Privacy Policy for Goodspring Keel
Version 2026-09-24. Goodspring Keel is a product of Goodspring LLC, Iowa, United States. Contact: hello@good-spring.com.
This policy says what Goodspring Keel collects, why, how long it is kept, and how it is deleted.
1. The short version
Keel reads product data: titles, identifiers, categories, attributes, images and prices. It does not read, store or process shopper personal information. It does not read orders, customers, carts or checkouts, and it does not ask for the Shopify scopes that would allow it to.
Keel uses a store's data only to provide Keel to that store.
2. What Keel collects
Product data from the merchant's store. Product and variant records and the fields Keel checks: title, description, vendor or brand, category, category attributes, GTIN, MPN, SKU, price, availability, images and their alt text, and the structured data published on the product page. Keel stores these so it can compare one scan to the next and show what changed.
Storefront observations. For the pages it is asked to read, the structured data on the page, the robots.txt file, and whether the read succeeded, was partial, or was refused. A refused or partial read is recorded as unknown; it is never recorded as a pass.
Merchant Center data, where the merchant connects an account. See section 4.
Account and operational data. The store domain, the plan, the installation and uninstallation dates, billing records held by Shopify, support correspondence, and the product-analytics events that record which parts of the app were used.
What Keel does not collect. Shopper names, email addresses, shipping addresses, payment details, order contents, browsing behaviour, or any other shopper personal information. Keel has no use for it and does not request access to it.
3. Why Keel holds it, and for how long
| Category | Purpose | Retention |
|---|---|---|
| Product data and scan results | run the checks; show change over time | while installed; deleted within 30 days of uninstall |
| Storefront observations | evidence behind a finding | while installed; deleted within 30 days of uninstall |
| Snapshots of changed fields | the 30-day undo | 30 days from the change, then deleted |
| Merchant Center item statuses | map a reason to the field that fixes it | until disconnect or uninstall, then deleted |
| Account and billing records | operate the service; meet tax and accounting duties | as long as the law requires |
| Support correspondence | answer and follow up | 24 months |
| Product-analytics events | see which parts of the app are used | 24 months, in a form not tied to a product |
4. Google Merchant Center data
Connecting a Google Merchant Center account is optional, and Keel works without it.
What Keel accesses. With the merchant's authorization, and only through the scope the merchant grants, Keel reads the product statuses in the merchant's own Merchant Center account and the reasons Google gives for them, together with the feed's price and availability for the comparison against the product page.
A note on the scope. Google publishes one scope for this data, and it carries both read and write access; there is no read-only form of it. Keel uses it only to read. Keel does not write to Merchant Center, does not submit or modify feeds, and does not change any account setting there.
How Keel uses it. Each status and reason code is stored with the product it refers to, so the app can name the Shopify field that would resolve it. That is its only use.
How Keel shares it. It is not shared. It is not sold, not disclosed to any third party, and not used for advertising or for training any model, and it is never combined with another store's data (section 5).
How long Keel keeps it. Until the merchant disconnects the account or uninstalls the app. Disconnecting from the app's settings revokes the token and deletes the stored statuses.
5. One store's data serves that store
Data from a store that installs Keel is used only to provide Keel to that store. Keel does not combine one store's data with another's to benchmark, rank or compare stores, and it does not use one store's data to shape what another store sees. Store-level data is never sold, shared or published.
6. AI-assisted suggestions
Keel can suggest a product's category and its category attributes. To make a suggestion, Keel may send the product's text from the merchant's store (its title, description and existing attributes) to an AI model provider acting on Goodspring LLC's instructions. The provider processes that text only to return the suggestion, under terms that forbid using it to train or improve its models.
A suggestion is only a suggestion: nothing is written to the store until the merchant has reviewed and confirmed it. Keel never asks an AI model for a barcode, GTIN, MPN or brand; those come only from the merchant, from a file the merchant supplies, or from the manufacturer. Keel never uses merchant data to train, fine-tune or improve any AI model.
7. Sub-processors and where data sits
Keel runs on infrastructure operated by third parties acting on Goodspring LLC's instructions: Shopify, for the platform and billing; Supabase, for the database; Fly.io, for the application and its background jobs; Vercel, for the grader's website; and, for suggestions only, an AI model provider (section 6). Data is processed in the United States. A current list is available at hello@good-spring.com, and it is updated before a new sub-processor is used.
Tokens and credentials are encrypted at rest. Each store's data is isolated from every other store's at the database level.
8. Deletion, and the privacy webhooks
Keel honours Shopify's mandatory privacy webhooks:
customers/data_request: Keel holds no shopper personal information, and responds saying so.customers/redact: no shopper data is held, so there is nothing to redact; the request is logged and acknowledged.shop/redact: everything Keel holds for that store is deleted.
Independently of a webhook, uninstalling deletes the store's data within 30 days.
Corrections Keel wrote to the merchant's own product data are the merchant's data and stay in the merchant's store; deleting Keel's records does not revert them.
9. A merchant's rights
A merchant may ask what Keel holds about their store, ask for it to be corrected, ask for it to be deleted, or ask for a copy in a portable form. Write to hello@good-spring.com, and Keel acts on the request within 30 days. Data-processing terms are available on request for merchants who need them.
10. Changes
Goodspring LLC may change this policy. The version date at the top changes with it, and a material change is notified in the app before it takes effect.
11. Contact
Goodspring LLC, hello@good-spring.com.