Haunted Theme privacy policy
Last updated October 5, 2026
Haunted Theme is a Shopify app that reads a store's theme and public storefront pages and reports code that apps may have left behind. This policy explains what the app collects when a merchant installs it, how that information is used, and how to contact us.
What we collect
- Store details from Shopify: the store's myshopify domain and the access token Shopify issues when the app is installed. The app requests only the
read_themespermission. - Theme files: copies of the files of the live theme and of any theme the merchant chooses to scan, so that scans can be compared over time.
- Public storefront pages: the HTML of up to four public pages, to see which scripts visitors load. If the storefront has a password page and the merchant enters the storefront password in Settings, it is stored encrypted (AES-256-GCM) and used only to view those pages.
- Settings the merchant enters: email addresses for alerts, time zone, quiet hours, apps marked as still in use, and apps added to the BFCM planner.
- Feedback: when a merchant marks a finding as wrong, the finding, the reason and an optional short note.
- Usage counts: how often in-app guides are opened and support is contacted, without any personal details.
Haunted Theme does not access orders, customers, products or payment information, and it does not collect personal information about a store's customers.
How we use it
- To scan themes and storefronts and show the report inside the Shopify admin.
- To send the alerts, weekly summaries and monthly emails the merchant sets up.
- To create read-only report links when the merchant asks for one. Each link expires after 30 days and can be turned off at any time.
- To improve how findings are detected, using feedback on findings.
We do not sell this information and do not use it for advertising.
Who we share it with
- Our hosting provider, which stores the app's database.
- Our email provider (Resend), which delivers alert emails to the addresses the merchant enters.
- Anyone the merchant gives a report link to, for as long as the link is active.
How long we keep it
While the app is installed, we keep scans and theme file copies to compare them over time. When the app is uninstalled, all of the store's data is deleted after 48 hours. If the app is reinstalled within those 48 hours, the data is kept. We also respond to Shopify's data protection requests (customer data requests, customer redaction and shop redaction).
Security
Data is sent over HTTPS. Storefront passwords are encrypted before they are stored. Access to the database is limited to the app's servers.
Your rights
Merchants can change or remove their settings in the app at any time, and can ask us to access, correct or delete their data by emailing us. If you are in the European Economic Area or the UK, you have rights under the GDPR, including to complain to your local data protection authority.
Contact
Questions about this policy: davidkulpe@gmail.com