Install App

Privacy Policy

How MCL Digital handles data for the MenuFields app and this website.

Last updated: 8 August 2026

MenuFields is a Shopify application provided by MCL Digital (“we”, “us”, or “our”). This Privacy Policy explains how we collect, use, store, share, and protect information when Shopify merchants install or use MenuFields, visit our website, or contact us for support.

MenuFields helps merchants enhance Shopify navigation menus with badges, icons and link styling, and attach structured data to menu items.

1. Information we collect

1.1 Shopify store information

When a merchant installs or uses MenuFields, we may receive:

  • Store name and Shopify domain
  • Store email address and contact information
  • Store currency, locale and timezone
  • Shopify store and subscription configuration
  • App installation status and approved access scopes
  • Shopify access tokens
  • Menu and navigation information
  • Theme configuration and app embed status
  • Menu publication and synchronisation status
  • MenuFields plan and billing status supplied by Shopify

We only request Shopify permissions reasonably necessary to provide MenuFields.

1.2 Navigation and theme information

To provide MenuFields, we may process:

  • Menu identifiers, handles and titles
  • Menu-item titles, URLs and hierarchy
  • The position of links within a menu
  • Theme sections, blocks and settings that reference menus
  • Theme configuration required to identify where menus appear
  • Whether the MenuFields theme app embed is enabled

MenuFields may inspect relevant theme configuration to map menus to their storefront locations. MenuFields does not use this access to rewrite merchant theme files.

1.3 MenuFields configuration

We store information created or selected by merchants, including:

  • Badge text, colours, shapes, positions and styling
  • Emoji and uploaded image icons
  • Link colours, emphasis and styling
  • Menu enablement and publication settings
  • Structured-data definitions and field settings
  • Structured values assigned to menu items
  • References to Shopify Files or metaobject entries
  • Draft, synchronisation and publication information
  • Theme-level appearance settings

Some published configuration is intentionally delivered to the merchant’s storefront. Information entered into storefront-facing fields may consequently be visible in the storefront page, source code or associated Shopify data.

Merchants should not place confidential, sensitive or personal information into badges, structured-data fields or other values intended for storefront publication.

1.4 Information provided directly

We may collect information supplied through MenuFields, our website or support channels, including:

  • Name
  • Business name
  • Email address
  • Shopify store domain
  • Support messages
  • Feedback and reviews
  • Screenshots, files or diagnostic information
  • App preferences and configuration choices

If our website uses a third-party form service, form submissions may be processed and stored by that provider on our behalf.

1.5 Technical information

When merchants use MenuFields or visit our website, our hosting and security providers may automatically process:

  • IP address
  • Browser and device information
  • Operating system
  • Request dates and times
  • Referring pages
  • Error and diagnostic logs
  • Security and performance information

We use this information to deliver, secure, troubleshoot and improve the service.

2. Storefront visitor information

MenuFields is designed primarily to process merchant-controlled menu configuration, not customer records.

MenuFields does not require customer names, email addresses, postal addresses, orders, carts or checkout information for its core functionality.

The MenuFields storefront script reads relevant navigation elements in the visitor’s browser and applies the configuration published by the merchant. MenuFields does not use this script to track individual browsing behaviour or create advertising profiles.

If future functionality requires additional customer information, we will request only the permissions required, update this Privacy Policy and comply with Shopify’s protected customer-data requirements.

3. How we use information

We use information to:

  • Install and authenticate MenuFields
  • Connect MenuFields to the correct Shopify store
  • Synchronise Shopify navigation menus
  • Identify where menus are referenced by a theme
  • Store merchant configuration and drafts
  • Publish menu appearance and structured data
  • Display badges, icons and link styling
  • Provide previews and Liquid usage guidance
  • Determine subscription plans and feature access
  • Process background operations such as syncing and publishing
  • Provide support and respond to enquiries
  • Diagnose errors and monitor reliability
  • Prevent fraud, misuse and unauthorised access
  • Meet Shopify platform and legal requirements
  • Communicate important service or support information

We do not sell merchant or customer personal data.

We do not use this information for unrelated behavioural advertising.

Where UK GDPR, EU GDPR or similar laws apply, we rely on:

  • Performance of a contract: to install and provide MenuFields and its requested functionality.
  • Legitimate interests: to operate, secure, troubleshoot and improve MenuFields, communicate with merchants and prevent misuse.
  • Consent: where consent is required for optional communications, cookies or similar technologies.
  • Legal obligation: where processing is required for legal, accounting, regulatory or Shopify platform obligations.

Where we rely on legitimate interests, those interests are operating a reliable and secure service, supporting merchants, improving the product and protecting MenuFields and its users.

5. Shopify authentication

Shopify provides access credentials when a merchant installs MenuFields. These credentials allow MenuFields to interact with the store only within the permissions approved during installation.

We store Shopify access tokens securely and use them solely to operate MenuFields.

After uninstall, we stop using the store’s access token and handle the associated information as described below.

6. Billing

MenuFields subscriptions and charges are processed through Shopify.

We may receive limited billing information from Shopify, including:

  • Current plan
  • Subscription status
  • Billing period
  • Pending plan changes
  • Charge or approval status

We do not directly collect or store full payment-card details.

7. Sharing information

We may share information with service providers that help us operate MenuFields, including:

  • Shopify
  • Hosting and database providers
  • Background-processing infrastructure
  • Website and form-hosting providers
  • Email and support providers
  • Error-monitoring and security providers
  • Analytics providers, where enabled
  • Professional advisers where reasonably necessary

These providers may process information only as required to provide their services to us and must protect it appropriately.

We may also disclose information where necessary to:

  • Comply with law or legal process
  • Respond to lawful authority requests
  • Enforce our terms
  • Investigate fraud, security incidents or misuse
  • Protect the rights and safety of merchants, customers, Shopify, MCL Digital or others

We do not sell personal data.

A current list of subprocessors is available by contacting support@menufields.com.

8. International transfers

Information may be processed in the United Kingdom, European Economic Area, United States or other countries in which our providers operate.

Where required, we use appropriate safeguards for international transfers, such as adequacy regulations, contractual protections or recognised data-transfer agreements.

9. Data retention

We retain information only for as long as needed to provide MenuFields, meet legal obligations, resolve disputes, maintain security and enforce agreements.

Generally:

  • Store and configuration information is retained while MenuFields is installed.
  • Access to the Shopify store stops after uninstall.
  • Associated store information is deleted or anonymised following uninstall and applicable Shopify deletion requests, unless continued retention is legally required.
  • Security and diagnostic logs are retained for a limited operational period.
  • Support and contact messages may be retained for support, audit and business-record purposes.
  • Billing records may be retained where required for accounting, tax or legal compliance.
  • Backups may retain deleted information temporarily until they are securely overwritten.

When information is no longer required, we delete or anonymise it.

10. Uninstalling MenuFields

When MenuFields is uninstalled, Shopify notifies us and invalidates the app’s access to the store.

We stop accessing the store and delete or anonymise associated personal information unless retention is reasonably necessary for security, legal, accounting or dispute-resolution purposes.

Merchants may also request deletion by contacting support@menufields.com.

11. Shopify privacy webhooks

We comply with Shopify’s mandatory privacy webhook requirements, including requests concerning:

  • Customer data access
  • Customer data erasure
  • Shop data erasure

Where MenuFields holds information covered by a valid request, we process the request in accordance with Shopify’s requirements and applicable law.

Because MenuFields does not ordinarily collect customer records, a customer request may return no customer-specific information.

12. Security

We use reasonable technical and organisational safeguards, which may include:

  • Secure Shopify authentication
  • Access controls
  • Encrypted network connections
  • Secure credential and token storage
  • Environment separation
  • Restricted administrative access
  • Monitoring and diagnostic logging
  • Dependency and infrastructure maintenance

No electronic system is completely secure, and we cannot guarantee absolute security.

13. Cookies and similar technologies

MenuFields and its website may use cookies or similar technologies where necessary to:

  • Authenticate merchants
  • Maintain secure sessions
  • Remember preferences
  • Protect against abuse
  • Measure and improve performance, where enabled

The MenuFields storefront functionality does not require advertising cookies or create cross-site advertising profiles.

Where required, consent will be requested before using non-essential cookies.

14. Merchant responsibilities

Merchants are responsible for:

  • Using MenuFields lawfully
  • Maintaining an accurate store privacy policy
  • Informing customers about relevant storefront apps
  • Obtaining any required consent
  • Avoiding personal or confidential information in publicly rendered fields
  • Responding to customer rights requests for information they control
  • Ensuring referenced Shopify Files and metaobjects are suitable for publication

15. Privacy rights

Depending on location, individuals may have the right to:

  • Access their personal information
  • Correct inaccurate information
  • Request deletion
  • Restrict or object to processing
  • Request data portability
  • Withdraw consent where processing relies on consent
  • Complain to a data-protection authority

Requests may be sent to support@menufields.com.

Where information is controlled by a Shopify merchant, we may direct the individual to that merchant.

Individuals in the United Kingdom may also complain to the Information Commissioner’s Office at ico.org.uk.

16. Controller and processor roles

For merchant account, app usage, support, billing, security and service-administration information, MCL Digital generally acts as an independent controller.

Where MenuFields processes information on a merchant’s behalf to provide storefront functionality, the merchant generally acts as controller and MCL Digital acts as processor or service provider.

17. Children

MenuFields is intended for Shopify merchants and is not directed at children.

We do not knowingly collect children’s personal information. If we learn that such information has been collected without appropriate authority, we will take reasonable steps to remove it.

18. Automated decision-making

MenuFields uses automated processes to synchronise menus, match storefront navigation and apply merchant-defined configurations.

These processes do not make decisions about individuals that produce legal or similarly significant effects.

19. Changes to this policy

We may update this Privacy Policy when MenuFields, our providers, Shopify requirements or applicable laws change.

We will update the “Last updated” date when changes are made. Where appropriate, we may notify merchants through MenuFields, by email or through another reasonable method.

20. Contact us

For questions, privacy requests or data-protection enquiries, contact:

MCL Digital
Email: support@menufields.com
Website: www.menufields.com

Please include your Shopify store domain and enough information for us to identify and respond to your request.