Privacy policy — Upfront

Last updated 11 August 2026.

Upfront audits a Shopify store’s pricing for compliance with the UK Digital Markets, Competition and Consumers Act 2024. This policy explains exactly what the app reads, what it stores, and for how long.

What we do not collect

Upfront never accesses customer data. The app requests only read_products, read_themes and read_shipping. It has no permission to read customers, orders, or payment information, and it cannot write anything to your store. We do not use cookies for tracking, and we do not sell or share data with third parties.

What we read

What we store

Only what is needed to produce and keep your audit results:

Data is held in a PostgreSQL database hosted by Railway (railway.app) in the Netherlands, within the EU, and is transmitted over HTTPS. Railway is our only processor; we share data with no one else.

Retention and deletion

Uninstalling the app deletes your session. On a shop/redact request from Shopify — sent 48 hours after uninstall — all scans and price observations for your store are deleted permanently. You can also request deletion at any time by email.

Because we hold no customer data, the customers/data_request and customers/redact webhooks have nothing to return or erase; they are acknowledged and no data changes.

Your rights

Under the UK GDPR you may request access to, correction of, or deletion of the data described above, and you may lodge a complaint with the Information Commissioner’s Office.

Who operates this app

Leon Rhein
Algierstrasse 4
8048 Zürich
Switzerland

Contact

Questions or deletion requests: alpineappsolutionsdev@gmail.com. We respond within 30 days.


Upfront is a technical audit tool, not legal advice. Its findings are indicators, not legal conclusions.