Permissions Policy

Last updated: July 2, 2026

This page explains exactly what permissions ShopMaxxing requests — both the Shopify store data we access and the browser capabilities we use — and why. Our guiding principle is least privilege: we ask for the minimum needed to run the app, and nothing more.

1. Shopify Access Scopes

ShopMaxxing requests these Shopify Admin API scopes during installation:

Aside from the product and theme write access above, all scopes are read-only, and any change is made only when you explicitly approve it. Theme changes are only ever saved to a draft you publish yourself.

2. Browser Permissions

ShopMaxxing runs embedded inside the Shopify Admin. It does not request access to any sensitive browser capabilities. We send a restrictive Permissions-Policy HTTP header that explicitly disables:

3. Framing & Embedding

ShopMaxxing is designed to load only inside the Shopify Admin. Our public pages set X-Frame-Options: DENY and a Content-Security-Policy that prevents them from being embedded by other sites, protecting against clickjacking.

4. Data Handling

For full details on what we collect, how it's used, and how to request deletion, see our Privacy Policy.

5. AI Features (AI Studio)

AI Studio is an optional, opt-in feature. It only runs when you explicitly click to analyze a product, a photo, or your store. When you do:

6. Contact

Questions about permissions or data access? Contact us at support@bgstudios.app.


© 2026 ShopMaxxing. All rights reserved. · Privacy Policy