Maxima privacy policy
Last updated: 13 September 2026
Maxima is a Shopify app that recommends and runs pricing experiments. This policy describes the information we collect when you install the app, how we use it, and how to contact us.
Shopify APIs we use
After you install Maxima, we use the Shopify Admin API with these scopes: write_products, read_inventory, and read_orders. We also receive Shopify webhooks for products, inventory, orders, billing, uninstall, and the mandatory compliance topics. We do not request protected customer data.
Information we collect
- Shop identity Shopify provides: myshopify domain, shop id, timezone, currency, and shop owner email
- Catalog and sales history: products, variants, inventory quantities, and order line items
- Pricing decisions: opportunities, experiments, measurement windows, and an audit log of price changes
- An encrypted Shopify offline access token used to sync the catalog and write authorized prices
- App usage events such as onboarding and experiment lifecycle, used to operate the service
Customer personal data
Maxima does not store customer names, emails, phone numbers, or addresses. Order records keep Shopify order and line ids, quantities, and amounts only. We do not drop cookies or pixels on the merchant's storefront. A Shopify customers/data_request therefore has no customer personal information to return. A customers/redact request is recorded for audit and does not leave residual customer PII.
How we use this information
We use shop and catalog data only to provide Autonomous Pricing: sync the catalog, recommend experiments, write prices you authorized, measure results, and bill through Shopify. We do not sell this information or use it to advertise to a merchant's customers.
Retention
We keep shop data while the app is installed. Uninstalling pauses Autonomous Pricing, stops running experiments, and reverts treatment prices where possible. After Shopify sends shop/redact, we delete the shop, credentials, catalog, orders, experiments, jobs, and events for that store.
Subprocessors
We host the app and database on infrastructure providers (currently Fly.io and managed Postgres). Optional error monitoring (Sentry) processes limited operational data when configured. Shopify processes identity, billing, and store data under its own terms.
International transfers
Servers may be located outside your country. Where we transfer personal data, we rely on the safeguards required by applicable law, including Shopify's platform terms for data received through its APIs.
Your rights
Merchants can access or correct shop settings in the app, uninstall to stop processing, and email us to ask what we store about their shop. After shop/redact, the shop record is deleted. Shopify also sends mandatory compliance webhooks that we honor.
Contact
Privacy questions: hello@trymaxima.com