Privacy Policy: Sionnach Search & Filters

Last updated: 2 October 2026

This policy covers the Shopify app Sionnach Search & Filters. For our website, see the site privacy notice.

Who we are

Sionnach Search & Filters is operated by 9196692 Canada Inc. (operating as Sionnach Solutions). Contact: [email protected].

What the app keeps

To provide search and filters for a store, the app keeps, on the merchant's behalf:

  • The store's published products: titles, descriptions, vendors, product types, tags, prices (including the prices in the store's markets), availability, variant options, image addresses, and which collections they belong to and in what order.
  • The merchant's settings: filters, synonyms, ignored words, hidden products and tags, branding and plan.
  • Search events: the words searched, the number of results, the filters applied, whether and where a result was clicked, and when. No shopper identifier is stored with them.
  • Storefront speed samples: anonymous page-timing values and the page's path (without its query), for a sample of page views.
  • Requests sent from the app's Help page (Ask us): the store's address, the theme name and the merchant's message. We receive them by email.
  • Customer data and deletion requests that Shopify forwards: the request's number and how many orders it names, for our records. Not the customer's ID, email address or phone number.

The app keeps no shopper names, email addresses, postal addresses, payment details or orders.

What reaches the app from the storefront

  • Searching and filtering: the shopper's browser sends the words searched, the filters, the page and sort order, and the shopper's country, through Shopify's app proxy. Shopify adds the shopper's customer ID when they are signed in, and our server sees their IP address.
  • Fair use: the IP address, the customer ID and a random identifier the page makes for each view are used only to share the search service fairly between shoppers. The raw values are never stored: only counters under a salted hash are kept, for one minute and gone within a few minutes, and our request log masks the values.
  • Prices in the shopper's market: the shopper's browser asks Shopify for these directly. When Shopify's answer cannot be used, the browser asks the app instead, with the products and variants on screen, the country and the exchange rate. When the prices the app holds need refreshing, the browser sends it the country code.
  • Request log: our host, Fly.io, keeps a log of requests in the United States for up to 7 days: the address requested, the answer's status and timing. Search words, customer IDs, identifiers and session tokens in an address are masked in that log. Entries written before 2 October 2026 recorded addresses in full, including those values; they are deleted automatically by 9 October 2026.

The app sets no cookies on the storefront. In the shopper's browser it keeps one time stamp in the tab's session storage, which is cleared when the tab closes, so that a theme check is not repeated more than once a minute; it identifies no one.

Where data is stored

The application servers (Fly.io), the database (Neon) and the search index (Typesense Cloud) are in London, United Kingdom. The request log is the exception: Fly.io keeps it in the United States, for up to 7 days. Messages from the app's Help page reach us by email through Resend. Data travels encrypted (TLS).

How long

For as long as the app is installed. Shopify sends a shop/redact request 48 hours after the app is uninstalled; the app then deletes the store's search index, settings, search events and requests.

A customer's data request (customers/data_request) or deletion request (customers/redact): the app holds no record about a customer to return or delete. Search events carry no customer identity, and the request itself is recorded without the customer's details. Fair-use counters are gone within a few minutes; request log entries after about 7 days (the last unmasked ones, written before 2 October 2026, by 9 October 2026).

Sub-processors

Shopify (platform and billing), Fly.io (hosting), Neon (database), Typesense Cloud (search index) and Resend (email to us from the app's Help page).

Your rights

Merchants can ask for a copy of their store's data, or for its deletion, at [email protected]. We answer within 30 days.

Changes

The date at the top changes whenever this policy does.