NEW TECH / PACKPROOF

PRIVACY NOTICE

Clear facts about your data.

Last updated September 5, 2026. This notice describes the current PackProof application behavior.

Data PackProof receives and stores

PackProof does not request customer lists, order records, checkout data, payment-card data, supplier systems, or physical-product photographs. Customer privacy webhooks are recorded only as delivery metadata; their customer payload is not stored.

Why it is used

The data is used to authenticate the installed shop, read its product catalog, save merchant-approved pack references, compare later catalog observations, preserve evidence history, schedule checks, prevent duplicate webhook or worker processing, and provide authenticated exports.

Retention limits

After each successful catalog check, audit runs and catalog snapshots older than the active plan window are removed: 30 days on Starter, 90 days on Growth, and 180 days on Pro. If no later check succeeds, older history can remain until the next successful check. The JSON export includes all saved references and findings and at most the latest 100 retained audit runs.

References, current findings, jobs, shop settings, and session data are not removed by that history-window cleanup. They remain while the app is installed unless access removal requires PackProof data to be erased.

Uninstall and erasure

Shopify’s app-uninstalled and shop-redaction webhooks erase the shop’s PackProof records, including sessions, catalog snapshots, references, findings, audit runs, jobs, and webhook receipts. A separate keyed lifecycle authority keeps only opaque shop and installation digests, install generations, event kinds, and timestamps so restoring an older application backup cannot restore erased tenant data. It contains no catalog snapshot, reference, finding, access token, or plain shop domain. Removing the required product-read scope preserves merchant evidence, stops catalog access, and pauses monitoring until the current installation and permission are verified again.

Exports already downloaded are controlled by the merchant and are not reachable by PackProof. Webhook delivery and final erasure timing also depend on Shopify delivering the required compliance event to the deployed app.

Security and sharing

PackProof uses the authenticated Shopify app session and requests read_products. Data is not sold. Service providers used to host the deployed app or database may process data only as needed to operate it. Production operators must protect the database, access tokens, lifecycle secret, cron secret, and backups.

Contact and release status

Email justinwalker4233@outlook.com for app data questions.