard.
- Billing subscription status — if Shopify Managed Pricing or Shopify Billing is used, we receive and store your current subscription plan status.
- Storefront visitor records — only if you enable the optional IP Tracker. When it is on, Ghostify records, for each storefront page view: the visitor's IP address, the two-letter country code resolved from that address, the URL of the page visited, the date and time, whether the visit was allowed or turned away and under which kind of rule, and a short technical code describing how the location was determined. These records power the IP Tracker, Country blocker, and IP blocker screens in your dashboard.
- Support communications — if you contact us for help, we retain the information you provide (such as your name and email address) to respond and resolve your request.
Visitor records are off by default. Nothing about storefront visitors is recorded unless you enable the Ghostify visitor controls embed in your theme and switch on the IP Tracker. Automated crawlers and bots (such as search engine indexers) are never recorded and never turned away.
3. Information We Do Not Intentionally Collect
Ghostify does not intentionally collect:
- Customer payment card data.
- Customer passwords or login credentials.
- Sensitive customer account credentials of any kind.
- City, region, or street-level location of storefront visitors. Shopify sometimes includes an approximate city and region in the request data it forwards to apps. Ghostify does not read those fields, does not decode them, does not store them, and does not display them. Only the country is read.
- Any link between a storefront visitor record and a Shopify customer account. Visitor records contain no customer ID, name, email address, phone number, or order information — an IP address identifies an internet connection, not a person or an account.
We do not sell merchant data or customer data to any third party.
4. How We Use Information
Information collected by Ghostify is used to:
- Provide and operate storefront content protection.
- Display protection status and recent protection activity in the Ghostify dashboard.
- Maintain your app installation and protection settings.
- Verify whether the Ghostify theme app embed block is active in your storefront.
- Process and display billing subscription status when applicable.
- Provide merchant support and assist with security troubleshooting.
- Show you the storefront visits recorded by the IP Tracker, and apply the country and IP rules you configure.
We do not use your data for advertising, analytics profiling, or any purpose beyond operating and improving Ghostify.
5. Sharing and Service Providers
Ghostify relies on third-party infrastructure providers — including hosting, database, monitoring, and related services — that are necessary to operate the app. These providers may process data on our behalf as part of delivering the service. We require that such providers handle data appropriately and only for the purpose of operating Ghostify.
Visitor IP addresses are not sent to anyone. Ghostify determines a visitor's country on its own servers, using an offline database file that is downloaded when the app is built. No visitor IP address is transmitted to a geolocation provider or to any other third party for lookup, at any point.
IP geolocation data is provided by DB-IP (IP to Country Lite database), used under the Creative Commons Attribution 4.0 International License. Ghostify uses this database to resolve a country code only.
We do not sell your data or your customers' data.
6. Data Retention and Deletion
Storefront visitor records are deleted automatically after 30 days. Ghostify also keeps at most the 10,000 most recent records per shop; older ones are removed when that limit is passed, even if they are younger than 30 days. You can also stop new records being created at any time by switching off the IP Tracker.
When Ghostify is uninstalled from your store, we delete the app session records, protection settings, protection event logs, visitor control settings, and all storefront visitor records associated with your shop. Shopify also sends a shop redaction request 48 hours after uninstall, which deletes the same data again as a safeguard in case the uninstall notification never reached us.
Billing records may be retained beyond uninstall only to the extent required for accounting, legal compliance, or dispute resolution purposes.
If you would like to request deletion of any data associated with your shop outside of the normal uninstall flow, please contact us at support@ghostifyshield.com.
7. Your Responsibilities as a Merchant
The visitor controls are optional and are enabled by you. When you switch on the IP Tracker, the records described in section 2 are collected from people visiting your storefront. In many jurisdictions an IP address is treated as personal data, and the obligation to inform your visitors about it — for example in your own store's privacy notice — rests with you as the operator of the store, not with Ghostify.
Because visitor records contain no customer identifier, Ghostify cannot match a request about a named individual to a specific visitor record. Requests that identify a person by name, email address, or Shopify customer account therefore cannot be resolved against these records. Deleting all visitor records for your shop is always possible: switch off the IP Tracker, uninstall the app, or contact us.
This section describes how Ghostify works. It is not legal advice, and it does not tell you what your own obligations are. If you are unsure how these rules apply to your store, please consult a qualified advisor in your jurisdiction.
8. Security
We apply reasonable technical safeguards to protect the data we store and process. Access to merchant data is limited to what is necessary to operate and support Ghostify.
No method of transmission over the internet or electronic storage is fully secure. We cannot guarantee absolute security, and we encourage merchants to contact us promptly if they have concerns about their data.
9. Merchant Rights and Contact
Depending on your jurisdiction, you may have the right to access, correct, restrict processing of, or request erasure of personal data associated with your store. To exercise any of these rights, or if you have any questions about this policy, please contact us:
Email: support@ghostifyshield.com
We will respond to requests within a reasonable timeframe.
10. Updates to This Policy
This privacy policy may be updated as Ghostify evolves or as legal requirements change. When we make material changes, we will update the date at the top of this page. Continued use of the app after an update constitutes acceptance of the revised policy.