SpotMetal Privacy Policy
SpotMetal Technologies ("SpotMetal", "we", "us", or "our") is committed to protecting the privacy and security of merchants, store administrators, and customers. This Privacy Policy describes how we collect, store, process, and protect information when you install or use the SpotMetal application ("App") from the Shopify App Store.
1. Information We Collect
When you install and authorize the SpotMetal App via Shopify OAuth, we collect and process specific categories of data necessary to provide live precious metal pricing and trade-in workflows:
A. Merchant & Store Data
- Shop Information: Store primary domain, myshopify.com URL, store name, email address, store owner name, country, currency, and timezone.
- Product & Inventory Data: Product IDs, variant IDs, SKU codes, pricing, inventory quantities, and custom precious metal metafields (metal type, karat purity, gram mass, labor fees, and minimum price floor bounds).
- Configuration Settings: Custom pricing formulas, weight brackets, margin spreads, and API feed preferences.
B. Customer Scrap Buyback & Appraisal Data
When store visitors submit scrap jewelry or bullion appraisal requests through the SpotMetal Storefront Buyback Widget (App Proxy), we collect:
- Customer contact details: Full name, email address, phone number, and physical mailing address (for trade-in shipping kits).
- Item specifications: Metal type, estimated karat fineness, gram weight, photographs (if uploaded), and appraisal valuation estimates.
2. How We Use Collected Information
We use the data strictly for legitimate operational purposes:
- Live Spot Price Synchronization: Calculating variant prices continuously based on global market feeds (XAU, XAG, XPT, XPD) and writing updates to your Shopify catalog via Shopify GraphQL Admin API.
- Formula Valuation: Executing mathematical markup equations, karat multipliers (8K–24K), tiered weight brackets, and hard margin floor safeguards.
- Trade-In Order Management: Processing customer scrap buyback requests, creating shadow appraisal items with
BB-*SKUs, and generating official Shopify Draft Orders for merchant payouts. - Service Communication & Auditing: Sending critical rate sync alerts, subscription updates, and maintaining immutable audit log records.
3. Data Protection & Security (AES-256 Encryption)
We implement industry-leading technical and organizational security measures:
- Encryption at Rest: All proprietary custom market data provider API keys and sensitive tokens are encrypted using AES-256-GCM with unique 96-bit Initialization Vectors (IV).
- Encryption in Transit: All communications between Shopify, our application servers, and external rate feeds are encrypted using TLS 1.3.
- Access Controls: Role-based access controls, continuous vulnerability scans, and strict database isolation per store partition.
4. Mandatory Shopify GDPR Webhook Compliance
SpotMetal is fully compliant with Shopify's mandatory data protection and GDPR requirements. Our servers automatically process the following statutory webhooks in real time:
1. customers/data_request
When a customer requests a copy of their stored data from the merchant, SpotMetal packages all trade-in appraisal records associated with that customer ID and securely delivers them to the merchant within statutory timeframes.
2. customers/redact
When a customer requests erasure of their personal data, SpotMetal immediately purges all customer names, emails, phone numbers, and addresses from our buyback order tables.
3. shop/redact
48 hours after an app uninstall event, SpotMetal permanently and irreversibly deletes all stored store records, product cache, formulas, audit logs, and settings from our database.
5. Third-Party Service Providers
We only share data with essential third-party infrastructure providers necessary to operate the App:
- Shopify Inc.: Platform hosting, OAuth authentication, GraphQL API, and App Billing.
- Market Data Providers: European Central Bank (ECB), Edelmetalle.de, GoldAPI.io, Metals-API (rates are ingested anonymously without transmitting merchant or customer identifiers).
- Cloud Infrastructure: PostgreSQL database hosting in secure SOC 2 Type II certified data centers.
6. Your Rights (GDPR & CCPA/CPRA)
Depending on your jurisdiction, you and your store customers hold the following legal rights regarding personal data:
- Right to Access: Request a full copy of the data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete records.
- Right to Erasure ("Right to be Forgotten"): Request complete deletion of your data.
- Right to Restrict Processing: Request suspension of data processing under certain circumstances.
7. Contact Information
If you have any questions, privacy inquiries, or wish to exercise your data rights, please contact our Data Protection Officer: