Privacy
Current tool mode: CSVs selected in the review tool are processed in your browser tab only. The tool does not transmit or store their contents. Paid onboarding and server-side CSV intake are disabled. Do not submit customer, order, payment, or other personal or sensitive data. The notice below also describes possible future/paid service processing; those features must not be used until provider and transfer details are published.
# LocaleDelta Privacy Notice
**Effective:** Upon publication
## Who is responsible
LocaleDelta is the trading name used by Localization change monitor for Shopify stores (“we”). This notice covers our CSV-based localization change-monitoring pilot, account and billing administration, and service communications. We act as a controller/responsible party for account and service administration data. For personal data in a merchant’s submitted file, we generally act as processor/service provider on that merchant’s instructions; the merchant is responsible for its collection and lawful use. Our Data Processing Addendum describes that relationship.
## Information we handle
We aim to collect only what is needed: (1) account and communications data such as name, business name, email, plan, subscription status, and support messages; (2) billing records such as plan, amount, currency, payment status, transaction references, and required accounting records; (3) submitted product/localization exports and necessary comparison fields such as product identifiers, language, source text, and translations; and (4) limited technical or security logs if collected by the service or its hosting provider. Payment-card details should be entered only with the checkout provider; do not send card data to us.
The pilot does not need Shopify passwords, customer lists, or store admin access. Remove unnecessary columns. Do not submit customer, order, payment, health, identity, authentication, or other sensitive personal data. We do not use submitted content to train general-purpose AI models. The CSV pilot does not promise automatic translation. If you use a translation provider under your own account or key, that provider’s own privacy terms apply.
## Uses and legal bases
We use account and communication data to respond, provide the Service, administer subscriptions, prevent misuse, secure operations, and meet legal duties. Depending on law, the basis is contract or pre-contract steps, legitimate interests in operating and securing the Service, consent where required, or legal obligation. We use submitted files only to provide the requested report, protect the Service, and meet legal duties, on the customer’s instructions. We do not sell personal information or use it for targeted advertising.
## Retention
We retain submitted CSV files and reports only as needed to prepare and return the report, then delete them within 30 days after delivery or end of paid service, whichever is later. We will act on a reasonable earlier deletion request unless law requires retention. Residual backups, if any, are overwritten or deleted within 90 days, protected, and not restored except for disaster recovery. Account and support records are retained while service is active and up to 24 months after it ends, unless longer retention is required for tax, accounting, disputes, or law; we retain only what is needed.
## Sharing and service providers
We do not sell or rent personal information. We may share necessary data with providers supporting hosting, security, payment, email, or administration, professional advisers, and public authorities where legally required. Payment providers may collect payment details directly under their own notices. Operational providers have not yet been selected or documented. Before accepting customer files or payments, we will identify relevant providers, roles, and locations in the Service provider information. If that information is not available, do not send files or pay. Providers may not use submitted content for their own independent purposes. We may disclose data to protect people, the Service, or legal rights, or in a business transfer with appropriate safeguards.
## International handling and security
The Service may be operated in a country different from yours. Before accepting files, we will identify provider locations and put in place an applicable transfer safeguard, such as an adequacy decision or approved contractual clauses, where required. We respect POPIA and other local cross-border rules. Do not submit files until provider and transfer details are available.
We will apply access controls, limit personnel access to those who need it, protect file transfer and storage using appropriate technical measures, and follow the retention schedule. No internet service can promise absolute security. If a personal-data incident occurs, we will investigate, contain it, and notify customers, people, or authorities as required by applicable law. Use a secure submission route and minimize data.
## Rights
Depending on where you live, you may have rights to access, correct, delete, object to or restrict processing, receive a copy, withdraw consent, or complain to a regulator. POPIA provides applicable access, correction, and objection rights. GDPR/UK GDPR provides rights including access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority. US state residents may have applicable rights to know/access, delete, correct, portability, and opt out of sale, targeted advertising, or certain profiling. We do not sell personal information or use it for targeted advertising and will not unlawfully discriminate for exercising a right.
To exercise a right, reply to the service or support email used for your order. We may verify identity and clarify the request. For information in a merchant’s file, contact the merchant first; we will assist the merchant where required. We respond within applicable legal deadlines. You may also complain to the relevant privacy regulator.
## Children, cookies, changes, contact
The Service is a business tool, not directed to children; do not submit children’s data. This notice does not assert use of optional analytics or advertising cookies. If used, cookie details and required consent choices will be provided before use; essential technical storage may be used to provide or secure a requested service. We may update this notice and communicate material changes through the Service or account contact route. For privacy questions or requests, reply to the service/support email used for your order. Do not send personal data until current provider and contact details are shown on the Service page.