Privacy Policy
Last updated: 28 August 2026
This policy explains what FastOG collects, why, and how long it is kept. The sections about data are written from what the software actually stores, not from a template.
FastOG is operated by the owner of fastog.com ("we", "us"). Contact: [email protected].
What FastOG does
FastOG generates Open Graph images — the preview picture shown when a link is shared on social networks. It runs as a hosted service and as an app installed on Shopify stores.
What we collect
From a connected Shopify store
When a merchant installs the Shopify app we store, for that store only:
- the store's
.myshopify.comdomain and its primary domain; - the store name, description, currency, country and product category, as reported by Shopify;
- access and refresh tokens for the Shopify Admin API, encrypted at rest;
- a cached profile of the store used to design covers: product titles, product types, prices, and the URLs of product and collection images;
- optionally, a screenshot of the storefront home page, encrypted at rest, used once to let the cover-design model match the store's visual style;
- the cover rules the merchant configures (template, colours, fonts, wording).
We do not collect, request, or store any of a store's customer data. The app requests no customer-related permissions from Shopify, and holds no customer names, email addresses, addresses, orders or payment details. Payment for the app is handled by Shopify Billing; we never receive card details.
From accounts on fastog.com
An email address, a password (stored only as a hash), and — where a plan is purchased — billing records created by our payment processor. We never receive or store full card numbers.
From image requests
Each generated image is logged with: the requesting API key, the template and the parameters requested, the resulting URL, the HTTP status, response time, and the originating IP address. We use these records for billing, quota enforcement, abuse prevention and debugging.
Analytics
We use a product-analytics service to record page views and feature usage on fastog.com and in the app. This is used in aggregate to understand which features are used.
Why we process it
- To provide the service — generating and serving covers is impossible without the store profile and cover rules.
- To bill accurately and enforce plan quotas.
- To secure the service and investigate abuse.
- To support merchants who contact us.
Where GDPR applies, our lawful bases are performance of a contract, and our legitimate interests in securing and improving the service.
Processors we share data with
We do not sell personal data and do not share it for advertising. Data is processed on our behalf by: our hosting and database provider; a content-delivery network that caches generated images; a payment processor; a product-analytics provider; and the provider of the AI model used to design covers. The model provider receives the store profile and, where captured, the storefront screenshot; it does not receive tokens or account credentials.
How long we keep it
- Shopify store data: deleted when the app is uninstalled. We retain the store record for up
to 48 hours after uninstall so a reinstall does not lose the merchant's settings, then delete
it. A
shop/redactrequest from Shopify deletes everything we hold for that store immediately. - Image request logs: retained while the account is active, for billing and abuse investigation.
- Account records: retained until the account is deleted, plus any period required for tax and accounting obligations.
Shopify's mandatory privacy requests
We implement Shopify's three compliance webhooks. Because we hold no customer data, a
customers/data_request or customers/redact request is acknowledged and requires no data to
be produced or erased. A shop/redact request erases the store's record and its cover rules.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict processing, and to complain to a supervisory authority. Write to [email protected] and we will respond within the period the applicable law requires.
Merchants: where FastOG processes data on behalf of your store, you are the controller and we are the processor. We process it only to provide the service and only as instructed by you.
Security
Tokens, storefront screenshots and API secrets are encrypted at rest. Traffic is served over HTTPS. Signed image URLs are content-derived, so altering a parameter invalidates the signature. No system is perfectly secure, and we do not claim otherwise.
International transfers
Our infrastructure and processors may be located outside your country, including in the United States. Where required, transfers rely on the European Commission's standard contractual clauses or another lawful transfer mechanism.
Children
FastOG is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes
We may update this policy. The date at the top reflects the current version, and material changes will be announced in the app or by email.
See also Terms of Service. Questions: [email protected].