Privacy Policy

Orbestra: 404 & Redirects — an app published by Orbestra.
Effective date: July 19, 2026 · Last updated: July 19, 2026

1. Who we are

Orbestra: 404 & Redirects (the "App") is a Shopify application operated by Orbestra ("we", "us", "our"). The App detects broken links (URLs on the Merchant's store that return a 404 error) and helps the Merchant fix them by creating reversible 301 redirects to the correct product, collection, or page.

The App does not access, store, or process the personal data of a Merchant's shoppers. It does not read customer records, order history, names, email addresses, or payment details. It works with store URLs, catalog metadata, and the redirects the Merchant chooses to create. For data about the Merchant's own account and store, we act as controller; for store configuration data we process on the Merchant's behalf as their processor.

Contact for privacy questions: support@orbestra.com

2. What data we access and store

When a Merchant installs the App, with their authorization we access the following through the Shopify API:

CategoryExamplesWhy
Store & account Store domain, plan, app settings Run the App, billing, configuration
Broken-link data The requested URL path that returned a 404, hit counts, and first/last-seen timestamps Detect broken links so the Merchant can fix them
Catalog metadata Product, collection and page titles and handles Match a broken URL to the correct destination
Redirect records The path → target of each redirect the App creates Create, preview and undo 301 redirects (stored as native Shopify URL redirects)
Merchant report contact The email address(es) the Merchant configures to receive the weekly report (Merchant's own staff) Send the optional weekly summary of new 404s and fixes

We deliberately keep the broken-link dataset free of personal data: we do not store shopper IP addresses or user-agent strings, and we do not access customer records, order history, payment details, or passwords. We do not sell personal data.

3. How we use the data

4. Legal basis (GDPR)

Our processing of Merchant account and store data is based on performance of our contract with the Merchant and our legitimate interest in operating and securing the App. Because the App does not process shopper personal data, no shopper-consent basis is required for its operation.

5. Subprocessors

We share the minimum data necessary with the following service providers to run the App:

ProviderPurposeData shared
ShopifyPlatform and data sourceAccess to store, catalog, and URL-redirect data (no customer or order data)
Anthropic (Claude)Suggest a redirect destination with AIThe broken URL path plus candidate product/collection/page titles and handles. No shopper personal data is sent. Data sent to the Anthropic API is not used to train their models.
ResendDeliver the weekly report to the MerchantThe Merchant's own report-recipient email address and the report content
RailwayApplication hosting and databaseAll App data at rest
ImprovMXForward support emailEmails sent to our support address

6. Merchant report emails

7. Data retention and deletion

8. Your rights

Depending on your location (including under the GDPR and the CCPA/CPRA), you may have the right to access, correct, delete, or restrict the processing of your personal data. Because the App does not process shopper personal data, such requests will typically concern only Merchant account data. Merchants and anyone else may contact us directly at support@orbestra.com.

9. Security

Data is encrypted in transit. Access is restricted and authenticated, public storefront requests are verified with Shopify's signed app-proxy HMAC, and we avoid writing personal data to application logs. No method of transmission or storage is perfectly secure, but we take reasonable measures appropriate to the sensitivity of the data.

10. International transfers

Our providers may process data in countries other than yours, including the United States. Where required, appropriate safeguards (such as Standard Contractual Clauses) apply.

11. Children

The App is not directed to children and we do not knowingly collect data from them.

12. Changes to this policy

We may update this policy from time to time. Material changes will be reflected by updating the "Last updated" date above.

13. Contact

Operator / data controller: Orbestra, the United States.
Email: support@orbestra.com
Governing law: the laws of the United States.