Watchwick LogoWatchwick
Terms of ServiceInstall App
Compliance & Transparency

Privacy Policy

Effective Date: October 1, 2026 · Version 1.0

1. Overview & Who We Are

Watchwick is an operations monitoring and silent revenue loss detection application built specifically for Shopify merchants. Watchwick continuously inspects operational data — orders, fulfillment requests, tracking details, authorization expirations, refund statuses, and inventory counts — and alerts store staff when operational bottlenecks or revenue leaks occur.

This policy explains what information Watchwick accesses, how that data is stored and protected, and our strict non-collection of customer Personal Identifiable Information (PII). For any privacy inquiries, reach us at security@watchwick.com.

2. What We Read from Shopify (Strictly Read-Only)

Watchwick operates strictly on a read-only basis. The application never alters store settings, updates product details, modifies inventory, or changes customer orders. We request the following explicit scopes:

  • read_orders: To detect unfulfilled order backlogs, cancellation surges, and payment authorization delays.
  • read_fulfillments & read_merchant_managed_fulfillment_orders: To monitor fulfillment flow and identify tracking drops.
  • read_third_party_fulfillment_orders: To detect rejected or stalled 3PL fulfillment requests.
  • read_inventory & read_locations: To flag stock depletion and multilocational divergences.
  • read_products: To detect erroneous or risky price shifts.
Zero Customer PII Policy

Watchwick intentionally excludes all customer personal identifiers. We do not read, process, or store customer names, email addresses, telephone numbers, shipping addresses, credit card numbers, or customer notes. Automated build-time tests verify that GraphQL and REST queries never request customer PII.

3. Merchant Staff Data

To authenticate store staff inside the Shopify Admin embedded app and deliver incident notifications, Watchwick retains:

  • Shopify staff user ID, internal role (Admin, Responder, Viewer), and notification preferences.
  • Verified staff email address (provided via Shopify OAuth) exclusively for sending transactional alert emails.
  • Audit logs of actions performed within Watchwick (acknowledging incidents, changing monitor thresholds).

4. Data Retention and Lifecycle

We apply strict time-to-live policies to keep stored data minimal:

Data CategoryRetention Window
Webhook deduplication keys48 hours
Order transaction & fulfillment records90 days from last update
Monitor evaluation history30 days
Incident logs & baseline metricsRetained while app is installed
App uninstallationStore data fully erased within 48h compliance webhook

5. Security Architecture

  • Row-Level Security (RLS): Multi-tenant isolation is enforced at the database kernel level in PostgreSQL. Tenants cannot access another store's records.
  • Token Encryption: Shopify offline access tokens and Slack bot credentials are encrypted at rest using AES-256-GCM authenticated encryption.
  • In-Transit Security: 100% of network traffic terminates via TLS 1.3 with automated HSTS enforcement.
  • Subprocessors: We use audited infrastructure providers: Oracle Cloud Infrastructure (Hosting), Resend (Transactional Email), and Slack (Notification webhooks).

6. Contact Information

For questions regarding this policy or data processing terms, email security@watchwick.com.