Melt (“we”, “our”, or “us”) operates the Melt Shopify application and the meltsecurity.com website. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
When a visitor interacts with a Shopify store that has Melt installed, we collect the following anonymous behavioral telemetry:
Collected data is used exclusively to:
We do not sell, share, or disclose this data to any third parties, advertising networks, or data brokers.
Telemetry data is retained for a maximum of 90 days from the date of collection, after which it is permanently deleted. Merchants may request early deletion at any time by contacting us at support@meltsecurity.com.
Melt fully supports Shopify’s mandatory GDPR webhook requirements:
Melt does not use cookies. Our telemetry script uses sessionStorage to count page views within a single browser session; this data is not persisted beyond the session and is never transmitted to a third party.
Merchants who install Melt provide an email address for weekly report delivery. This email is stored securely and used only to send Melt intelligence reports. It is never shared with third parties.
All data is transmitted over HTTPS and stored in an encrypted database. Access is restricted to authorised personnel only. Webhook requests from Shopify are verified using HMAC-SHA256 signatures to prevent spoofing.
We may update this Privacy Policy from time to time. Material changes will be communicated to merchants via email or in-app notification. Continued use of the app after such changes constitutes acceptance of the updated policy.
For any privacy-related questions or requests, contact us at:
support@meltsecurity.com