Clarmit ("the App", "we", "us") is a Shopify application operated by Apexa Tech AB ("the Company") that provides AI-assisted translation and translation-quality monitoring for Shopify merchants. This Privacy Policy explains what information the App accesses and processes when a merchant installs and uses Clarmit, and how that information is used, shared, retained, and protected.
This policy applies only to the Clarmit Shopify app. It does not apply to the merchant's own store, Shopify's platform, or other applications the merchant may install. Those services are governed by their own privacy policies.
1. Information We Access and Collect
When a merchant installs Clarmit and grants the requested permissions, the App accesses the following categories of information solely to provide the translation and translation-quality monitoring features enabled by the merchant:
- Store content for translation — product titles and descriptions, collection titles and descriptions, page and article content, product variant option names and values, navigation menu labels, shop policy text, and SEO metadata such as meta titles and descriptions for the resources the merchant chooses to translate.
- Store configuration — the store's enabled languages and locales, including information available through Shopify Markets and language settings, used to determine available translation targets.
- Merchant and shop information — the shop domain and basic Shopify account or shop identifiers needed to authenticate the App session and associate App data with the correct store.
- Support requests — if a merchant submits a message through the App's Support form, we collect the message content and the contact email address provided by the merchant, solely to respond to and manage the support request.
We do not intentionally access or collect Shopify customer records, order data, or payment information. Clarmit accesses and processes store-content fields only to the extent necessary to provide its translation and translation-quality monitoring functionality.
2. How We Use Information
- To scan store content and detect fields that are missing a translation, out of date, or have been overwritten after translation.
- To generate AI-assisted translation suggestions based on source content selected by the merchant.
- To allow the merchant to review and approve AI-generated translations before they are written back to the Shopify store.
- To write merchant-approved translations back to the store through the Shopify Admin API.
- To maintain a translation memory consisting of source text and its approved translation, so that identical or reusable text does not need to be translated repeatedly, reducing cost and improving consistency.
- To respond to support requests submitted through the App.
- To operate, maintain, secure, troubleshoot, and improve the reliability and performance of the App.
3. Legal Basis for Processing
Where applicable, including under the EU/UK General Data Protection Regulation (GDPR), we process personal data on the following legal bases:
- Performance of a contract — to provide the App's translation, monitoring, and support functionality requested by the merchant.
- Legitimate interests — to operate, secure, troubleshoot, maintain, and improve the App, where our interests are not overridden by applicable privacy rights.
- Legal obligations — where processing is necessary to comply with applicable laws or regulatory requirements.
4. Data Controller and Processor Roles
Depending on the nature of the data and the processing activity, Apexa Tech AB may act as either a data controller or a data processor.
For information relating to the merchant's direct relationship with Clarmit, such as support communications and information required to operate the App, Apexa Tech AB generally acts as the data controller.
To the extent Clarmit processes store content on behalf of a merchant, the merchant may act as the controller and Apexa Tech AB may act as the processor, subject to applicable data protection terms and agreements.
5. Third-Party Service Providers
We use selected third-party service providers to operate Clarmit. We share only the information reasonably necessary for each provider to perform its service. Where applicable, these providers act as processors or sub-processors on our behalf.
- Anthropic (Claude API) — selected store content is sent to Anthropic's Claude API to generate translation suggestions. We use Anthropic's commercial API services. According to Anthropic's current commercial privacy terms, commercial API inputs and outputs are not used to train Anthropic's models by default, unless the customer explicitly provides feedback or opts in to training.
- Resend — used to deliver transactional emails, including support-request notifications submitted through the App's Support form.
- Shopify — Clarmit operates within the Shopify platform and communicates with Shopify's APIs to read store content, access relevant store configuration, and write merchant-approved translations back to the store.
- Cloud hosting and database providers — used to host the App and securely store information required to operate the service, including translation memory, scan records, and App configuration.
We do not sell store content, translation data, or support-request information to third parties. We do not use this information for advertising or cross-site tracking.
Translation memory is associated with the relevant merchant store and is used to provide translation functionality for that store. It is not intentionally shared with other merchants.
6. International Data Transfers
Some of our service providers may process data outside the European Economic Area (EEA). Where personal data is transferred outside the EEA or another jurisdiction with applicable transfer restrictions, we rely on appropriate safeguards required by applicable data protection law, such as an adequacy decision or Standard Contractual Clauses, where applicable.
7. Data Retention and Deletion
- Translation memory — source text and its approved translation are retained while the App remains installed so that translations can be reused and previously translated content can be matched.
- Scan records — records associated with a store resource or field are removed when the underlying resource or field is deleted and this has been confirmed through the Shopify Admin API.
- Support requests — support-request records are retained only for as long as reasonably necessary to handle and resolve the request, unless a longer retention period is required by law.
- App uninstall — when you uninstall the app, it immediately stops accessing your store and your session is removed. Shopify then sends us a data erasure request for your store; when we receive it, we permanently delete the data we hold for your store, including scan records, translations, translation memory, glossary entries, usage logs, and any support messages. The timing of that request is determined by Shopify, not by us. You can also contact us at any time to request erasure.
8. Cookies and Tracking
Clarmit runs embedded inside the Shopify Admin. Merchant authentication and session management are handled using Shopify's App Bridge and session-token mechanisms.
Clarmit does not use advertising cookies, third-party tracking cookies, or cross-site tracking technologies for its translation functionality.
9. Data Security
We use appropriate technical and organizational measures designed to protect the information processed by Clarmit against unauthorized access, alteration, disclosure, or destruction.
- HTTPS/TLS encryption is used for data transmitted between systems.
- Access to production systems and production data is restricted to authorized personnel and service processes that require such access.
- Access is managed according to least-privilege principles where reasonably practicable.
10. Your Rights
Depending on applicable law and jurisdiction, including under the EU/UK GDPR, individuals may have rights regarding personal data we process, including the right to:
- request access to personal data;
- request correction of inaccurate or incomplete data;
- request deletion of personal data;
- request restriction of processing;
- object to certain processing activities; and
- where applicable, receive personal data in a portable format.
Requests relating to data processed by Clarmit can be submitted using the contact details below. We may need to verify the identity and authority of the person making a request before responding.
Where applicable, individuals may also have the right to lodge a complaint with their competent data protection supervisory authority.
11. Children's Privacy
Clarmit is a business tool intended for Shopify merchants. It is not directed at children and is not knowingly designed to collect personal information from children.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the App's functionality, our data-processing practices, or applicable legal requirements.
The "Last updated" date at the top of this page will indicate the most recent revision. Where required by applicable law, we will communicate material changes to affected merchants.
13. Contact Us
If you have questions about this Privacy Policy or how Clarmit handles data, please contact:
Apexa Tech AB
Email:
info@apexatech.app