Privacy Policy: Lighthouse-md
Last updated: July 25, 2026
Lighthouse-md ("the app") audits your Shopify storefront's web performance and turns the results into reports, fix plans, and answers in Shopify Sidekick. This policy describes exactly what data the app handles. The short version: we analyze your public storefront, we store the results for your shop, and we never collect or store your customers' personal data.
What we collect and store
- Shop identity: your myshopify.com domain, your storefront's primary domain, and the API access token Shopify issues to the app (used only to read your shop's domain and manage the app's own subscription).
- Audit results: Google Lighthouse / PageSpeed Insights results for your public storefront URL (performance scores, Core Web Vitals, failing audits), plus a history of past audits so the app can show trends.
- Usage and billing metadata: how many audits your shop has run and when, used to operate the free-audit allowance and the Pro subscription. Subscriptions and payments themselves are handled entirely by Shopify; we never see payment details.
What we do NOT collect
- No customer personal data: no names, emails, addresses, orders, or browsing behavior of your customers.
- No theme code: the app reads nothing from your theme and writes nothing to your store.
- No analytics trackers or advertising pixels in the app.
Third parties
- Google PageSpeed Insights: to run an audit, we send your storefront's public URL to Google's PageSpeed Insights API, the same service anyone can use at pagespeed.web.dev.
- Hosting: the app and its database run on Railway infrastructure. Data is encrypted in transit (HTTPS).
- Shopify Sidekick: when you ask Sidekick about your store's performance, Sidekick reads your latest cached audit summary from the app through Shopify's own extension platform.
Data retention and deletion
- On uninstall: your session tokens, cached audit briefs, and audit history are deleted immediately. A minimal usage record (how many audits were run) is kept so the one-free-audit allowance survives reinstalls.
- GDPR redaction: when Shopify sends the shop redaction request (48 hours after uninstall) we erase everything we hold for the shop, including the usage record. Customer data requests and customer redaction requests are acknowledged and require no action, because we store no customer data.
Contact
Questions or data requests: bkocdur@gmail.com