Data Protection

Security, retention, and merchant transparency

This page describes Meridian's operational posture for data minimization, retention, encryption, and merchant transparency for AI customization, bundles, and A/B experiments.

Effective March 31, 2026MeridianContact via getmeridian.app@gmail.com

Data minimization

Meridian processes only the information needed to authenticate the merchant, deliver AI customization, apply storefront changes, run bundle experiments, and provide merchant-facing revenue and performance reporting.

Meridian's current policy is to avoid requesting direct customer identity fields unless a feature genuinely requires them and the access has been reviewed.

Meridian does not collect or store protected customer identity fields such as name, email, phone, or address in its normal analytics workflows.

For bundle analytics, Meridian processes limited order-level fields (order identifier/date, totals, discounts, line items, product/variant identifiers, quantities, and Meridian attribution properties) plus consent-aware pseudonymous experiment events. Raw Shopify payloads and merchant-defined line-item properties outside Meridian's own namespace are not persisted.

Retention controls

Meridian runs a scheduled retention sweep every 6 hours. Guide sessions expire within 7 days, completed/failed capture jobs and unapplied generated-image records expire after 30 days, and inactive chat/customization records expire after 90 days.

Raw storefront session, touch, and experiment-event records expire after 90 days. Raw order facts expire after 400 days to support the 365-day merchant dashboard. Completed ingest envelopes expire after 7 days and permanently failed envelopes after 30 days.

An active A/B experiment receives a rolling 90 days retention hold so its evidence, refunds, and safety checks remain available until the test has ended. Aggregate daily metrics remain while a merchant is installed; they do not retain visitor or session identifiers.

Encryption and access control

Meridian's operational expectation is that production traffic is encrypted in transit with HTTPS/TLS and that production databases and storage providers apply encryption-at-rest controls.

Access to operational data should be restricted to authorized staff and service accounts that need the data to run, secure, or support the product.

  • Scoped Shopify permissions are used to limit access to store resources.
  • Background jobs and worker endpoints require authenticated internal requests.
  • Expiry columns are indexed and cleanup runs in bounded batches to avoid broad database scans.

Merchant transparency

Meridian should disclose what data it processes and why through merchant-facing documentation such as the privacy policy, app listing materials, and in-product support resources.

Merchants can contact Meridian for privacy questions or deletion assistance. Shopify customer and shop-redaction webhooks remove applicable Meridian-held data when received.