Orbestra: 404 & Redirects — an app published by Orbestra.
Effective date: July 19, 2026 · Last updated: July 19, 2026
Orbestra: 404 & Redirects (the "App") is a Shopify application operated by Orbestra ("we", "us", "our"). The App detects broken links (URLs on the Merchant's store that return a 404 error) and helps the Merchant fix them by creating reversible 301 redirects to the correct product, collection, or page.
The App does not access, store, or process the personal data of a Merchant's shoppers. It does not read customer records, order history, names, email addresses, or payment details. It works with store URLs, catalog metadata, and the redirects the Merchant chooses to create. For data about the Merchant's own account and store, we act as controller; for store configuration data we process on the Merchant's behalf as their processor.
Contact for privacy questions: support@orbestra.com
When a Merchant installs the App, with their authorization we access the following through the Shopify API:
| Category | Examples | Why |
|---|---|---|
| Store & account | Store domain, plan, app settings | Run the App, billing, configuration |
| Broken-link data | The requested URL path that returned a 404, hit counts, and first/last-seen timestamps | Detect broken links so the Merchant can fix them |
| Catalog metadata | Product, collection and page titles and handles | Match a broken URL to the correct destination |
| Redirect records | The path → target of each redirect the App creates | Create, preview and undo 301 redirects (stored as native Shopify URL redirects) |
| Merchant report contact | The email address(es) the Merchant configures to receive the weekly report (Merchant's own staff) | Send the optional weekly summary of new 404s and fixes |
We deliberately keep the broken-link dataset free of personal data: we do not store shopper IP addresses or user-agent strings, and we do not access customer records, order history, payment details, or passwords. We do not sell personal data.
Our processing of Merchant account and store data is based on performance of our contract with the Merchant and our legitimate interest in operating and securing the App. Because the App does not process shopper personal data, no shopper-consent basis is required for its operation.
We share the minimum data necessary with the following service providers to run the App:
| Provider | Purpose | Data shared |
|---|---|---|
| Shopify | Platform and data source | Access to store, catalog, and URL-redirect data (no customer or order data) |
| Anthropic (Claude) | Suggest a redirect destination with AI | The broken URL path plus candidate product/collection/page titles and handles. No shopper personal data is sent. Data sent to the Anthropic API is not used to train their models. |
| Resend | Deliver the weekly report to the Merchant | The Merchant's own report-recipient email address and the report content |
| Railway | Application hosting and database | All App data at rest |
| ImprovMX | Forward support email | Emails sent to our support address |
customers/data_request,
customers/redact, and shop/redact. Because the App stores no shopper
personal data, customer-level requests return no personal data; a shop/redact
request deletes the store's App data.Depending on your location (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or restrict the processing of your personal data. Because the App does not process shopper personal data, such requests will typically concern only Merchant account data. Merchants and anyone else may contact us directly at support@orbestra.com.
Data is encrypted in transit. Access is restricted and authenticated, public storefront requests are verified with Shopify's signed app-proxy HMAC, and we avoid writing personal data to application logs. No method of transmission or storage is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.
Our providers may process data in countries other than yours, including the United States. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.
The App is not directed to children and we do not knowingly collect data from them.
We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.
Operator / data controller: Orbestra, the United States.
Email: support@orbestra.com
Governing law: the laws of the United States.