Permissions Policy
Last updated: July 2, 2026
This page explains exactly what permissions ShopMaxxing requests — both the Shopify store data we access and the browser capabilities we use — and why. Our guiding principle is least privilege: we ask for the minimum needed to run the app, and nothing more.
1. Shopify Access Scopes
ShopMaxxing requests these Shopify Admin API scopes during installation:
- read_orders — to count fulfilled orders for XP, streaks, milestones, and matchmaking scores. We store counts and per-order totals, not full order details.
- read_customers — to detect new vs. returning customers for XP. We store only an opaque Shopify customer ID for repeat detection — never names, emails, or addresses.
- read_checkouts — to support checkout-related progress metrics.
- read_products — to count how many products your store has (for onboarding badges and milestones), and, when you use AI Maxxing, to read the specific product's title, description, SEO fields, price, and image so our AI can review and rewrite them. Product content is sent to our AI provider only when you click to analyze that product — see section 5.
- write_products — only used by AI Maxxing to apply an AI-suggested change after you review it and click Apply or Use this photo. This covers product text (title, description, or SEO fields) and product photos: a generated photo is added to the product and, when it replaces the photo it was built from, that original photo is removed from the listing. We never change product content automatically; every change is initiated by you and is logged. Text changes can be reverted in one click; photo changes are applied to your media library, so review each photo before you use it.
- read_themes — used by the Storefront Designer to read your current theme so the AI can design a matching storefront look (palette, typography, homepage layout).
- write_themes — used by the Storefront Designer to save a design only to a draft copy of your theme, which you review and publish yourself. We never edit or publish your live theme automatically.
Aside from the product and theme write access above, all scopes are read-only, and any change is made only when you explicitly approve it. Theme changes are only ever saved to a draft you publish yourself.
2. Browser Permissions
ShopMaxxing runs embedded inside the Shopify Admin. It does not request access to any sensitive browser capabilities. We send a restrictive Permissions-Policy HTTP header that explicitly disables:
- Camera and microphone
- Geolocation
- Payment request and USB device access
- Motion sensors (accelerometer, gyroscope, magnetometer)
- Ad-targeting interest groups (Topics / FLoC)
3. Framing & Embedding
ShopMaxxing is designed to load only inside the Shopify Admin. Our public pages set X-Frame-Options: DENY and a Content-Security-Policy that prevents them from being embedded by other sites, protecting against clickjacking.
4. Data Handling
For full details on what we collect, how it's used, and how to request deletion, see our Privacy Policy.
5. AI Features (AI Studio)
AI Studio is an optional, opt-in feature. It only runs when you explicitly click to analyze a product, a photo, or your store. When you do:
- We send store data only to our AI provider, Anthropic (Claude): the product's title, description, SEO fields, price, and public image URL, or — for the store report — your product catalog and aggregate sales totals.
- We never send customer data — no names, emails, addresses, or individual order details are included in any AI request.
- Results are cached in our database so a page reload doesn't re-run the analysis. You can regenerate any result at any time.
- Anthropic processes these requests to generate your results and does not use them to train its models. See Anthropic's privacy policy at anthropic.com/legal/privacy.
- When you use the optional photo enhancer, we send that specific product's public image to Google (Gemini) to generate one or more improved versions (up to four at once), and we send each generated image back to Anthropic (Claude) to check that it still shows the same product before we show it to you. It is store content only, never customer data. A generated image is added to your product only after you review it and click to use it, and when it replaces the photo it was built from, that original photo is removed from the listing.
6. Contact
Questions about permissions or data access? Contact us at support@bgstudios.app.
© 2026 ShopMaxxing. All rights reserved. · Privacy Policy