NEW TECH / OFFERPROOFHome

PRIVACY DETAILS ยท DEVELOPMENT DRAFT

How OfferProof handles your data

Updated September 5, 2026. These details describe the current implementation. Operator contact and production service providers must be finalized before public release.

What the app stores

Shop identity and installation authorization, Shopify session tokens, scoped Storefront access, selected catalog facts, approved campaign URLs and market contexts, reference sources, check results, findings, job status and limited webhook metadata. Campaign codes and evidence are encrypted with application-managed keys; session tokens remain within the official server-side session store and require protected production storage.

Purpose and Shopify access

We use this data to compare approved offers with current product, variant, price, availability and optional anonymous-cart discount facts. The app does not request customer or order access. Anonymous cart probes do not submit orders or payments. Shopify processes API requests and their associated operational data under its own policies.

History and retention

Plans retain detailed check and finding evidence for 30, 90 or 180 days. Retention cleanup runs with the background worker. Current approved references remain available while installed. An unresolved finding whose detailed evidence expires remains labeled evidence expired rather than being marked recovered; exports identify history limits. A separate lifecycle authority records only opaque keyed installation and erasure events so a restored primary database cannot revive erased tenant data. Production backup retention and recovery verification remain release requirements.

Your controls

You can pause automatic checks, stop individual offers and export retained references and evidence without an active paid plan. Exported copies stay under your control. Uninstalling revokes app access; the uninstall and Shopify shop-redaction handlers erase app-owned shop records and sessions. Reopening after erasure requires a fresh Shopify-authenticated installation and does not restore old tenant data. Customer privacy webhooks are handled without storing customer payloads.

Contact and release status

The production privacy contact is not configured. Public distribution is blocked until a working contact and final policy are approved.

Do not include customer details, private tokens or unrelated personal data in campaign links or reference notes.