Last updated September 8, 2026
Qurata Privacy Policy
Qurata helps Shopify merchants create and measure product styling recommendations. This policy explains the information Qurata processes when a merchant installs the app or a shopper interacts with the Complete the Look widget.
Information we process
We process the merchant's store domain, authorized Shopify session, product catalog, variants, inventory status, product images, and styling configuration. For performance analytics, we record widget impressions, product clicks, styled-look expansions, and successful add-to-cart events.
When Shopify reports a paid order, Qurata immediately discards customer identity, addresses, contact information, payment information, and unrelated order fields. We keep only the product variant, quantity, price, currency, and cryptographically hashed cart, order, and line-item references needed to attribute revenue without identifying the shopper.
Purposes and legal basis
We use this information only to provide catalog analysis, outfit recommendations, storefront rendering, fraud and abuse prevention, service operations, and merchant-facing performance and revenue attribution. Storefront analytics are collected only when Shopify's Customer Privacy API indicates that analytics processing is allowed.
Service providers and international processing
Qurata uses Shopify to operate the app, Google Cloud to host and secure the service, and OpenAI to analyze merchant-provided product content and create optional styled-look images. Customer identity and order information are not sent to OpenAI. These providers may process data in countries other than the merchant's or shopper's country under their applicable contractual and security safeguards. We do not sell personal data or use it for advertising.
Retention and deletion
Pseudonymous attribution events are retained for up to 400 days. Successful background-job records are retained for 30 days, failed-job records for 90 days, and rate-limit counters for 7 days. Shopify sessions and tenant-owned data are deleted when Shopify sends the mandatory shop-redaction request. Merchants may also contact us to request access, correction, or deletion where applicable.
Security
Data is encrypted in transit using HTTPS/TLS and at rest using Google Cloud encryption. Production secrets are stored in Google Secret Manager, access is restricted by service identity, order references are keyed hashes, and Shopify webhook signatures are verified before processing.
Contact
Questions or privacy requests can be sent to support@qurata.app.