Skip to content
← Back to ProfitShield

Privacy Policy

Last updated: August 31, 2026

ProfitShield reads your Shopify catalogue, discounts and the monetary side of your orders. It does not read, receive or store your customers. This page sets out exactly what is kept, why, and for how long.

1. Summary

ProfitShield is a profit analysis app for Shopify stores, operated by HOX SINCE 2019 LTD. This policy explains what the app stores, what it deliberately does not store, and how long it keeps anything at all.

The short version: we store your catalogue, your discounts and the monetary side of your orders. We do not store your customers. Names, email addresses and postal addresses are removed from the data before it is written anywhere, and the app never asks Shopify for permission to read your customer records in the first place.

In data protection terms, you are the controller of your store's data and HOX SINCE 2019 LTD is a processor acting on your instructions. For the small amount of information you give us directly - a message sent through the contact form - we are the controller.

2. What we store

Store record: your myshopify.com domain, currency, timezone, plan, sync status and install date, plus an access token for the Shopify API which is encrypted at rest with AES-256-GCM.

Products and variants: title, handle, status, vendor, product type, SKU, price, inventory level, cost per item, and where that cost came from (Shopify, manual entry, CSV import, or none).

Collections: title, handle, and which products belong to them - used to work out what a discount actually applies to.

Orders: order number, currency, subtotal, discount total, shipping, tax, refunds, order total, financial status, whether it is a test order, and the date it was processed. Line items are stored with title, quantity, price, per-item discount, and a snapshot of the product cost at the time of sync, so that historical profit is never recalculated with today's costs.

Discounts: title, type, value, status, schedule, and a summary of what they apply to.

Settings and results you create in the app: cost settings (average shipping, payment fee percentage and fixed fee, packaging), promotion simulations with their inputs and formula version, alerts, and your subscription state.

Notification settings: the email address you choose for alert and summary emails (seeded from your store's own contact address, and yours to change or blank at any time), and a ledger of which summary emails have already been sent so you are never sent the same one twice.

Operational records: a short-lived log of processed Shopify webhook IDs used to discard duplicate deliveries, and application logs that identify a store by its domain or internal ID.

Contact form: if you send us a message from this site, we store the name, email address and message you typed.

3. What we never store

We do not store your customers. No names, no email addresses, no phone numbers, no billing or shipping addresses, no IP addresses from orders, no payment details, and no customer IDs.

This is enforced in two places rather than promised once. First, the app does not request Shopify's customer read scope, so that data is not available to it. Second, incoming order webhooks are projected down to the fields listed above - order totals and line items - before they are handed to the background queue, so customer fields never reach our queue or our database even in transit.

We never sell, rent or share your data with anyone for advertising, and we do not use your store data to train machine learning models. We do not combine data across merchants; there are no cross-store benchmarks in this version of the app.

4. The 60-day order window

The app imports orders from the last 60 days only. That is the standard order access window Shopify grants without additional approval, and we deliberately did not apply for access to your full order history.

The practical effect: profit figures and trends are based on a rolling recent window rather than your store's entire history.

5. Why we process this data

To provide the app you installed: calculating margins and net profit, grading discounts, generating alerts, running simulations, and producing reports.

To bill you correctly through Shopify Billing, including counting orders against your plan allowance.

To keep the service working and secure: deduplicating webhooks, retrying failed jobs, diagnosing errors.

To answer you when you contact us.

The legal basis for processing store data is the contract between us (these are the instructions you gave us by installing the app). For contact form messages it is our legitimate interest in replying to you.

6. How long we keep it

Store data is kept for as long as the app is installed, and is refreshed continuously so that it mirrors your Shopify store rather than accumulating history beyond the 60-day order window.

When you uninstall, we delete it. Shopify sends an uninstall notification, and the app deletes the store record and everything attached to it - products, variants, collections, orders and line items, discounts, campaigns, alerts, simulations, cost settings, subscription records and sync state - together with the authentication session and the webhook deduplication rows for that store. This happens within 48 hours of uninstall, and in practice immediately on receipt of the notification.

Shopify's shop/redact request, which arrives some days after uninstall, is honoured as a backstop and runs the same deletion again, so a missed uninstall notification cannot leave data behind.

One thing is deliberately kept after you uninstall: an anonymised, keyed fingerprint of your shop domain together with the date your free trial ends. It is retained so that reinstalling the app cannot restart the 14-day trial. The fingerprint is a one-way keyed hash - it cannot be reversed into your shop domain, it is not linked to any of your store data, and it carries nothing else. If you reinstall, it is used only to work out whether your original trial period has already run out.

Contact form messages are kept while we deal with your enquiry and for a reasonable period afterwards, and are deleted on request.

Application logs are retained for a short operational period. They identify stores, never customers.

7. Shopify's mandatory privacy requests

The app implements the three privacy webhooks Shopify requires of every app.

customers/data_request - a customer of your store has asked for the data an app holds about them. We return nothing, because we hold nothing about them; the request is logged.

customers/redact - a customer has asked to be erased. There is nothing to erase, because customer data is stripped before storage; the request is logged.

shop/redact - sent after a store uninstalls the app. It triggers the full deletion described above.

8. Subprocessors

We keep the supply chain deliberately short, and we name it. Fly.io hosts the application, its background worker, the PostgreSQL database and the Redis job queue, in the European Union (Frankfurt). Resend delivers the app's emails - alert digests, summaries and contact form notifications. Sentry receives error reports so failures can be diagnosed; those reports identify stores, never customers. Cloudflare provides DNS for this domain and routes inbound email sent to our support address.

Each of these processes data only to run the service, under a contract with terms at least as protective as this policy. We do not use advertising networks, analytics profiling services, or third-party trackers.

Shopify itself is the source of the store data and remains subject to your own agreement with Shopify.

If this list changes, this page is updated before the new provider handles any of your data.

9. Security and international transfers

Data is transmitted over TLS and stored on managed infrastructure in the European Union (Frankfurt), with access restricted to the people who operate the service. Shopify access tokens are encrypted at rest with AES-256-GCM using a key held outside the database.

Every database query is scoped to the authenticated store, so one merchant's data cannot be reached from another merchant's session.

Where data is processed outside your own country, we rely on the standard safeguards our providers offer for such transfers, including the European Commission's standard contractual clauses where they apply.

No system is perfectly secure. If a breach affects your data, we will notify you and, where required, the relevant supervisory authority without undue delay.

10. Cookies

The embedded app uses a session cookie set during Shopify authentication. It is strictly necessary to keep you signed in, and it is the only cookie the app sets.

This marketing site sets no cookies, loads no fonts, scripts, images or trackers from third-party servers, and does not profile visitors.

11. Your rights

As a merchant, you can ask us for a copy of the data we hold about your store, ask us to correct it, ask us to delete it, or object to how we process it. Most of it you can already see inside the app, and uninstalling deletes all of it.

If you are in the European Economic Area or the United Kingdom, you also have the right to data portability and the right to lodge a complaint with your local data protection authority. If you are in California, you have the corresponding rights under the CCPA; note that we do not sell or share personal information as those terms are defined there.

To exercise any of these rights, write to support@profitshield.shop. We respond within 30 days.

If one of your own customers contacts you about data held by this app, the answer is that we hold none - see the section on Shopify's mandatory privacy requests above.

12. Children

ProfitShield is a business tool sold to merchants. It is not directed at children and we do not knowingly process the data of anyone under 16.

13. Changes to this policy

We update this policy when the app's data practices change. The date at the top of this page always reflects the current version, and material changes are announced in the app or by email before they take effect.

14. Contact

Privacy questions, data requests and complaints: support@profitshield.shop, or use the contact form on this site.

HOX SINCE 2019 LTD is the operator of ProfitShield and the point of contact for this policy.

Questions about this page? Contact us.