Privacy policy
Shopify Shark browser extension & website · Last updated: July 27, 2026
This policy explains what Shopify Shark (the Chrome extension built by Hyper Cavs Studio, “we”, “us”) does with information when you use it, and what our website does. “You” is the person running the extension or visiting this site. The extension is a tool for Shopify store owners, operators and researchers: it tells you whether the page you have open is a Shopify store, and which third‑party apps that store appears to use.
This is the core of Shopify Shark, so we want to be precise. When you open the extension on a tab, two things happen, in very different places:
All of this is information that is already public on the webpage. Anyone who visits the same page in any browser can see the same markup and the same script hostnames. We do not extract anything private or hidden from the page — no form contents, no account data, no cookies.
Our server uses those three fields only to do a read‑only match against our app library and to return the matching app names and icons. The server does not crawl or browse the store itself. The page URL may also be placed in an aggregate, de‑identified queue that we use to keep our app library up to date; it is not linked to you or to any account.
One‑time consent. Because detection sends the page data above to our server, the extension asks for your agreement once, the first time you detect apps, before any request is made. The dialog lists exactly what is sent and links to this policy. If you agree, later detections proceed without asking again; if you decline, no detection request is sent. You can revoke this at any time by clearing the extension's stored data in Chrome.
What is never sent, now or ever: your name, email address or Google account; your login credentials, passwords, cookies or session tokens; your browsing history on other sites; anything you type into forms; and any payment information.
Shopify Shark can also read a store's public product and collection listings (the same data Shopify publishes at /products.json and /collections.json) so you can export them to CSV. Those requests go directly from your browser to the store you are viewing, not through our server, and the resulting files are saved to your own computer. We do not receive or store the products you export.
You do not need an account to use app detection or export. Signing in with Google is optional and is used only to manage an optional Premium licence. When you sign in, Google shares your email address with us so we can check and issue your licence; we never receive your Google password. If you never sign in, we never receive an email address from the extension.
We do not sell your information. We share information only with the small set of vendors that host and run the service (for example our server and payment processor), under obligations of confidentiality, and only as needed to provide the service. We may also disclose information where required by law, court order, or to protect our rights and safety, or in connection with a merger or sale of the business (in which case the same privacy obligations transfer).
You can clear the extension's stored data (preferences, consent and any local cache) at any time from Chrome's extension settings, and you can uninstall the extension to remove it entirely. Data held on our server for the app library is aggregate and not tied to you. Where we do hold personal information (for example a signed‑in email), we keep it only as long as needed for the purpose above, and you may email us to request access, correction or deletion; we will respond within 30 days.
Detection requests travel over HTTPS, and our server sits behind Cloudflare. Payment processing is handled by PCI‑compliant vendors using encrypted (SSL) transactions. Account passwords, where they exist, are stored encrypted and are not visible to us. No system is perfectly secure; if a breach materially affects you we will notify you as soon as we reasonably can and describe the corrective action taken.
The extension and website are not directed at children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with information, contact us and we will delete it.
When we change this policy we post the new version here and update the “Last updated” date above; material changes are also surfaced in the extension. Changes apply to information collected after they take effect. If you object to a change within 20 days of posting, the change will not apply to information we already hold about you, though we may then be unable to keep providing the affected feature.
If you have any questions about this policy, or want to access, correct or delete information we hold, contact us at [email protected].