Loook Audit ("the App") is a Shopify app that scans a merchant's product catalog for cosmetic regulatory compliance (ingredients and marketing claims) against public regulatory sources for the US, EU, KR, and AU markets. This policy explains what data the App accesses, why, and how it is handled.
.myshopify.com domain and an
offline access token, used to read your catalog. Tokens are stored encrypted
(AES-GCM) and are never shown to us in plain text.read_products scope. We use this
solely to run compliance checks and show you the results.The App runs on Cloudflare Workers (hosting and database). Regulatory-change alert emails, if you enable them, are sent via Resend. Compliance reference data comes from public regulatory sources (FDA, EU CosIng, Korea MFDS, Australia). These providers process data only as needed to operate the App.
Scan results and settings are kept while the App is installed. When you uninstall the App, or when Shopify sends a shop/redact request, all data associated with your store is deleted — except a minimal record of your store domain retained solely to prevent repeated free trials (billing-integrity purpose). This record contains no customer or personal data. You can also request deletion at any time by emailing us.
You may request access to, correction of, or deletion of your store's data by contacting
aidan.kr@gmail.com. We respond to Shopify's mandatory GDPR data-request and redaction webhooks
(customers/data_request, customers/redact, shop/redact).
We may update this policy; material changes will be reflected here with a new "last updated" date.
Last updated: 2026-08-18 · Contact: aidan.kr@gmail.com