This policy is for merchants who connect a Shopify or WooCommerce store to Modestly. It explains exactly what the app reads, why it needs it, and what happens to it if you disconnect or uninstall. If you are a shopper rather than a brand, the policy you want is our main privacy policy, which also carries our full company registration details.
Who is responsible
You remain the merchant of record for your own store. For the data we read out of it, you are the data controller and Modestly v/Sehit Emir Degirmenci acts as your processor — we handle it on your instructions, for the purpose of listing your products on Modestly, and for nothing else.
For orders placed by shoppers on Modestly, we are the controller, because those are our own customers buying through our marketplace.
What we access
When you connect a store, you approve a specific, limited set of permissions. We read:
- Your products: titles, descriptions, images, categories, options, variants, SKUs and prices.
- Your stock: inventory counts and the locations they are held at, so we can stop selling something you have run out of.
- Your store’s identity: the shop domain, and a secure access token that lets us keep reading the above.
- Orders and fulfilments: for orders that Modestly itself sent to your store — so we can pass on the shipping details you need and record when you have shipped them.
We do not read your existing customer list, your marketing data, your Shopify billing, your themes or your apps. We do not use your product data to train models, and we do not sell it to anyone.
Why we need it
The whole point of the app is that you do not maintain a second catalogue. Your store stays the source of truth: when you change a price, edit a piece or sell one, Modestly follows. That is only possible if we can read the catalogue and the stock, and it is why those two permissions are not optional.
Order and fulfilment access exists so a Modestly sale reaches you where you already work, instead of in a separate dashboard you have to remember to check.
Where it is stored
Your data is stored in the European Union. Access tokens are encrypted at rest and are never shown in the Modestly interface, never written to our logs, and never sent to your browser.
Who else sees it
We use a small number of service providers to run Modestly. Each is bound by a data-processing agreement and may only use the data to provide their service to us:
- Vercel — hosting and content delivery.
- Supabase — our database, hosted in the EU.
- Stripe — payments and your payouts. Card numbers go to Stripe directly; we never see or store them.
- Resend — transactional email, such as an order notification.
- Sentry — error monitoring, so we can find faults.
- PostHog — product analytics, hosted in the EU and only with consent.
We do not share your store’s data with other brands.
Disconnecting and uninstalling
You can disconnect your store at any time, from Settings in your brand portal or by uninstalling the app in Shopify. When you do:
- Your pieces come off Modestly immediately — shoppers stop seeing them.
- We stop reading your store. No further products, prices or stock levels are collected.
- Your catalogue records are archived, not deleted, so that reconnecting later brings your listings straight back rather than making you start again.
Shopify then sends us a formal erasure request about 48 hours after an uninstall. On receiving it we delete your store’s connection outright: the encrypted access token, the shop identity, and the record of which person connected it. The archived catalogue is retained at that point, because it is our record of what was listed on our marketplace and is bound up with orders we are legally required to keep under Danish bookkeeping law.
If you would like the archived catalogue removed as well, email us and we will do it — see below.
Requests from your customers
If one of your Shopify customers asks you to export or erase their data, Shopify forwards that request to us and we act on it for you.
We review these by hand rather than deleting automatically, deliberately. A Modestly order can involve several brands and belongs to a Modestly account, so erasing records because one store was named risks destroying another brand’s order history and a shopper’s own account. Every request is logged when it arrives and answered within the statutory deadline.
Security
- Connecting a store uses Shopify’s own approval flow. We never ask for your Shopify password.
- Access tokens are encrypted at rest and scoped to the permissions you approved.
- Every message we accept from your store is cryptographically verified before it is processed, so nobody can impersonate your shop.
- Only a brand owner can connect or disconnect a store.
Contact
Email modestlyeu@gmail.com for anything on this page — a copy of what we hold about your store, deletion of your archived catalogue, or a question before you install. You also have the right to complain to your local data protection authority; in Denmark that is Datatilsynet.
If we change this policy we will update the date at the top of the page, and tell you in the brand portal if the change affects what we collect.

