Privacy Policy

How Meridian handles store information

Meridian helps merchants create bundles, run controlled offer experiments, and customize storefront blocks. This page explains the limited store and storefront information Meridian processes, why it is used, and how long it is kept.

Effective March 31, 2026MeridianContact via getmeridian.app@gmail.com

Information Meridian processes

Meridian processes merchant and shop data needed to authenticate the app, connect to Shopify, provide AI customization workflows, create bundles, and measure the performance of Meridian bundle experiments.

When a merchant uses Meridian Chat, Meridian may process chat prompts, conversation history, optional reference images, customization previews, block and theme settings needed to apply changes, and related operational logs.

  • Shop and installation metadata such as shop domain, access scopes, and app session state.
  • Product and collection data needed to create bundles and other supported storefront blocks.
  • App configuration data such as block settings, theme settings, and storefront embed state.
  • AI chat inputs such as prompts, thread history, clarification answers, reference image context, and generated customization previews for blocks like bundles, buy buttons, announcement bars, sticky cart, and payment icons.
  • Storefront configuration and implementation context needed to preview, apply, or undo supported AI edits within the merchant's Shopify environment.
  • Limited order analytics for Meridian bundles: order identifier, order date, currency, order and discount totals, product and variant identifiers, quantities, and Meridian's own bundle attribution properties. Meridian uses these records to calculate bundle revenue, refunds, profit checks, and A/B-test outcomes.
  • Pseudonymous storefront experiment signals: an anonymous visitor or session identifier, experiment and variant assignment, interaction type, timestamp, and the relevant bundle/page identifier. These signals are sent only when Shopify's storefront privacy API permits analytics processing.
  • Meridian does not intentionally collect or store customer names, email addresses, phone numbers, postal addresses, full customer profiles, or raw Shopify order/web-pixel payloads for these analytics workflows.
  • AI usage counts, credit counts, billing status, and plan state used to govern access to app features.
  • Support and troubleshooting context that merchants intentionally provide through support requests sent to getmeridian.app@gmail.com.

How Meridian uses information

Meridian uses processed information to authenticate merchants, run AI chat customization flows, generate and apply supported storefront edits, measure AI feature usage, calculate bundle and experiment performance, monitor service health, and respond to support requests.

Meridian uses the minimum data reasonably required for those workflows. Meridian does not sell customer data and does not request protected customer identity fields such as name, email, phone, or address. Order data is used only for merchant-facing bundle analytics and experiment decisions.

Sharing and subprocessors

Meridian may share data with infrastructure and service providers that help operate the app, such as hosting, database, queueing, analytics, AI, and Shopify platform services. Data is shared only as needed to provide the service, secure the product, or comply with legal obligations.

Where screenshots or files are created through Shopify-managed storage, those merchant-owned assets remain subject to the merchant's Shopify environment and controls.

Retention

Meridian applies automated retention periods to data stored in its application database. Guide sessions expire within 7 days, completed/failed capture jobs expire after 30 days, and inactive chat/customization records expire after 90 days.

Raw storefront session and interaction records expire after 90 days. Raw order facts expire after 400 days, which supports the merchant's 365-day dashboard view. Active A/B tests receive a temporary retention hold so they cannot lose evidence before a decision is made.

Completed analytics ingest jobs expire after 7 days; permanently failed jobs expire after 30 days. Aggregate daily dashboard metrics are retained while the merchant remains installed because they do not contain visitor or session identifiers.

Security

Meridian is intended to encrypt data in transit using HTTPS/TLS and to rely on encrypted-at-rest controls provided by its production hosting and storage providers. Access to protected operational data should be limited to authorized personnel with a business need to know.

Meridian also uses access controls, scoped Shopify permissions, and operational logging to reduce unnecessary exposure of store and merchant data.