Shopify data we access
CommerceMemo reads store orders, products, and inventory to generate merchant-facing operations reports. Customer opportunity analysis is used only if customer data access is explicitly requested and approved.
Policy
This page describes how CommerceMemo handles Shopify store data for the read-only daily operations report MVP.
CommerceMemo reads store orders, products, and inventory to generate merchant-facing operations reports. Customer opportunity analysis is used only if customer data access is explicitly requested and approved.
The app stores encrypted Shopify access tokens, operational snapshots, generated reports, and basic app event logs.
The MVP sends minimized structured report metrics to OpenAI for report writing, and sends report email content to the configured email provider for delivery. The app should not send unnecessary customer-identifying fields to either provider.
Merchants can provide a report recipient email, send time, timezone, and alert thresholds. The app uses those settings only to generate and deliver the merchant's own reports.
Access tokens are encrypted at rest. Operational logs are used for sync, report, billing, webhook, and delivery troubleshooting and should avoid full customer-sensitive values.
Order and customer snapshots are retained for up to 90 days, reports for up to 180 days, and operational, usage, and compliance logs for up to 90 days. Expired report links are removed after 30 days. Shopify's verified deletion webhooks can remove data sooner.
The app does not sell customer data, use Shopify data for advertising, use merchant or customer data to train or develop AI or machine-learning models, or automatically change products, prices, inventory, orders, or customers.
After uninstall, the app marks the shop inactive, disables daily email delivery, stops using the Shopify access token, and follows Shopify privacy webhook requirements.
For data handling or privacy questions, contact support@commercememo.com.