1. Who we are

Gridtiva (“Gridtiva”, “we”, “us”) is a Shopify application operated by Franzsheskoli Carlos Cabrera Toribio, a self-employed business owner established in Spain.

Operator Franzsheskoli Carlos Cabrera Toribio
Spanish tax ID 60549467N
Registered business address Carrer de l'Avellaner 57, Matadepera 08230
Contact for privacy matters support@gridtiva.com
Website https://gridtiva.com

For the purposes of the EU General Data Protection Regulation (GDPR), we act as a data processor on behalf of the merchant who installs Gridtiva. The merchant is the data controller for the store data Gridtiva processes on their instruction.

Where we hold contact and account details about the merchant themselves (see section 3.1), we act as a data controller for that limited set of information.

The Article 28 terms that govern our role as your processor are set out in full in the Data Processing Addendum. It applies automatically from the moment you install Gridtiva and does not need to be signed.

We are established in Spain, within the European Union, so no representative under Article 27 GDPR is required. We have not appointed a Data Protection Officer, because none of the conditions in Article 37(1) GDPR applies to this service: our core activities do not consist of processing that requires regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data. The address above is the contact point for all data protection matters.

2. Scope

This policy covers the Gridtiva Shopify app and the website at gridtiva.com. It does not cover Shopify itself, whose handling of your data is governed by Shopify’s own policies.

3. What data Gridtiva processes

Gridtiva requests exactly three Shopify access scopes:

  • read_metaobject_definitions
  • read_metaobjects
  • write_metaobjects

Gridtiva does not request, and therefore cannot access, customer records, orders, products, inventory, payments, or any other store data outside metaobjects.

3.1 Store and installation information

When you install Gridtiva, Shopify provides — and our hosting platform stores — a record of your shop. This record includes information such as your .myshopify.com domain and primary domain, store name, store contact email, customer-facing contact email, store phone number, store owner name, store postal address (street, city, province, country, postal code), store coordinates, timezone, currency, primary locale, and Shopify plan name.

We use this only to identify your installation, to scope all data to your store, and to support you. We retain it for as long as Gridtiva is installed. See section 6.

3.2 Session information

We store an authenticated session record linking your Shopify session to your store, so that the embedded app can verify who is making a request. Session records are deleted when the app is uninstalled.

3.3 Metaobject definitions and entries

When you open Gridtiva and select a metaobject definition, we read that definition and its entries from the Shopify Admin API and display them in your browser.

These reads are not stored in a Gridtiva database. They are fetched on demand for display and are discarded when you close or reload the app.

3.4 Change history and undo snapshots

This is the one place where Gridtiva durably stores your store’s content, and we state it plainly.

When you apply a change, Gridtiva records, for every edited cell:

  • the metaobject definition type;
  • the metaobject entry identifier;
  • the field key and field type;
  • the value before your change and the value after your change , each up to 5,000 characters;
  • timestamps and a verification status;
  • counters describing how many entries and cells were requested, verified, conflicted, failed, or not applied.

We store this for two stated purposes only: to show you a verified history of what was actually written, and to make Undo possible.

Retention: 30 days. The window is fixed in the software and is not configurable. A scheduled job runs hourly and permanently deletes expired records. The retention window is additionally recorded on each stored row so that it can be audited.

We do not store an aggregated copy of your metaobject data, and we do not copy entries you have not edited.

3.5 Subscription and plan information

To determine whether your store is on the Free or Paid plan, Gridtiva queries the Shopify Partner API for the active subscription your store holds for Gridtiva.

We read only whether an active contract exists, its plan identifiers and billing period, and whether a plan change is pending. We do not read, receive, or store payment amounts, card details, bank details, invoices, or any payment instrument. All payment processing is performed by Shopify. This subscription check is not stored in a Gridtiva database; it is read at the moment it is needed.

3.6 Technical logs

Our hosting platform records operational logs for the app. Gridtiva’s own log entries are deliberately written to contain identifiers, phase codes, timings, and counts — not merchant field values, and not access tokens or secrets.

Platform-level log retention is set by Gadget, which does not publish a fixed period; its policy states that it keeps information “no longer than is required or permitted”. We do not state a number here that we cannot stand behind. If you need a retention commitment for your own records, ask us and we will obtain it from Gadget in writing.

3.7 The gridtiva.com website

This website uses no analytics, no cookies, no tracking pixels and no third-party scripts. It is a set of static pages. Nothing on it is loaded from another domain, so no third party is able to observe your visit. We set no cookies, so no cookie banner is needed.

Our web host will process the technical information any web server receives in order to serve a page, such as your IP address, in its own server logs. That processing is governed by the host named in section 7.

4. What Gridtiva does not do

  • We do not access customer records, orders, products, or inventory.
  • We do not sell, rent, or share your data with advertisers.
  • We do not use your store data to train machine-learning models.
  • We have no AI feature.
  • We do not export your data to CSV or to any third-party destination.
  • We do not process payments or handle payment credentials.
  • We carry out no automated decision-making or profiling within the meaning of Article 22 GDPR. Nothing Gridtiva does produces a legal or similarly significant effect on any individual.
  • We do not enrich, combine or cross-reference your data with data from any other source.

5. Legal bases (GDPR)

Processing Basis
Reading and writing metaobjects on your instruction Performance of a contract (Art. 6(1)(b)); processing on the controller’s documented instructions (Art. 28)
Storing change history and undo snapshots for 30 days Performance of a contract, and our legitimate interest in providing a verifiable, reversible editor (Art. 6(1)(f))
Storing your store and contact details Performance of a contract (Art. 6(1)(b))
Checking your subscription status Performance of a contract (Art. 6(1)(b))
Operational logging and security Legitimate interest (Art. 6(1)(f))

6. Retention and deletion

Data Retention
Change history and undo snapshots 30 days, then permanently deleted by a scheduled job. Deleted immediately on uninstall.
Session records Deleted immediately on uninstall.
Store record Retained while installed. On uninstall the record is kept only so that a reinstall can restore your installation. On Shopify’s shop/redact request — sent approximately 48 hours after uninstall, provided the app has not been reinstalled — every stored field of the store record is erased.
Sync and compliance-request records Deleted immediately on uninstall, and again on shop/redact.
Metaobject definitions and entries Not stored.
Subscription status Not stored.

Shopify mandatory compliance webhooks

Gridtiva implements all three:

  • customers/data_request — Gridtiva stores no customer data, so there is nothing to provide. The request payload is discarded and is never persisted.
  • customers/redact — Gridtiva stores no customer data, so there is nothing to erase. The request payload is discarded and is never persisted.
  • shop/redact — Gridtiva erases the store’s change history and snapshots, sessions, sync records and compliance records, and clears every stored field of the store record. If the store has reinstalled Gridtiva in the meantime, the live installation is deliberately left untouched.

7. Sub-processors

Sub-processor Role Location
Gadget Inc. Application hosting, database, background job execution and logging for the Gridtiva app Canada and the United States
Cloudflare, Inc. Authoritative DNS for gridtiva.com, and hosting, delivery and TLS termination for this website. Website visitors only; no merchant data reaches it, and it is not used by the Gridtiva app, which runs inside your Shopify admin Global anycast network — no single region

Gadget publishes its own sub-processors and their locations in its privacy policy at gadget.dev/privacy. We do not reproduce that list here, because a copy would go out of date without notice; the authoritative version is Gadget’s own.

No region is stated for Cloudflare because there is not one to state. Cloudflare serves this website from whichever of its edge locations is closest to the visitor; naming a single country would be inventing a fact. Its own data protection terms and published sub-processor list govern that processing, which concerns website visitors only — no merchant metaobject data passes through it.

Shopify is not our sub-processor, and we do not list it as one. We do not engage Shopify to process data on our behalf: you already have your own relationship with Shopify, and Shopify is the source and the destination of the data Gridtiva reads and writes. Shopify’s handling of your store data is governed by your agreement with Shopify.

No other sub-processor is used. If an email provider, analytics provider, or support desk is later introduced for the website or for support, this table will be updated before that provider is used, and merchants will be given at least 30 days’ notice as set out in the Data Processing Addendum.

8. International transfers

Yes, your data leaves the European Economic Area. We say so plainly rather than leaving it to be inferred from section 7.

Gadget, the platform that hosts Gridtiva, states that data it collects may be transferred to and stored in Canada and the United States. Transfers are made under the mechanisms in our agreement with Gadget: the European Commission’s adequacy decision for Canada, and for the United States the EU–US Data Privacy Framework adequacy decision and, where that is unavailable or does not cover a given recipient, the Standard Contractual Clauses adopted under Article 46(2)(c) GDPR.

If a mechanism we rely on ceases to be available, we will move to another lawful mechanism or stop the transfer, and we will say so here.

9. Security

  • All Gridtiva data is scoped to a single store; the software enforces this on every read and every write, and refuses any request whose store identity does not match.
  • The browser never supplies the store identity; it is resolved server-side from the authenticated Shopify session.
  • Access tokens and secrets are held by the hosting platform and are never written to logs, never returned to the browser, and never included in error messages.
  • Every write is preceded by a fresh read and followed by an explicit verification; a write that cannot be verified is reported as unconfirmed rather than as a success.

10. Your rights

Under GDPR you may request access, rectification, erasure, restriction and portability, and you may object to processing.

Because Gridtiva acts as a processor for store content, requests about that content should normally be directed to the merchant who controls the store. For data we hold as a controller (section 3.1), or to exercise any right, contact support@gridtiva.com.

We rely on consent for nothing, so there is no consent for you to withdraw. Where we rely on legitimate interests (section 5) you may object at any time, and we will stop unless we can demonstrate compelling legitimate grounds that override your interests.

Providing the store and account information in section 3.1 is not a statutory requirement, but it is necessary for us to provide Gridtiva: Shopify supplies it as part of installing any app, and without it we cannot identify your installation or scope your data to your store.

You also have the right to lodge a complaint with a supervisory authority. In Spain this is the Agencia Española de Protección de Datos (AEPD), www.aepd.es. You may also complain to the authority where you live or work.

11. Children

Gridtiva is a business tool. It is not directed at, and must not be used by, anyone under 16.

12. Changes

We may update this policy. Material changes will be reflected in the “Last updated” date above and, where the change is significant, announced on gridtiva.com.

13. Contact

Franzsheskoli Carlos Cabrera Toribio
Carrer de l'Avellaner 57, Matadepera 08230
support@gridtiva.com