Ironclad SEO Privacy Policy
Ironclad SEO is a Shopify app published by Sizzle (“Sizzle,” “we,” “us,” or “our”). This policy explains what information the app accesses, how we store and use it, and the choices you have. It applies to merchants who install Ironclad SEO on their Shopify store.
Ironclad SEO is an on-page SEO tool. It scans your products and collections for SEO problems (missing search titles and descriptions, images without alt text, duplicates), lets you fix them with a live Google preview, and adds structured data for rich results. Every change is previewed before it applies and can be undone in one click.
Summary
In short: Ironclad SEO works with your store's own SEO content and nothing about your shoppers. We request no customer or order permissions, so we never access shopper names, emails, addresses, or orders. Your data is stored in the United States, we use only three service providers (Neon, Netlify, and Shopify), and we run no tracking or advertising cookies. When you uninstall, your stored data is fully deleted about 48 hours later.
Information we access and store
Ironclad SEO is an on-page SEO tool, so the data it works with is your store's own catalog content and the working data needed to keep every change reversible. Specifically:
- Your store domain and a Shopify access token: used to connect securely to your store and make Shopify API calls on your behalf. The token is never shared.
- Product and collection content (titles, descriptions, images, and their SEO fields — search title, search description, image alt text), read through Shopify's API to scan for issues and to make the changes you choose. Your SEO edits are written back to Shopify's own native fields, not held in a separate copy.
- Change history (the activity log): for every change you make with the app we store the product's name, which field changed, the value before and after, and the time. This is what makes every change reversible with one click.
- SEO audit results: a record of the issues found in your most recent scan, so the app can show them to you.
Every record is scoped to your store, and it consists of your store's own catalog content and the metadata needed to organize it.
Information we do not collect
Ironclad SEO does not access, process, or store any customer or shopper personal data. The app requests no customer or order permissions from Shopify, so it has no API access to shopper names, email addresses, mailing addresses, payment details, or order records. We do not run analytics or profiling, and we do not sell or share data for advertising.
Shopify permissions we request
Ironclad SEO requests only the permissions it needs to scan and fix your store's on-page SEO, and it includes no customer or order scopes:
write_products— to read your products and update their SEO fields and image alt text.write_content— to read and update SEO fields on your store content.
How we use your information
We use the information described above only to provide the Ironclad SEO service: to scan your catalog for SEO issues, to apply the fixes you choose, to keep the activity log so every change can be undone, to power the structured data you enable, and to manage your subscription and billing status. We do not use your data for any other purpose.
Cookies and your storefront
Ironclad SEO is a standard embedded Shopify app built with Remix, Polaris, and App Bridge. It sets only the functional session cookies required by Shopify's authentication and embedded app framework. It uses no analytics, advertising, or tracking cookies.
The app is used only by you inside the Shopify admin. The structured data it can add to your storefront is a theme app embed served by Shopify — it collects no personal information about your shoppers, and Shopify removes it automatically if you uninstall.
Where your data is stored
All persistent data and processing takes place in the United States (AWS US East, us-east-1). We store your audit results and change history in a Neon Postgres database, and the application runs on Netlify.
Service providers
We keep our list of service providers small. The following third parties process data on our behalf or as part of delivering the service:
- Neon: the Postgres database that stores your audit results and change history.
- Netlify: application hosting and serverless functions.
- Shopify: the source of your store data and the processor of all billing through the Shopify Billing API.
We use no other subprocessors. There is no separate analytics, error tracking, email, advertising, or payment provider.
Billing
Billing for Ironclad SEO is handled entirely through Shopify using the Shopify Billing API (Managed Pricing). We do not use an external payment processor, and we do not receive or store your payment card details.
Data retention and deletion
While Ironclad SEO is installed, your audit results and change history are retained so the activity log and one-click undo keep working. When you uninstall the app, your session and access token are deleted immediately. Shopify then sends a shop redaction request about 48 hours after uninstall, at which point we permanently erase all remaining data associated with your store — audit results, change history, and billing state. Effective retention after uninstall is therefore about 48 hours, followed by complete deletion. You can also request deletion at any time by contacting us.
Your SEO content itself (search titles, descriptions, alt text) lives in Shopify's own native fields, so everything you fixed stays fixed after you uninstall — nothing breaks and nothing is left behind in your theme.
Shopify compliance webhooks
Ironclad SEO implements all three of Shopify's mandatory privacy webhooks:
customers/data_request: because we store no customer data, there is nothing to return. We log the request.customers/redact: no operation, since there is no customer data to redact. We log the request.shop/redact: we actively purge all stored data for the shop as described above.
Your rights
Because the data Ironclad SEO stores is your own store's SEO content and change history, you remain in control of it. You can review and undo your changes at any time inside the app, and you can trigger deletion of all your stored data by uninstalling Ironclad SEO, which leads to complete erasure about 48 hours later through Shopify's shop redaction process.
Depending on where you or your customers are located, data protection laws such as the GDPR and the CCPA may give additional rights, such as the right to access, correct, or delete personal data. Since Ironclad SEO does not collect shopper personal data, these requests are limited in scope, but you can contact us at any time and we will assist.
Security
We take reasonable measures to protect the data we store. Data is held on managed infrastructure provided by Neon and Netlify, and access is limited to the app's own functions. No method of storage or transmission is completely secure, so while we work to protect your data we cannot guarantee absolute security.
International users
Ironclad SEO stores and processes data in the United States. If you install the app from outside the United States, you understand that your store data will be transferred to and processed in the United States.
Children
Ironclad SEO is a business tool for Shopify merchants and is not directed to children. We do not knowingly collect personal information from children.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the date at the top of this page. Your continued use of Ironclad SEO after an update means you accept the revised policy.
Contact
If you have questions about this policy or how Ironclad SEO handles data, contact us atcontact@sizzle.so.