Zen Image Optimizer

Privacy policy

How Zen Image Optimizer handles your store's data. Last updated 31 July 2026.

The short version

The app requests no access to customers, orders, or any personal data, and it holds no personal data about your buyers. It reads your product and file images, stores a copy of each original image it replaces so you can undo the change, and keeps a record of what it optimized and when.

What the app can access

The app is installed with three Shopify permissions, and no others:

  • Read files — to list the images in your store and read the original bytes of an image before compressing it.
  • Write files — to replace an image with its compressed version. The image keeps the same URL and the same media ID.
  • Read products — to find which images belong to which product, and to notice new product images when automatic optimization is enabled.

It requests no permission to read customers, orders, checkouts, payment data, or your theme code. Those permissions are not held, so that data cannot be accessed even by mistake.

What is stored, and where

  • Your store domain and access token, so the app can act on your behalf.
  • Image metadata — file name, media ID, URL, dimensions, file size, format, alt text, and the product an image belongs to.
  • A copy of the original bytes of every image the app replaces, kept for 30 days so you can restore it, then deleted automatically.
  • A record of optimization runs — what ran, when, how many images, how many bytes were saved — and a usage counter used for plan limits and billing.

Records are stored in a PostgreSQL database on servers we operate, and the original image bytes on disk on the same infrastructure. Compression happens on our server; images are never sent to a third-party image service, an AI provider, or any advertising or analytics network. The app has no third-party sub-processors beyond our own hosting provider and Shopify itself.

What is never collected

No customer names, email addresses, shipping addresses, order contents, payment details, or browsing behaviour. The app does not add any script, pixel, or tracker to your storefront, and it does not read data about the people who visit your store.

Deletion

  • Backups expire on their own after 30 days, image by image.
  • When you uninstall, the access token is destroyed immediately and all queued work stops. Your optimization history and remaining backups are kept for 48 hours, so a reinstall does not lose them.
  • 48 hours after uninstall, Shopify sends a deletion request and everything the app holds for your store is erased — every database record and every stored image file.

You can ask for deletion sooner by emailing us; requests are actioned within 30 days and usually the same week.

Changes and contact

Material changes to this policy are reflected in the “last updated” date above. Questions, data requests, and complaints: [email protected].