Privacy Policy for Theme Inspector for Shopify
Last Updated: September 22, 2026
This Privacy Policy explains how the Theme Inspector for Shopify Chrome extension ("the Extension"), formerly named Shopify Theme Check, handles information. The Extension is an independent project and is not affiliated with or endorsed by Shopify Inc.
1. Information the Extension Handles
The Extension handles the following information only when a user opens or interacts with the Extension:
- Website content and browsing context from the active tab, including the page URL, theme metadata, script and asset references, app signals, social links, font names, and same-origin links.
- Website content fetched from the active website's same-origin sitemap and pages when the user explicitly starts Deep Scan.
- A Shopify store domain, client ID, and client secret entered by the user when using the optional Admin API token generator.
- The access token, scopes, and expiration information returned by Shopify.
The Extension does not collect analytics, advertising identifiers, payment information, or personal information for the developer.
2. How Information Is Used
Website content is processed to identify Shopify theme details, apps, social profiles, and fonts. Deep Scan is optional and user initiated. It requests at most 100 public pages from the active website's own origin, without cookies or login state, and never requests cart, checkout, account, order, or search pages. It pauses between requests and stops immediately if the website signals rate limiting.
When the user requests a token, the store domain, client ID, and client secret are sent directly over HTTPS to the selected store's Shopify token endpoint. Shopify returns the token directly to the Extension. This information is used only to complete the user's requested token-generation operation.
Disclosure: For apps owned by your organization and installed on stores you own. Credentials are sent directly to the selected Shopify store over HTTPS and are never saved or sent to the extension developer.
3. Storage and Retention
The Extension does not use Chrome storage, local storage, session storage, IndexedDB, cookies, or a developer-operated server to retain user information.
- Website scan results remain in memory and are discarded when the popup closes.
- Client ID and client secret fields are cleared after each token request attempt.
- Generated tokens are held only in popup memory, masked by default, and automatically cleared after two minutes or when the popup closes.
- If the user copies a token, it remains in the operating system clipboard until the user replaces or clears it. The Extension cannot control clipboard retention after copying.
4. Information Sharing
The developer does not receive website content, browsing activity, credentials, or generated tokens.
Credentials are shared only with the user-selected https://{shop}.myshopify.com/admin/oauth/access_token endpoint as necessary to perform the requested Shopify client-credentials flow. Clicking result links can open Shopify, ThemeForest, Google Fonts, or detected social-media websites in a new tab. Those websites process visits under their own privacy policies.
The popup's "Send feedback" and "Missing an app?" links open a GitHub issue form in a new tab. The "Missing an app?" form is prefilled with the inspected store's address, the apps the Extension detected, and the Extension version. Nothing is sent unless the user reviews the form and chooses to submit it on GitHub, where it is handled under GitHub's privacy policy. The "Rate it" link opens the Extension's Chrome Web Store reviews page.
When the Extension is uninstalled, Chrome opens a short feedback page on the project website. The page does not identify the user, and answering is optional.
The Extension does not sell user data or share it with advertisers, data brokers, or unrelated third parties.
5. Security
Credential requests use HTTPS. The Extension requests temporary access only to the entered myshopify.com store and removes that permission after the request. Credentials and tokens are not logged, persisted, or sent to the developer.
Users should only enter credentials for an app owned by their organization and installed on a store they own. Users should clear their clipboard after copying a token and rotate credentials if they may have been exposed.
6. Chrome Web Store Limited Use
The use of information received from Chrome APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
7. Changes to This Policy
This policy may be updated when the Extension's behavior or legal requirements change. Updates will be identified by a revised "Last Updated" date.
8. Contact
For privacy questions, open an issue at https://github.com/Atul8007/stc-website/issues.