App Review Documentation
GuardianStack - Shopify App
Last Updated: 5 March 2026
1. Product Summary
GuardianStack is a Shopify app that helps UK merchants identify compliance gaps and complete practical remediation workflows.
Core outcomes:
- Detect likely compliance gaps from store configuration and policy surface data.
- Map findings to relevant UK obligations.
- Provide step-by-step remediation support and downloadable evidence outputs.
2. Install and Access Flow
- Merchant installs GuardianStack via Shopify.
- OAuth authorisation is completed in Shopify.
- GuardianStack stores the encrypted access token server-side.
- Merchant enters onboarding context and can run scans/workflows.
No OAuth tokens are exposed to frontend clients.
3. Required Access and Why
GuardianStack requests read access needed for compliance analysis. Typical scope categories include:
- Orders and customer metadata (for retention/compliance workflow logic)
- Products/content/pages
- Script tags and store configuration signals
Scope rationale:
- To detect data-processing footprint and policy/compliance mismatches.
- To generate action plans tied to real store state.
4. Data Handling and Retention
GuardianStack stores operational app data including:
- Shop/account identifiers
- Scan outputs and action metadata
- Generated artefacts needed for merchant re-download/audit support
Customer personal data storage is limited to workflows that explicitly require it (for example retention exports), and governed by published retention periods.
Reference: https://guardianstack.com/legal/privacy
5. Third-Party Processors
Current sub-processors are published at:
https://guardianstack.com/legal/subprocessors
6. Uninstall and Data Deletion Behaviour
When the app is uninstalled:
- Connection is marked inactive.
- OAuth token is deleted under the documented schedule.
- Data deletion obligations are handled through documented processes and webhook flows.
Reference: https://guardianstack.com/legal/privacy
7. User-Facing Legal and Support Links
- Terms: https://guardianstack.com/legal/terms
- Privacy: https://guardianstack.com/legal/privacy
- Sub-processors: https://guardianstack.com/legal/subprocessors
- FAQ: https://guardianstack.com/legal/faq
- Changelog: https://guardianstack.com/legal/changelog
- Support: support@guardianstack.com
8. Known Boundaries
- GuardianStack provides compliance guidance software, not legal advice.
- Merchant remains responsible for legal compliance decisions.
This App Review Documentation is effective as of 5 March 2026.
