Margin Shield — Privacy Policy
Margin Shield is a Shopify app that calculates contribution profit per order, product, region and advertising campaign for a merchant's store. This policy explains what data the app accesses, why, how long it is kept, and the choices available to merchants and their customers.
1. Who the data is about
- The merchant (the Shopify store owner and staff who use the app).
- Store data belonging to the merchant — orders, products, costs, transactions and, to a limited extent, order destinations.
Margin Shield is a business-analytics tool. It does not build customer profiles and does not use store data for advertising, resale, or model training.
2. What we access from Shopify, and why
On install the merchant approves these Shopify access scopes:
| Scope | What it reads | Purpose |
|---|---|---|
read_orders (and optionally read_all_orders) | Order totals, line items, discounts, refunds, shipping charged, taxes, payment transactions and their fees, fulfilment status, and the order's ship-to city / province / country | Calculate contribution profit and margin per order; separate delivered / pending / return-to-origin economics |
read_products | Products, variants, SKUs, product/variant identifiers, images | Attribute profit to the right product and variant |
read_inventory | InventoryItem.unitCost (the "Cost per item" a merchant sets in Shopify) | Use the correct cost of goods when computing profit |
We request the minimum scopes needed for these features and do not request access to customer profiles, marketing consent, or storefront browsing behaviour.
3. Personal information
Margin Shield is designed to avoid storing customer personal information. Specifically:
- We store an order's city, province and country only, to produce regional profitability and RTO analytics.
- Where a customer is associated with an order, we store a one-way salted hash (SHA-256 of the store domain plus the Shopify customer ID). This lets us group repeat orders for cohort analytics without holding the customer's identity. The hash cannot be reversed to a name, email, address or phone number.
- We do not store customer names, emails, phone numbers, street addresses, IP addresses, or payment card data.
Merchant staff information (name, email, Shopify user ID) is processed only to authenticate app sessions and to record who made an audited change (for example a manual cost override).
4. Data we generate and store
- Normalised order economics and versioned "cost snapshots" (an immutable per-order profit record).
- Dated cost history per product/variant.
- Merchant-configured cost rules (fulfilment, packaging, payment/COD fees, RTO model), profit-alert rules and alert events.
- Daily pre-computed aggregates used to render dashboards.
- Advertising spend and attribution data, if the merchant connects an ad platform (see section 6).
- An audit log of privileged actions (cost overrides, rule changes, historical recalculations).
5. How the data is used
- To provide the app's analytics inside the merchant's Shopify admin.
- To send profit alerts and an optional periodic digest to the merchant's email, if enabled.
- To operate, secure, debug and improve the service.
We do not sell data, share it with data brokers, or use it for advertising or for training machine-learning models.
6. Third-party connections (optional, merchant-initiated)
7. Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Shopify | Source of store data; app hosting platform surfaces | Per Shopify's terms |
| [YOUR HOSTING / DATABASE PROVIDER] | Application hosting and PostgreSQL database | [REGION] |
| [YOUR EMAIL PROVIDER] (only if alert emails are enabled) | Delivery of profit alerts and digests | [REGION] |
8. Retention and deletion
- Store data and derived analytics are retained while the app is installed.
- When the app is uninstalled, Shopify sends an
app/uninstalledwebhook; access tokens are revoked and integration secrets are cleared immediately. - Margin Shield handles Shopify's mandatory compliance webhooks:
customers/redact,shop/redactandcustomers/data_request. Onshop/redact(sent ~48 hours after uninstall) all data for that store is permanently deleted. - A merchant can request export or deletion of their data at any time by contacting [YOUR PRIVACY EMAIL]. The app also provides self-service export from its Settings screen.
9. Security
- All traffic is served over HTTPS.
- Shopify and ad-platform tokens and other integration secrets are encrypted at rest.
- Shopify webhooks are HMAC-verified and processed idempotently.
- Access to privileged actions is restricted and audited.
- We apply least-privilege access scopes and minimise the personal data we hold.
10. A customer's rights
Margin Shield acts as a processor on behalf of the merchant (the controller). A shopper who wishes to access or delete their data should contact the merchant they purchased from. When the merchant or Shopify forwards such a request to us, we action it as described in section 8. Because we hold only a store's city/province/country and a non-reversible hash, in most cases there is no identifiable customer data for us to return.
11. Changes to this policy
We may update this policy; material changes will be reflected by the "Last updated" date above and, where appropriate, communicated to merchants in-app or by email.
12. Contact
[YOUR LEGAL / COMPANY NAME]
[YOUR ADDRESS]
Privacy enquiries: [YOUR PRIVACY EMAIL]