Privacy Policy
Last updated: July 28, 2026
Who We Are
GMC Checker ("we," "us," or "our") operates gmccheck.com and the GMC Checker Shopify app. We provide storefront compliance scanning and a Google Merchant Center recovery workflow.
Information We Collect
- Information you provide — your store URL, email address, account details, and information you provide when using the Service.
- Public storefront content — when you request a scan, we crawl pages that are publicly accessible, including product, policy, navigation, and structured-data pages.
- Connected Shopify data — when you connect Shopify, we process the product and content data needed to provide the connected workflow.
- Google Merchant Center data — when you connect Google Merchant Center, we process the account, issue, product-status, feed-health, and reporting data needed for the diagnosis you request.
- Usage and technical data — device, browser, IP address, pages viewed, and event or error information used for security, analytics, and service improvement.
How We Use Information
- To run scans, generate reports, and provide diagnosis, fix proposals, and guidance.
- To operate accounts, process payments, provide support, and send transactional email.
- To improve and secure the Service using aggregated or de-identified information where practicable.
- To meet legal obligations and prevent fraud, abuse, and security incidents.
Shopify Admin Access and Merchant Approval
The connected agent can read and, only after your approval, write to your Shopify store through the Shopify Admin API. It can edit product metadata and create or edit store pages, including policy pages. Before a change is applied, the Service presents a proposed change for your review; no Shopify write is executed until you approve that proposal.
The Shopify app requests these Admin API scopes: read_products, write_products, read_content, and write_content. The read scopes let the Service inspect relevant product and content data. The write scopes are used solely for merchant-approved product and content changes.
Google Merchant Center Access
We request Google's Merchant Center content OAuth scope after your consent. We use it to read the Merchant Center data needed for connected diagnosis. We do not use that access to create, edit, delete, or upload Merchant Center products, feeds, campaigns, or account settings.
GMC Checker's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, use it for advertising, or use it to train AI models.
Third-Party Services
We use the following live services to operate GMC Checker:
- Google — Merchant Center OAuth and APIs for connected diagnosis.
- Shopify — the Shopify app platform, Admin API connection, and Shopify managed pricing.
- Clerk — account authentication and user management.
- Polar — one-time Store Fix Plan payment processing.
- Neon — database services for scan, account, connection, and case data.
- Trigger.dev — background processing for free scans.
- Vercel AI Gateway — AI-assisted analysis, summaries, and agent responses. We do not send OAuth tokens to model providers.
- Resend — transactional email delivery.
- PostHog — product analytics and diagnostics, not advertising.
- Vercel and Vercel Analytics — application hosting, deployment, and web analytics.
Sharing and Transfer
We share information with the providers above only as needed to operate, secure, maintain, and improve the Service. For example, our infrastructure providers process the records required to host the application, store scan and account data, and run background jobs; payment providers process payment details; and AI providers process the content supplied for the requested analysis. We do not intentionally send OAuth tokens, complete raw Google API responses, or complete Merchant Center exports to analytics providers.
We may also disclose information where required by law or where reasonably necessary to protect users, GMC Checker, or the public from fraud, abuse, or security threats. We do not share information with advertisers, data brokers, or information resellers for their independent use.
Data Retention and Security
We retain data for as long as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. You may request deletion of your account data by contacting us. We use TLS in transit, encrypt sensitive credentials at rest, and restrict access to systems and credentials needed to operate the Service.
Cookies
We use cookies and similar technologies for authentication, session management, interface preferences, and analytics. We use PostHog and Vercel Analytics to understand usage, detect errors, and improve reliability. We do not use third-party advertising cookies.
Your Choices
- You may revoke Google access through your Google Account permissions.
- You may disconnect Shopify or uninstall the Shopify app.
- You may request access to or deletion of personal data we hold about you.
- You may unsubscribe from non-essential email communications.
Changes to This Policy
We may update this policy from time to time. We will post the revised version on this page and update the date above.
Contact Us
Questions about this policy can be sent to info@gmccheck.com.