Privacy Policy
Last updated: July 2, 2026
ShopOps COO ("we", "us", or "our") operates ShopOps COO (the "Service"), accessible at www.shopopscoo.com. This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information. By using the Service, you agree to the practices described in this policy.
1. Information We Collect
1.1 Information You Provide
- Account information: Name, email address, and password when you register.
- Billing information: Billing is processed through Shopify's billing system. We do not store your payment card details.
- Communications: Messages you send us via email or support channels.
1.2 Shopify Store Data
When you connect your Shopify store, we access and store data through the Shopify API, including:
- Orders and revenue metrics (revenue, order count, refunds, average order value)
- Product and inventory data (names, SKUs, stock levels, prices)
- Customer analytics data (pseudonymized customer IDs, order counts, total spend, tags, and purchase history for RFM segmentation)
- Store metadata (shop domain, currency, timezone)
We do not persist Shopify customer names, email addresses, phone numbers, or postal addresses for analytics. Shopify customer, order, and refund identifiers are pseudonymized with a keyed HMAC before storage so we can keep syncs idempotent without storing raw protected IDs.
1.3 Automatically Collected Data
- Usage data: Pages visited, features used, timestamps.
- Log data: IP address, browser type, referring URLs.
- Cookies: Session cookies for authentication. We do not use advertising or tracking cookies.
2. How We Use Your Information
- To provide, operate, and improve the Service
- To generate AI-powered insights, health scores, and recommendations about your store
- To send you daily briefing emails and alerts (if enabled in settings)
- To process billing through Shopify's billing API
- To respond to support requests
- To detect and prevent fraud or abuse
- To comply with legal obligations
We do not sell your data to third parties. We do not use your store data to train AI models that serve other merchants.
3. AI and Data Processing
The Service uses Anthropic's Claude API to generate daily briefs, risk analysis, and conversational responses. Aggregated, anonymized store metrics (e.g., revenue trends, inventory levels) may be sent to Anthropic as part of AI prompt inputs. Individual customer personal data is not included in AI prompts.
Anthropic's data usage is governed by their Privacy Policy. We use the API under a commercial agreement that restricts Anthropic from using our API inputs to train their models.
4. Data Sharing
We share data only with the following categories of third parties:
- Supabase: Database hosting (EU/US regions). Your data is encrypted at rest and in transit.
- Anthropic: AI inference (see Section 3).
- Resend: Transactional email delivery (daily briefs, alerts).
- Vercel: Application hosting and serverless compute.
- Shopify: OAuth authentication and store data access via their API.
We may disclose information if required by law, regulation, legal process, or governmental authority.
5. Data Retention
- Active accounts: Store data is retained for the duration of your subscription.
- After cancellation: We retain store data for 30 days to allow recovery, then delete it through an automated retention job.
- After app uninstall (Shopify): Per Shopify requirements, customer personal data is erased within 30 days of a redact request. Store data is deleted within 48 hours of a shop redact request.
- Protected-data access logs: Server-side access to Shopify customer/order analytics is logged and retained for up to 365 days.
- System logs: Operational logs are retained only as long as needed for security, debugging, and legal compliance.
6. GDPR — Rights of EU/EEA Residents
If you are located in the European Union or European Economic Area, you have the following rights:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Correct inaccurate data.
- Erasure: Request deletion of your personal data.
- Portability: Receive your data in a machine-readable format.
- Objection: Object to processing for legitimate interest or direct marketing.
- Restriction: Request restricted processing under certain conditions.
To exercise any of these rights, email us at privacy@shopopscoo.com. We will respond within 30 days.
Our legal basis for processing is: contract performance (to provide the Service), legitimate interest (product improvement, security), and consent (marketing emails).
7. CCPA — Rights of California Residents
California residents have the right to know what personal information we collect, request deletion of their personal information, and opt out of the sale of personal information. We do not sell personal information. To submit a request, contact us at privacy@shopopscoo.com.
8. Shopify Customer Data Requests
As a Shopify app, we comply with Shopify's mandatory GDPR webhooks:
- customers/data_request: We log the request with minimized metadata and can provide store owners a report of data we hold for a customer upon request.
- customers/redact: We anonymize or delete customer personal data within 30 days and remove contact fields from local records.
- shop/redact: We delete all store data within 48 hours of receiving this webhook (sent 48 hours after uninstall).
9. Security
We implement industry-standard security measures including TLS encryption in transit, AES-256 encryption at rest (via Supabase), Row Level Security to isolate tenant data, least-privilege service access, production/test separation, access logging for protected-data reads, and access controls restricting employee access to production data. Despite these measures, no system is 100% secure. If you discover a security issue, please report it to privacy@shopopscoo.com.
We do not use production customer data for development or testing. Access to production systems is limited to authorized staff, protected by strong authentication, and reviewed when business needs change.
10. Children's Privacy
The Service is intended for business use by adults. We do not knowingly collect personal information from anyone under 18. If we learn we have collected data from a minor, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or by posting a notice in the Service at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.
12. Contact Us
For privacy-related questions or to exercise your rights, contact us at: