Vetta - Privacy Policy
Last updated: 8th September, 2026
Vetta is a Shopify application operated by Runways.dev.
This policy explains what data we access, why, where it is stored, and what rights you have over it. It covers two things: the Vetta application installed on a Shopify store, and the Runways.dev website that presents it.
Part A — The Vetta application
1. What Vetta does with your data, in short
Vetta adds an approval step before content changes go live on a Shopify store. To do that, it reads the content of your store, keeps copies of it as versions, and writes approved versions back to Shopify.
Vetta does not access your customers' personal data, your orders, your payment information, or your store's financial reports. The app does not request the Shopify permissions that would allow it to.
2. Data we collect
2.1 Store data
When you install Vetta, we access, through the Shopify Admin API and the permissions you grant at installation:
- Products, collections, pages, blog articles, and their fields (titles, descriptions, SEO fields, handles, tags, metafields, media alt text)
- Translations of that content in every language enabled on your store
- Your store's enabled languages and locale settings
- Metaobject and metafield definitions used by that content
- Your store's domain, name, and basic settings
We store copies of this content in our database: a current copy used to detect changes and compare versions, plus every version that has been proposed, approved, or recorded. Version history is what the product does — it is retained until you delete the content, uninstall the app, or ask us to erase it.
2.2 App user accounts
For each person invited into Vetta, we store:
- Email address
- Display name
- Role in the app (author, reviewer, or administrator)
- The store they belong to
- Sign-in records and session identifiers
Users sign in either through a link sent to their email address, or with Google Sign-In. When they use Google, we receive their email address, name, and a Google account identifier. We never receive their password, and we request access to no other Google service.
2.3 Usage and billing data
- Which versions were proposed, approved, rejected, or restored, by whom, and when — this audit trail is a feature of the app
- Your subscription plan and credit consumption
- Server logs (IP address, request time, error traces) kept for security and troubleshooting
Payments are processed by Shopify through its billing API. We never see or store your card details.
2.4 Data we do not collect
We do not access customer records, orders, checkouts, draft orders, fulfilment data, or analytics from your store.
3. Why we process this data
| Purpose | Legal basis (GDPR) |
|---|---|
| Providing the app's features to the merchant | Performance of a contract |
| Authenticating users and securing accounts | Legitimate interest, legal obligation |
| Sending transactional emails (invitations, sign-in links, review notifications) | Performance of a contract |
| Billing and fraud prevention | Performance of a contract, legitimate interest |
| Diagnosing errors and improving reliability | Legitimate interest |
We do not sell personal data, do not share it with advertisers, and do not use your store content to train machine learning models.
4. AI agents and the MCP server
Vetta exposes an MCP (Model Context Protocol) server so that an AI assistant you choose can propose content versions inside the app.
- This connection is off until you deliberately set it up and authorise it.
- When it is active, the AI assistant you connected can read the content you expose to it and submit proposals. It is bound to the author role and can never approve, publish, or restore content.
- Content sent to an AI assistant leaves our systems and is handled by that assistant's provider under their privacy terms, not ours. Review their policy before connecting one.
- We do not send your data to any AI provider on our own initiative, and we do not use your content to train any model.
5. Where your data is stored
Your data is hosted on Google Cloud Platform in the European Union (Europe West 1). Some of our service providers may process limited data outside the EU; where they do, transfers are covered by the European Commission's Standard Contractual Clauses.
6. Service providers
We use the following processors, each bound by a data processing agreement:
| Provider | Purpose | Data involved |
|---|---|---|
| Shopify | Platform, authentication, billing | Store and installation data |
| Google Cloud / Firebase | Hosting, database, authentication | All app data |
| Resend | Transactional email delivery | Recipient email address, message content |
| Google Sign-In | Optional user authentication | Email, name, account identifier |
| Cloudflare | Website hosting and delivery for the Vetta site, and bot protection on its forms (Turnstile) | Visitor IP address, browser and request characteristics |
We do not share your data with anyone else, except where required by law.
7. Retention and deletion
- While the app is installed: content versions and audit records are retained so that history and rollback remain available.
- After uninstallation: your access tokens and sessions are deleted immediately. All remaining store data, version history, and user accounts are permanently deleted 30 days after uninstallation. Reinstalling within that window restores your history; reinstalling after it starts from an empty history.
- On request: you can ask us to delete your data at any time by writing to [email protected]. We respond within 30 days.
- Server logs are kept for 30 days, then deleted.
8. Your own customers' data
Vetta does not collect or store data about your customers. If you receive a data access or deletion request from one of your customers, it does not concern data held by Vetta. We nevertheless respond to Shopify's mandatory data request, customer redaction, and shop redaction webhooks, and confirm that no customer data is held.
Part B — The Runways.dev website
When you visit runways.dev, we process:
- Server logs, including your IP address, browser type, and the pages you requested, kept for 30 days for security and to keep the site running.
- Information you send us, if you use a contact form or write to us: your name, email address, and the content of your message. We keep it as long as needed to answer you and to maintain a record of the exchange, then delete it.
The website sets no advertising or analytics cookies, uses no third-party tracking, and does not profile visitors. We do not sell or share any of this information.
Part C — Common provisions
9. Your rights
If you are in the European Economic Area, Switzerland, or the United Kingdom, you have the right to access, correct, delete, or export your personal data, to restrict or object to its processing, and to lodge a complaint with your supervisory authority. In France, that authority is the CNIL (www.cnil.fr).
If you are a California resident, you have the right to know what personal information we collect, to request its deletion, and not to be discriminated against for exercising those rights. We do not sell or share personal information as those terms are defined by the CCPA.
To exercise any of these rights, write to [email protected]. We reply within 30 days.
10. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to authorised personnel and protected by multi-factor authentication. Roles inside the app limit what each user can see and do. Should a personal data breach occur, we notify affected merchants and the competent supervisory authority within 72 hours of becoming aware of it, as required by the GDPR.
11. Cookies
Vetta and the Runways.dev website use strictly necessary cookies only: they keep you signed in and secure your session. We set no advertising or analytics cookies and do not track you across other websites.
12. Children
Vetta is a business tool and is not directed at anyone under 16. We do not knowingly collect personal data from children.
13. Governing law
This policy is governed by the law of France, without prejudice to the protections you enjoy under the data protection law of your own country of residence.
14. Changes to this policy
We may update this policy as the app evolves. The date at the top always reflects the current version. Material changes are announced to installed merchants by email at least 30 days before they take effect.
15. Contact
Runways.dev
Email : [email protected]