Privacy Policy
Effective September 7, 2026 · Applies to the Store Locator & Stockists app for Shopify.
Who we are
Store Locator & Stockists (“the app”) is built and operated by Conspire, a Shopify development company based in Los Angeles, California. The app lets a merchant publish a map of the stores, dealers and stockists that carry their products, and optionally which products each store has in stock. This policy explains what information the app collects, how it is used, and the choices merchants, their retailers and their shoppers have.
Information we collect
When a merchant installs the app, we collect and store:
- Store information - the store domain, store name, plan, currency and time zone that Shopify shares with apps, plus the API access token that lets the app read the store’s product catalog. The app requests only the
read_productspermission. Access tokens are stored encrypted. - Location data - the stores, dealers and stockists the merchant enters, imports from a spreadsheet, or pushes through the app’s API: business names, street addresses, opening hours, and any phone number, email address or website the merchant chooses to publish for that location. Addresses are converted to map coordinates (geocoded) so they can be shown on a map.
- Product availability - which products are stocked at which locations and, where the merchant provides it, a stock level or quantity. This includes product titles and identifiers from the merchant’s Shopify catalog.
- Staff account details - the name and email address of staff members who open the app in the Shopify admin, used for support and product-update email.
- API tokens - when a merchant creates a token so a retailer, distributor or ERP system can push locations and stock, we store only a hash of that token and the date it was last used.
Shoppers using the map
When a shopper uses the store locator on a merchant’s website, the place they type (a city or postal code) or, if they choose “Use my location”, the approximate coordinates their browser provides are sent to our servers so we can return the nearest stores. These searches are processed to answer the request and are not stored against the shopper or used to build a profile. Geolocation is only used when the shopper explicitly allows it in their browser.
Map tiles are loaded by the shopper’s browser from OpenFreeMap (OpenStreetMap data), which receives the shopper’s IP address as part of that request, as with any web resource. The app does not set advertising cookies on the merchant’s storefront.
How we use it
- Displaying the merchant’s locations and product availability on their storefront, in the app’s admin, and through the merchant’s own API tokens.
- Geocoding addresses so locations appear in the right place on the map.
- Operating the admin dashboard, imports, and support.
- Aggregate product analytics and error monitoring so we can fix problems and improve the app.
We do not sell or rent merchant, retailer or shopper data, and we do not use it for advertising.
Service providers
We rely on a small number of infrastructure providers to run the app, each processing data only on our instructions: Vercel (hosting), Neon (database), Upstash (caching), Sentry (error monitoring), Mixpanel (aggregate product analytics), and Intercom (support). Location addresses are sent to a geocoding provider (OpenStreetMap Nominatim or Mapbox) to be converted to coordinates; no shopper data is sent to those providers.
Data retention and deletion
Data is retained while the app is installed. When a merchant uninstalls, the app’s access to the store is revoked immediately and stored sessions are deleted. We honor Shopify’s mandatory privacy webhooks: customer data requests, customer data erasure, and shop data erasure are processed automatically on the schedule Shopify defines, permanently deleting the associated records. Merchants can also delete any location or product assignment from the app at any time.
You can also request deletion at any time by emailing hello@conspireagency.com.
Security
All data is encrypted in transit over HTTPS and encrypted at rest by our database provider. Shopify API access tokens are additionally encrypted at the application level before storage, and merchant API tokens are stored only as one-way hashes. Access to production systems is limited to the small team that operates the app.
Changes and contact
If we make material changes to this policy we will update this page and the effective date above. Questions and privacy requests: hello@conspireagency.com · Conspire, 145 S. Fairfax Ave, Suite 200, Los Angeles, CA 90036, US.