Privacy & data
Protected Customer Data
Omnibus accesses no protected customer data. It reads product prices to compute the legally-required 30-day reference — and nothing about your customers or orders.
What we access
Product & variant prices (read) — the current price and compare-at price of each variant, captured when it changes (products webhook) plus a one-time backfill on install. We use these to record your price history and compute the lowest price in the last 30 days.
One product metafield (write) — we write ONE app-owned metafield (omnibus.references) holding the computed reference price per variant, which the theme block reads. We never edit your product content, price or inventory.
Scopes: read_products, write_products. That is the complete list — no order, customer, fulfillment, or financial scopes.
What we never access
No orders and no customer PII of any kind: no names, emails, phone numbers, shipping or billing addresses, IP addresses, or payment details. Omnibus never requests read_orders or read_customers. Because we hold no protected customer data, the app operates below Shopify’s Protected Customer Data Level 1 requirements.
Retention & deletion
We store only price points, computed references, app settings and billing status. On uninstall we mark the shop inactive; on Shopify’s shop/redact webhook we delete all of the shop’s rows. The customers/data_request and customers/redact webhooks are answered truthfully: we hold no customer data to return or erase.