Privacy Policy
Last updated: 21 September 2026
CostSonar reads product and inventory data from your Shopify store so it can tell you which products sell below cost, and keeps a record of cost changes that Shopify itself does not keep. It does not read or store your customers’ personal data.
Who operates this app
CostSonar is operated by Marimon Apps, based in Spain. For anything in this policy, contact us through the app’s Shopify App Store listing.
What the app reads from your store
When you install it, you grant two read-only permissions: read_products and read_inventory. Those are the only scopes the app requests, and both are read-only: the app never writes to your store.
Through them it reads:
- Product and variant titles, SKUs and status
- Selling prices
- Inventory item unit costs and their currency
What the app stores
Everything stored is tied to your store domain and is never mixed with another store’s data:
- Your store domain and the access token Shopify issues at install, so the app can talk to your store.
- The last known cost of each inventory item. This is required to detect changes: Shopify’s webhooks never send the previous value.
- A record of each cost change: the item, the old and new cost, the currency and the date. This is the app’s reason to exist — Shopify keeps only the current cost.
- The result of each catalogue scan: how many variants were checked and which ones were below cost, missing a cost, or on a thin margin.
- Your alert preference (on or off), and a log of alerts: the subject line, how many products it covered, and whether it was sent.
What the app does not do
- No customer data. The app does not request access to orders or customers, so it never sees names, addresses, emails or payment details of the people who buy from you.
- No writing to your store. Both permissions are read-only. The app cannot change a price, a cost or a product.
- No selling or sharing your data. Your costs and margins are commercially sensitive. They are not sold, shared or used to train anything.
- No tracking or advertising. There are no analytics scripts, no advertising pixels and no third-party cookies in the app.
Email alerts
If you turn alerts on, the app emails you when a product that was profitable starts selling below cost. Alerts are always sent to the store owner address that Shopify holds for your store, read at the moment of sending. You cannot point them at a different address, and that is deliberate: it keeps the app from being used to send mail to third parties. The address itself is not stored.
Where the data lives, and who else touches it
- Fly.io — hosting and database storage, in the Paris (France) region. The storage volume is encrypted.
- Resend — delivery of alert emails, and only when alerts are enabled. Resend receives the recipient address and the message.
No one else receives your data. The app has no other integrations.
How long it is kept, and how to have it deleted
Uninstalling the app is enough. Shopify notifies the app, and within 48 hours every record belonging to your store is permanently deleted: costs, cost history, scans, alert settings, alert log and the access token. Nothing is retained as a backup copy beyond the routine infrastructure snapshots, which roll over within days.
You can also ask for deletion at any time without uninstalling, using the contact above.
Your rights
Under the GDPR you can ask for access to the data held about your store, its correction, its deletion, or a copy of it in a portable format. Write to the contact above and you will get an answer within 30 days. You also have the right to complain to your national data protection authority.
Changes to this policy
If what the app stores ever changes, this page changes with it and the date at the top is updated. If a change materially affects you, you will be told inside the app rather than only here.