Skip to content

EmbBarcoder - Privacy Policy

Last updated: September 30, 2026

EmbBarcoder ("the App"), provided by MerchBytes ("we", "us", or "our"), helps Shopify merchants scan barcodes that contain a price or weight, find the corresponding Shopify product variant, and apply the calculated price in Shopify POS. Merchants configure barcode rules and test them in the App's Shopify admin interface ("the Service"). This Privacy Policy explains how we collect, use, and share information when you install or use the App with your Shopify store.

Personal Information the App Collects

Depending on the information available from Shopify and your use of the App, we process:

  • Store and account information: your store domain and Shopify store ID, store contact email, and installation status. We also read your store name, currency and the Shopify capabilities needed to operate the App when required; these are not kept as a separate store profile.
  • Authentication information: Shopify access tokens, refresh tokens, their expiry information and session information needed to connect the App to your store and authenticate requests from Shopify admin and Shopify POS.
  • App configuration: whether scanning is enabled, barcode rules and their names, prefixes, product-code and value positions, price or weight interpretation, decimals, units, checksum and verifier settings, rule priority, product lookup order, unit-price basis, configuration version and update time.
  • Product information: the product code extracted from a barcode, and Shopify product and variant identifiers, titles, SKUs, barcodes, prices and the product information needed to determine whether a variant can be used by the App. This information is used for product lookup and pricing; the App does not keep a separate product catalogue in our database.
  • Subscription information: the App subscription information and status provided by Shopify, which we use to check access to the Service. Shopify handles subscription billing.
  • Technical and support information: information recorded in request and error logs and security alerts, including authentication details where needed to diagnose authentication failures, and details you provide when contacting us for support or making a privacy request.

We receive this information through Shopify and Shopify POS, information entered by you or your staff, and your communications with us. If Shopify sends us a privacy request, we also process the information in that request to verify and handle it.

The App's barcode features do not request customer profiles or customer order history and do not collect payment card details. Payments are handled through Shopify. The App does not use advertising or analytics trackers. Information entered in free-text fields, such as a barcode rule name or a support message, may contain personal information. Please avoid entering unnecessary personal or sensitive information in these fields.

Information Kept in Your Shopify Store

The full barcode is parsed in the Shopify admin interface or on the Shopify POS device. For a product lookup, our backend receives the extracted product code and, for POS requests, the configuration version.

When a cashier adds a scanned item to the cart, the App adds barcode and pricing details to the cart line. These include the scanned barcode, rule identifier, price or weight mode, product code, Shopify variant identifier, configuration version and update time, lookup method, currency, unit price, calculated total and, where applicable, the encoded price or weight and unit. These properties become part of the order in your Shopify store. The App does not maintain a separate barcode scan history or customer order history in our database.

The App also stores a copy of the barcode configuration in Shopify custom data associated with its Cart Transform. Where required to verify a barcode match, it stores variant identity metadata containing the Shopify variant identifier, product code and configuration version. This information is used to apply the correct price to the corresponding Shopify variant.

On the POS Device

The App keeps a copy of your configuration, including its version and update time, in Shopify POS device storage. It refreshes that copy from our backend when loading the scanner. Barcode scans and the item currently being processed are processed on the device; the details described above are sent to Shopify when the item is added to the cart. Copies held on the POS device are subject to Shopify POS storage practices.

Shopify Permissions

The App requests read_products to find Shopify product variants by SKU or barcode, and write_products to store the app-owned variant identity metadata needed to verify barcode matches. It requests read_cart_transforms to check its Cart Transform configuration and write_cart_transforms to create and configure the Cart Transform that applies barcode-based prices. The App does not request permissions to read customer profiles or order history.

How Do We Use Your Personal Information?

We use information to provide and operate the Service, including to:

  • Connect the App to your store and authenticate access.
  • Store and test barcode rules, find the corresponding Shopify variant, calculate a price from a barcode and apply that price in Shopify POS.
  • Keep the App's Shopify configuration and POS configuration up to date.
  • Check your App subscription through Shopify billing.
  • Respond to support and privacy requests.
  • Diagnose problems, maintain the App, keep it secure and improve its functionality.
  • Meet applicable legal obligations and address disputes or misuse.

We do not sell or rent personal information and do not use it for advertising.

If the EU or UK General Data Protection Regulation applies, we process store and account information to provide the Service you installed (performance of a contract), to maintain and secure the App and support you (our legitimate interests), and where required by law (legal obligations). Where we process information on a merchant's behalf, we act as the merchant's service provider.

Sharing Your Personal Information

We exchange information with Shopify as needed to provide the Service. Product metadata, cart properties and order information held in your Shopify store are subject to Shopify's and your store's practices. Relevant information may be available to people who have access to the App or the corresponding Shopify records for your store. Shopify's handling of data is described in its Privacy Policy: Shopify Privacy Policy.

We use service providers that support the hosting, operation and maintenance of the App, including hosting our servers and database, delivering security alerts and support communications, and providing technical infrastructure. Google Firebase hosts the App's admin interface. Information may be processed in countries other than the country where you are located, depending on the services used to provide the App.

We may disclose information when required by law or when necessary to respond to lawful requests or protect our rights.

Your Rights

Depending on the laws that apply to you, including the GDPR and US state privacy laws, you may have rights to access, correct, update, export or request deletion of personal information we hold about you. You may also have rights to object to or restrict processing and to complain to a data protection authority.

To make a request, contact us using the details below. Please identify the Shopify store concerned and describe your request. We may need to verify your identity or authority to act for the store before responding. We respond within the time required by applicable law.

If your information was entered by a merchant using EmbBarcoder, you may also contact that merchant. Some records are held independently by Shopify or the merchant, and requests concerning those records may need to be directed to them.

Data Retention

We retain information for as long as needed to provide the Service, maintain relevant business records, resolve disputes and meet applicable legal obligations. Retention depends on the type of information and the purpose for which it is held.

When you uninstall the App, we mark your store's installation as uninstalled. When Shopify sends us a shop data erasure request, we delete your store's EmbBarcoder settings. If the installation is still marked as uninstalled, we also delete its installation record, including the stored Shopify access and refresh tokens. Uninstalling does not delete all information immediately.

You can contact us to request deletion of information associated with your store. Some information, such as support communications, security records or records required for legal obligations or unresolved disputes, may need to be retained separately. Copies of configuration or transaction details held by Shopify or your store, including cart and order properties, are subject to their own retention practices.

Security

Requests between Shopify POS, Shopify admin and our servers use HTTPS and are authenticated using Shopify session tokens. Shopify access and refresh tokens are used to connect the Service to your store. We use technical and operational measures to protect information and diagnose security issues.

Changes

We may update this Privacy Policy to reflect changes to the App, our practices, or operational, legal or regulatory requirements. We will publish the updated policy on this page and revise the date above.

Contact Us

For questions about our privacy practices, privacy requests or complaints, email contact@merchbytes.com or write to:

MerchBytes
10 The Green, Suite A
Dover, DE 19901
USA