Altovexa

Privacy Policy

SDLC LIMITED · Last updated 9 October 2026

Altovexa is a Shopify app operated by SDLC LIMITED. It compresses the images on your products, writes alt text for them, and reports what that saved. This page describes exactly what the app reads, what it keeps, and who else sees it.

What the app is allowed to access

At install, Shopify asks you to grant two permissions, and the app cannot reach anything outside them:

  • write_products — read and modify your products, their images and their metafields.
  • write_files — read and modify files in your store's content library, which is where product image alt text is written.

The app does not request access to orders, customers, payments, discounts or your storefront theme, and so has no way to read them.

What we store

Everything the app keeps in its own database is listed here. There is nothing else.

Shopify session

Your shop domain plus the access token Shopify issues at install, and the name, email and locale Shopify attaches to the authenticating staff account. This is what lets the app call the Admin API on your behalf.

Monthly image counter

Your shop domain, the current month, and how many images have been optimized in it. Used to enforce your plan's quota.

App settings

Your shop domain and whether auto-optimize for new products is switched on.

Image size cache

The measured byte size of a Shopify CDN image URL. Stores a number and a URL — never the image itself. It exists so the product list does not re-measure thousands of images on every page load.

We never store your images. During optimization an image is downloaded into memory, re-encoded, uploaded back to Shopify and discarded. No copy is written to disk and no copy is retained. The only thing kept about an image is how many bytes it was.

We store no customer data. The app has no access to your customers, their orders or their personal information, and keeps no record of any shopper.

What the app changes in your store

When you run an optimization, the app acts on your behalf to:

  • Upload a compressed WebP copy of an image, attach it to the product, and delete the original image from that product.
  • Restore the image order you had before the run.
  • Write alt text on images that have none, when your plan includes that feature.
  • Save a record of the result on the product as metafields in the image_optimization namespace — the before and after file size, the compression achieved and when it ran. This is what the analytics and reports are calculated from.

Nothing happens to a product until you select it and start a run, with one exception: if you switch on auto-optimize, products you create from that point on are optimized in the background on the same terms.

Who else receives data

Shopify

Product, media, file and metafield reads and writes via the Admin API.

This is your own store data; the app is operating on it at your request.

OpenAI

The public Shopify CDN URL of an image, plus the product title. OpenAI fetches the image from that URL itself.

Generating alt text. Only happens when you run the Alt Text Generator, or when the optimizer meets an image with no usable alt text on a plan that includes the feature.

Anthropic

The image contents and the product title.

An optional alternative alt-text provider. Only reachable if the deployment has an Anthropic key configured and you pick that provider.

Google PageSpeed Insights

The public URL of one of your product pages.

Running a live Lighthouse test, and only when you press the button on the Page Speed Reports page.

These providers process that data under their own terms and privacy policies. The app shares nothing with anyone else — no analytics vendors, no advertising networks, no data brokers — and never sells data.

Retention and deletion

  • When you uninstall, Shopify notifies the app and it deletes your session and access token. The app can no longer reach your store.
  • If Shopify sends a shop erasure request, the app additionally deletes your usage counter and your saved settings.
  • Customer data requests and erasure requests are acknowledged, and there is nothing to act on, because the app holds no customer records.
  • The image size cache holds a public CDN URL and a byte count, with no link to a shop or a person.

Optimized images and the metafields describing them stay on your store after you uninstall. They are your store's own content, and deleting them would remove the images your products are using. If you want them gone, remove them in Shopify.

Security

  • All traffic to the app and to every provider above is over HTTPS.
  • The database is reachable only from the application itself on a private network; it is not exposed to the internet.
  • Access tokens are held only for as long as the app is installed, and are deleted on uninstall.

No system is perfectly secure, and we do not claim otherwise. If you believe you have found a vulnerability, please report it to the contact below before disclosing it publicly.

Your rights

Depending on where you are, you may have the right to ask what data is held about you, to have it corrected, or to have it erased. For this app that is the short list in What we store above, and uninstalling removes your session immediately. For anything further, contact us.

Changes

If this policy changes materially, the date at the top of the page changes with it. Continuing to use the app after a change means you accept the updated policy.

Contact

SDLC LIMITED — support address pending — set CONTACT_EMAIL