Last updated 25 July 2026
The short version. VLink stores your store's products and the content of the page you build, so it can render that page. It never sees your customers' payment details, because checkout happens in your own Shopify checkout. Its page analytics are daily totals only — no cookies, no IP addresses, no visitor profiles. The only personal data it ever stores about a shopper is what that shopper types into a contact form you chose to add.
This policy describes the VLink app for Shopify ("VLink", "we"), published by
Vergenerd Ltd. It applies to merchants who install VLink and to visitors of the
public pages VLink renders at vergr.app/l/<handle>.
For the purposes of the GDPR, the merchant is the data controller for their store and page data; Vergenerd Ltd acts as a data processor on the merchant's instructions.
| Data | Why | Kept for |
|---|---|---|
| Store domain, store name, currency, and the API access token Shopify issues at install | To identify your store and to read your catalog on your behalf | Until you uninstall |
| Product title, handle, description, vendor, type, image URL, variant prices, SKUs and inventory counts | So your page renders instantly without calling Shopify on every visit, and so prices and stock stay correct | Until you uninstall, or the product is deleted or unpublished |
| Your page content: blocks, text, images you upload, colours, fonts and settings | It is the page. Without it there is nothing to render | Until you delete it or uninstall |
| Daily totals: page views, link clicks, cart adds, checkouts started, per block | To show you which parts of your page work | Until you uninstall |
| Contact-form submissions ("leads"): name, email, message, and phone if given | Only collected if you add a contact form block. They are your leads and only you can read them | Until you delete them or uninstall |
| Your subscription tier | To apply your plan's limits. Billing itself is handled by Shopify | Until you uninstall |
| Sales attribution (only if order tracking is enabled for your store): the date, the order total, the currency, and which block on your page the sale came from | To show you which part of your page actually earns money, rather than only which part gets clicked. No buyer details are stored — see below | Until you uninstall |
read_customers permission.read_orders permission and is
deliberately built to keep nothing personal: for each order we store only a date, a
total, a currency code, and the id of the block that earned it. We do not store buyer
names, email addresses, postal addresses, phone numbers, line items or order numbers.
The order number is hashed one way and used solely so that a repeated delivery of the
same notification is not counted twice — never as a way to look the order up.VLink pages set no tracking cookies. Two items are written to the browser's own local storage, both functional:
If you add your own marketing pixels (Meta, TikTok, Google) to your page, VLink shows a consent bar and loads nothing until the visitor accepts. If they decline, no pixel is loaded. Those pixels are then governed by the privacy policy of the provider you chose, and by your own.
If you use the catalog feed, VLink publishes a feed of your products at a URL containing your page handle. It contains product information only — title, description, price, availability, image and link. It contains no personal data. Anyone with the URL can read it, which is what lets Meta, Google and TikTok fetch it. Treat the URL as public.
We do not sell data and we do not share it for advertising. It is processed by:
europe-west1) — hosting and database;You can export your leads to CSV at any time from the app, and delete any page, block or lead yourself.
VLink implements Shopify's mandatory privacy webhooks, so deletion is automatic:
shop/redact, sent by Shopify 48 hours
after uninstall) — your store record, page, product cache, statistics and leads are
permanently deleted.customers/redact) — any contact-form
lead matching that customer's email or phone is permanently deleted.customers/data_request) — we respond with
any data held for that customer, which in practice is contact-form submissions or nothing.To exercise any right directly, or to ask what is held, email support@vergr.app. We reply within 30 days.
Encrypted in transit and at rest. All traffic is served over HTTPS. Everything stored is held in Google Cloud Firestore and Cloudflare R2, both of which encrypt data at rest by default; we operate no unencrypted storage of our own.
Access tokens are stored server-side and are never sent to a browser. Admin requests are authenticated with short-lived Shopify session tokens, and every incoming webhook is verified against its HMAC signature before it is acted on. API keys, if you create any, are stored only as a one-way hash and are shown to you once at creation — we cannot recover one, and neither could anyone reading our database.
We keep the minimum needed to run the app, for as long as you use it, and no longer:
We process the data above only to provide VLink to you: to build and serve your page, to keep your catalog and stock accurate, and to report your own statistics back to you. We do not sell it, we do not share it for advertising, we do not use it to train anything, and we do not use it to make automated decisions about any individual. If we ever needed it for a new purpose, this policy would change first.
VLink is a business tool and is not directed at children under 16.
If this policy changes materially we will update the date above and notify merchants in the app. Continuing to use VLink after a change means accepting it.
Vergenerd Ltd — support@vergr.app
A separate Data Processing Agreement covers our role as your processor under UK GDPR and EU GDPR, including the sub-processors listed above.