Privacy Policy
Last updated: August 3, 2026
This Privacy Policy explains how data is collected, used, stored and protected in connection with Custodian, a subscription Shopify application presented by OriginMind and operated by Adrien Belhomme. The App helps merchants and their authorized teams generate landing and product pages and optionally connect advertising accounts.
1. Who we are
Custodian is operated by Adrien Belhomme, a sole trader registered in France under SIREN 822 039 673 (RCS Nanterre), at 67 avenue Gambetta, 92400 Courbevoie, France. The Shopify merchant is the controller of its store data and Custodian acts as its processor. For questions about this policy or your data, contact adrien@custodiancommerce.com.
2. Information we collect
- Shopify store data. When a merchant installs the App, we access store information through the Shopify Admin API (store domain, products, theme and brand assets) as needed to generate pages. Access is granted by the merchant during the Shopify OAuth install and is limited to the scopes approved at that time.
- Advertising connection credentials (OAuth). If you choose to connect Meta or Google Ads, the platform issues us an access token (and, for Google, a refresh token) plus the identifier of the ad account you select. We never receive or store your Meta or Google password.
- Advertising data (read-only). With your consent, we list accessible ad accounts and read existing campaigns, ads, creatives (including headlines, body copy, images, names and destination URLs), and reporting statistics. This lets us display reporting and offer an ad you select as a starting point inside the page editor.
- Technical logs. Standard, short-lived operational logs used to run and secure the service.
3. How we use information
- To generate, pre-fill and improve the pages you create.
- To display your connection status and the list of ad accounts you can choose from.
- To display campaigns, ads and reporting statistics, and associate an ad you select with a landing page.
- When you explicitly request page generation from a selected ad, to send the selected advertising data to our AI pipeline and generate the page you requested. OriginMind does not use Google Ads data to train AI models.
- To operate, secure and support the service.
We access your advertising data on a read-only basis. We do not create, edit, pause or delete any campaign or ad, and we do not change budgets, bids, targeting, or delivery settings. We may store or cache reporting metrics for a limited period to provide reporting and operate the integration reliably.
4. Data obtained from Meta and Google
Meta.Our use of data obtained through Meta's APIs complies with the Meta Platform Terms and Developer Policies. Meta Platform Data is used solely to provide the functionality described above and is deleted on request or when you disconnect.
Google. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We use Google Ads data only to provide user-facing features, we do not sell it, and we do not use it for advertising. When you explicitly request page generation from a selected ad, the selected Google Ads data may be transmitted to AI processing providers acting as service providers solely to produce the page you requested. OriginMind does not use Google Ads data to train AI models.
5. Storage and security
Access and refresh tokens are encrypted at rest using AES-256-GCM and isolated per store. All network traffic uses HTTPS. Only the server components strictly required to fulfil an authorized request access decrypted tokens, and only at the moment of that request.
6. Sharing
We do not sell your data. We share it only with technical sub-processors required to operate the service (such as hosting and database providers), with AI processing providers when you request generation from selected advertising data, and where required by law.
7. Retention and deletion
- When you click Disconnect inside the App, we attempt to revoke the platform authorization, then delete the stored access and refresh tokens and live connection even if the platform revocation endpoint is temporarily unavailable.
- They are deleted when you uninstall the App from your Shopify store. In line with Shopify requirements, we honor the mandatory compliance webhooks (
customers/data_request,customers/redact,shop/redact). - You may request deletion of all your data at any time by emailing adrien@custodiancommerce.com.
- Reporting metrics may be stored or cached for a limited period and are deleted when they are no longer needed to provide the service or when your deletion request is completed. Bounded campaign/page provenance may remain with the merchant page for up to 24 months so historical reports stay explainable.
8. Your rights
Depending on your jurisdiction (including the GDPR and CCPA), you may request access to, correction of, or deletion of your personal data. You can also revoke the App's access at any time from your Meta account (Settings → Business Integrations) or your Google account (myaccount.google.com → Security → Third-party access).
9. Compliance with platform terms
We operate in accordance with the Shopify API License and Terms of Use, the Meta Platform Terms, and the Google API Services User Data Policy. We process personal data only as necessary to provide the App's functionality to the installing merchant.
10. Changes to this policy
We may update this policy from time to time. The "Last updated" date above reflects the current version, and material changes will be communicated within the App.
11. Contact
Questions about this policy or your data: adrien@custodiancommerce.com.
OriginMind — Privacy Policy, publicly available at https://originmind.xyz/privacy