Privacy Policy
Last Updated: July 13, 2026
This app and website are operated by Timvw.
This Privacy Policy describes how Shop Vector ("we", "our", or "us") handles data when you install or use the Shop Vector application (the "App") via the Shopify App Store.
1. Zero-Knowledge Architecture & Data Minimization
Shop Vector is architected strictly as a high-availability infrastructure routing layer and "shock absorber." We operate under a strict Zero-Knowledge data policy.
- No Value Extraction: While our pipeline transformation engine allows you to restructure, rename, and remap JSON payload keys and schemas on the fly, our system processes these structures blindly. We never read, extract, analyze, or log the actual data values contained within those fields.
- No Access to Raw Data: To maintain complete security, raw webhook payload values are never permanently written to user-accessible databases or surfaced anywhere within the Shop Vector dashboard.
2. Transit Streams & Retention Windows
When Shopify fires a webhook event to your store's dedicated Shop Vector ingress endpoint, the data enters an isolated, encrypted event-streaming topic:
- Transit & Buffering: Webhook payloads exist entirely as encrypted transient messages within your store's dedicated stream, held safely before being processed by your pipelines.
- 3-Day Deletion Window: To guarantee system resilience and handle downstream endpoint outages or extended incremental back-offs, data remains in your secure event topic for a strict maximum of three (3) days, after which it is permanently discarded.
- Error-Only Observability: The monitoring dashboard only captures, exposes, and logs transport metadata—such as pipeline names, event topics, execution timestamps, and network/HTTP error status codes returned by your destination systems.
3. Cryptographic & Credential Security
Because Shop Vector manages sensitive integration keys, we treat your authentication layers with enterprise-grade protection:
- All inbound connections are verified using upstream Shopify HMAC signatures.
- All outbound credentials—including custom HTTP headers, OAuth2 tokens, and handshake secrets—are strictly encrypted at rest and in transit.
4. Mandatory Webhook Compliance (GDPR / CCPA)
We fully support and comply with Shopify's mandatory data protection framework:
- Customer Data Requests (
customers/data_request): Because we maintain no long-term databases or indexable caches of customer data values, no historical customer profiles exist on our systems to extract. - Customer Redaction (
customers/redact): Any real-time erasure requests are managed upstream by Shopify. Because our data streams automatically purge data on a rolling 3-day loop, no historical data remnants persist. - Shop Redaction (
shop/redact): Upon request, your store's pipeline schema configurations, webhook secrets, and routing parameters are immediately flagged for total deletion from our control servers.
5. Contact & Support
If your compliance team requires formal verification of our data transit practices, please contact us at: [email protected]
