Skip to main content

Open for Agents

Privacy policy

This policy explains the limited information processed by the Open for Agents Shopify catalogue-assurance application.

Effective 2026-07-18. Document version 2026-07-18.1.

Operator

The application is operated by Enoki Limited, a New Zealand company. Contact the privacy team using the monitored address below.

Information processed

  • Shopify installation information, shop domain, granted scopes, offline access token and installation state.
  • Supported product, variant, publication, market, price, availability, disclosure, policy-presence and catalogue-title intent facts.
  • Normalized Storefront Catalog and public-web observations, source health, findings, changes and evidence receipts. Raw Catalog and public-web response bodies are discarded.
  • Scan history, retention settings, finding review actions and one optional encrypted operational-alert email address.
  • Minimized security and reliability logs containing bounded event codes and aggregate measurements.

The app does not request protected-customer-data access or customer, company, order, checkout, payment, transaction, fulfillment, return or staff scopes. Shopify’s standard installation disclosure identifies store-owner name, email, phone number and physical address because those fields are available through the Admin Shop object without a separate staff scope. Open for Agents does not query or persist those store-owner personal details.

Why information is used

Information is used to authenticate the installed shop, perform requested and scheduled read-only comparisons, preserve reproducible evidence, show material changes, deliver configured operational alerts, secure the service and meet Shopify privacy obligations.

Retention and deletion

  • Normalized scan evidence follows the merchant-selected 30, 90, 180 or 365-day retention window.
  • Alert-delivery webhook receipts expire after 90 days.
  • Removing an alert address deletes the encrypted address and cancels pending delivery.
  • Uninstall disables sessions, jobs and alerts. Shopify’s required redaction workflow deletes tenant evidence and retains only a keyed, non-reversible operational reference where required.
  • Supabase Pro retains up to seven daily backups; deleted records may remain in backups for up to seven days and are reconciled before any restore is promoted.

Providers and transfers

Enoki Limited uses Hetzner Cloud for application hosting, Supabase for managed database hosting and backups, and Mailgun for operational email. Information handled for those purposes may be processed outside New Zealand, including in the United States, under applicable contractual privacy and security terms. Availability monitoring receives only service-health status and aggregate operational state; it does not receive merchant catalogue evidence or alert addresses.

Security

Controls include TLS, Shopify authentication, least-privilege scopes, tenant-keyed authorization, bounded outbound requests, encrypted alert addresses, separated secrets, authenticated webhooks, minimized logs, retention controls, dependency review, backups and recovery testing. No system is absolutely secure.

Requests and contact

To request access, correction or deletion, or to ask a privacy question, email [email protected]. Report a security concern to [email protected].