1.1. This Privacy Policy (this “Policy”) describes the practices of WeLynk LLC, a limited liability company organized under the laws of the State of Alabama (the “Company,” “we,” “us,” or “our”), with respect to the collection, use, processing, retention, and disclosure of information in connection with Cleartill, a Shopify application that presents merchants with their net profit after cost of goods sold, payment-processing fees, shipping, and advertising spend, together with the Company’s related servers, websites, and electronic mail communications (collectively, the “Service”).
1.2. The Service is a business-to-business application made available to merchants (“Merchants,” “you,” or “your”) that operate online stores on the Shopify platform (“Shopify”). This Policy applies to information processed through the Service. It does not apply to Shopify’s own processing of your data, which is governed by Shopify’s agreements and privacy policy, nor to any other product or service of the Company.
1.3. Controller and processor roles. With respect to a Merchant’s account and contact information, the Company acts as a controller. With respect to the store data that the Company accesses from a Merchant’s Shopify store in order to provide the Service, the Company acts as a processor and service provider on the Merchant’s behalf and under the Merchant’s instructions, and processes such data solely to provide the Service and for no independent purpose of the Company. As between a Merchant and the individuals whose data may appear in store records, the Merchant is the controller.
2.1. Authorized scopes. Upon installation, the Service requests only two Shopify access scopes and no others: read_orders and read_products. The Service does not request write access to any store resource, and does not request access to customer accounts or marketing. Separately from installation, the Service declares one optional scope, read_shopify_payments_accounts, which is never requested at installation, is granted only if a Merchant expressly chooses to grant it from within the Service, and may be declined without affecting any other function; its sole use is described in Section 2.5.
2.2. Order data. Under the read_orders scope, the Service accesses order records for a trailing sixty (60) day window, limited by field selection to financial and line-item information only, namely: order and line-item identifiers, timestamps, financial status, cancellation status, test-order status, currency, subtotal, discounts, taxes, shipping charges, total amounts, refunds, and line-item titles, quantities, prices, and product and variant identifiers. Access to order data constitutes access to Protected Customer Data at Level 1 under Shopify’s Protected Customer Data requirements, and the Company maintains the corresponding data-use declaration with Shopify.
2.3. Product data. Under the read_products scope, the Service accesses the Merchant’s product catalog, including product and variant titles, prices, vendors, product types and categories, images, stock-keeping units, barcodes, weights, and Merchant-entered unit costs.
2.4. Store record. On each authenticated load, the Service reads the store’s own record, namely its Shopify store identifier, time zone, currency, and the store and contact electronic mail addresses that the store publishes to installed applications. The time zone and currency are required to compute a Merchant’s figures in that store’s local day and currency. The electronic mail address is retained only as described in Section 4.1 and is used only as described in Section 5.5. Where a store does not make these electronic mail addresses available, the Service continues to operate without them.
2.5. Shopify Payments payout data (optional). Where, and only where, a Merchant has expressly granted the optional read_shopify_payments_accounts scope described in Section 2.1, the Service reads the Merchant’s own Shopify Payments balance transactions in order to replace its estimated card-processing fee with the fee the Merchant was actually charged. The fields read are limited to the transaction identifier, transaction type, test-transaction status, transaction and fee amounts, the associated payout’s identifier and status, and the identifier of the associated order. No customer information, bank-account information, or payout destination is read. A Merchant who does not grant this scope, or whose store does not use Shopify Payments, keeps the estimated figure, which the Service labels as an estimate throughout.
3.1. The Service is designed so that it does not receive, process, or store the personal information of a Merchant’s customers. The Company does not access, request, or store customer names, electronic mail addresses, physical or billing addresses, or telephone numbers. The Service’s order-data feed is restricted by field selection to the financial and line-item fields enumerated in Section 2.2, and order records are stored without any customer-identifying field. The Company does not construct profiles of, and does not track, any Merchant’s individual shoppers.
3.2. The Service is embedded within the Shopify administrative interface and authenticates each request using Shopify session tokens. The Service does not employ advertising cookies, cross-site tracking technologies, third-party behavioral analytics, or tracking of individuals across websites or services. The Service does measure its own product usage and its own electronic mail, as described in Section 4.5: this measurement is first-party, is recorded against the store’s domain rather than any individual, uses no third-party analytics provider, sets no cookies, and does not follow anyone beyond the Service’s own pages and messages.
The Company stores the following categories of information for the purpose of providing the Service:
4.1. Merchant and store information: the store’s myshopify.com domain, Shopify store identifier, time zone, currency, plan status, and installation state; the electronic mail address that a Merchant optionally provides in order to receive the Service’s profit emails, being the daily profit digest and the monthly summary described in Sections 5.3 and 5.7; a record of whether, and when, a Merchant has asked the Company to stop sending the messages described in Section 5, and of when a monthly summary was last sent; operational timestamps recording when the Service last completed an authenticated load for the store, when Shopify last delivered a webhook for it, whether and when the initial import was scheduled, and whether and when Shopify requested erasure, all of which exist so that the Service can tell a store that is still in use from one that has gone (see Section 9.5) and none of which describes any individual; and the store or contact electronic mail address read from the store record at installation as described in Section 2.4, which the Service retains as a fallback recipient for the messages described in Section 5.5;
4.2. Order financial records: the order and line-item financial fields enumerated in Section 2.2, stored without customer-identifying information, together with associated refunds;
4.3. Product and cost records: product and variant catalog data, unit costs, and the source and confidence of each cost (Merchant-entered, imported from Shopify, or estimated as described in Section 6); and
4.4. Derived figures: daily profit rollups computed from the foregoing, the flat shipping cost a Merchant enters, and advertising-spend figures, which are either entered by the Merchant or imported from an advertising account the Merchant has connected as described in Section 4.8;
4.5. Product-analytics events: a record of significant events in the Service’s own lifecycle, so that the Company can measure whether the Service works for the Merchants who install it. Each record consists of the application name, the store’s myshopify.com domain, an event name drawn from a fixed list (for example, that the application was installed, that the initial import finished, that costs were confirmed, that a profit figure was first viewed, that a subscription began, that a digest was sent, opened, or clicked, or that the application was uninstalled), a timestamp, a small set of non-textual properties limited to numbers, true/false values, and values from fixed lists, and a de-duplication key. These records contain no customer information, no free text, and nothing a Merchant types. They are stored in the Company’s own database and are not sent to any third-party analytics provider. Where an event relates to electronic mail, it is recorded by a one-pixel image or a redirect through the Company’s own servers, as described in Section 3.2; and
4.6. Outreach list: where the Company has contacted a store directly, the store’s myshopify.com domain and a campaign label, entered by the Company by hand, so that an installation can be attributed to that outreach. This list contains publicly available store domains only.
4.7. Payment-fee records: where a Merchant has granted the optional scope described in Section 2.5, a record of each Shopify Payments balance transaction relevant to a fee, consisting of the transaction identifier, the identifier of the associated order, the transaction type, the transaction and fee amounts, the associated payout’s status, and whether the transaction was a test. These records contain no customer information and no bank-account information; and
4.8. Advertising-account connection records: where a Merchant expressly connects a Meta or Google Ads account, the Service stores the authorization credentials that the Merchant’s grant produces, being an access credential and, for Google, a refresh credential, together with the identifier and display name of the advertising account the Merchant selected, that account’s currency, the credential’s expiry, and the state and any error of the most recent import. The credentials are stored encrypted at rest using authenticated encryption with a key held separately from the database. They are never displayed to the Merchant, never sent to any party other than the advertising platform that issued them, and never included in any response the Service sends to a browser. They are deleted when the Merchant disconnects the account, and when the application is uninstalled. The Service uses them only to read daily advertising-spend totals, and never to create, modify, or read the content of advertisements.
The Company processes the information described in this Policy solely for the following purposes:
5.1. to compute and present the Merchant’s net profit, product margins, cost breakdowns, and related figures within the Service;
5.2. to estimate missing product costs by the automated means described in Section 6;
5.3. to compose and deliver the optional daily profit digest to the electronic mail address a Merchant provides. That message identifies the Company by name and postal address and carries a link by which the Merchant may stop it in a single action without signing in, as described in Section 5.7;
5.4. to operate, secure, maintain, and support the Service, and to comply with applicable law and with the Company’s obligations to Shopify;
5.5. to send a single message after a store uninstalls the Service, asking why, so that the Company can improve the Service. That message is sent at most once per installation, is never followed by any further message or sequence of its own, is not sent at all where the Merchant has asked the Company to stop writing to them, is plain text, identifies the Company and states why it was received, and is addressed to the digest address where one was provided and otherwise to the address described in Section 2.4. The Company honors a reply asking that it not write to an address again; and
5.6. to measure, in aggregate and by reference to the store’s domain rather than to any individual, whether Merchants successfully activate and continue to derive value from the Service, using the records described in Section 4.5; and
5.7. to send, at most once every thirty days and only to a store on the free plan, a summary of that store’s own figures for the preceding thirty days, being its net profit, its order count, its margin, and the number of its products that sold at a loss, together with a reference to the Company’s paid plans. That message is sent only to the address a Merchant provided as described in Section 4.1, is not sent where the store had no sales in the period, names no individual product, states why it was received, identifies the Company by name and postal address, and carries a link by which the Merchant may stop it in a single action without signing in. The Company records and honors that request, which is sitewide: a single request stops every message the Company sends about that store, being the digest described in Section 5.3, the message described in Section 5.5, and this one. The Company honors it for as long as it holds the store’s records, which are erased as described in Section 9. A Merchant who wishes to resume may do so by saving a digest address again in the Service’s settings, which the Company treats as renewed consent; clearing that address is not consent and does not resume anything.
The Company does not sell information, does not share information for advertising, and does not use store data for any purpose other than providing the Service.
6.1. Where a product lacks a Merchant-entered or Shopify-imported cost, the Service may estimate that cost using an artificial-intelligence service provided by Anthropic, PBC (“Anthropic”). For this purpose, the Company transmits product-catalog information only, namely: product and variant titles, vendor, product type and category, product tags, an excerpt of the product description, stock-keeping unit, barcode, weight, price, and the product image. To make estimates accurate for the Merchant’s own catalog, the Company also transmits a small sample of that Merchant’s own confirmed unit costs, together with the corresponding product titles and prices, as reference examples. The Company does not transmit order data, sales or financial totals, refund data, or any customer information to Anthropic.
6.2. Anthropic processes such data on the Company’s behalf as a service provider, subject to contractual restrictions that prohibit use of the data to train Anthropic’s models or for Anthropic’s own purposes. Estimated costs are identified as estimates within the Service, and a Merchant may override any estimate at any time.
7.1. Sub-processors. The Company engages the following categories of service providers, each of which processes information on the Company’s behalf, for the purposes described in this Policy, under written contracts that restrict processing to the Company’s instructions and require appropriate confidentiality and security:
| Sub-processor | Purpose | Location | |---|---|---| | Amazon Web Services, Inc. | Cloud hosting (compute and database) and transactional electronic mail delivery | United States (us-east-1) | | Cloudflare, Inc. | Edge network, transport-layer security, and denial-of-service protection | United States / global | | Anthropic, PBC | Automated product-cost estimation (product metadata only; see Section 6) | United States | | Google LLC | Web-font delivery on the Company’s public marketing page only. Not used by, and not loaded within, the embedded application. A visitor’s internet-protocol address is disclosed to Google when that public page is loaded | United States / global |
7.2. Legal disclosures. The Company may disclose information where it believes in good faith that disclosure is required or permitted by applicable law, including in response to valid legal process, to protect the rights, property, or safety of the Company or others, or to enforce the Company’s agreements.
7.3. Corporate transactions. In connection with any merger, acquisition, financing, reorganization, or sale of all or a portion of the Company’s assets, information may be transferred to the parties to such transaction and to a successor entity, subject to this Policy or a successor policy.
7.4. No sale; no advertising. The Company does not sell information, does not share information for cross-context behavioral advertising, and does not disclose information to any third party for such third party’s own marketing or advertising purposes, and has not done so during the twelve (12) months preceding the Effective Date of this Policy.
7.5. What is disclosed to an advertising platform. Where a Merchant connects a Meta or Google Ads account, the only information the Service transmits to that platform is what the authorization protocol itself requires: the Company’s own application credentials and the authorization code or credential issued by that platform, together with the identifier of the advertising account the Merchant selected and the date range being requested. No store data, order data, product data, customer data, or profit figure is transmitted to either platform at any time. The exchange is one-directional in substance: the Service reads advertising-spend totals out, and sends nothing about the store in.
8.1. Information processed by the Service is stored on infrastructure operated by Amazon Web Services in the United States (the us-east-1 region).
8.2. The Company maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including: encryption of data in transit using Transport Layer Security; encryption of data at rest on the Company’s database volume; restriction of the application origin so that it is reachable only through the Company’s edge network; verification of the authenticity of Shopify webhooks by cryptographic signature; and access controls limiting personnel access to information necessary to their functions. No security program eliminates risk entirely, and the Company does not warrant or guarantee the absolute security of any information.
8.3. Security incidents. In the event of a breach of security resulting in the unauthorized access to or disclosure of information processed through the Service, the Company will notify affected Merchants and, where required, applicable regulators, in the manner and within the time periods required by applicable law, and will take reasonable measures to contain and remediate the incident.
9.1. The Service computes and displays a Merchant’s profit for a trailing sixty (60) day window and does not surface order history beyond that window. Order, product, and derived records are retained for so long as the Service remains installed on the store, and are deleted upon uninstallation as described in Section 9.2.
9.2. Uninstallation. When a Merchant uninstalls the Service, the Company marks the store for deletion and, after a recovery window of forty-eight (48) hours, purges the store’s data from its active systems: the store record, its order, product, cost, and derived records, the outreach-list entry for that store if any, and the stored Shopify access credentials are deleted outright. Reinstallation within that window cancels the pending deletion, so that a Merchant who uninstalls and reinstalls does not lose configured costs and settings.
9.3. Product-analytics events are pseudonymized, not deleted. The records described in Section 4.5 are treated differently, and the Company states the difference plainly. At deletion, the store’s myshopify.com domain in those records is replaced with an irreversible-in-practice keyed hash and the de-duplication key is cleared; the rows themselves are retained indefinitely, so that historical measurements of the Service do not disappear. This is pseudonymization, not anonymization. myshopify.com domains are public and can be enumerated, so a party holding the Company’s hashing key could reconstruct the mapping. The Company therefore holds that key only on its own servers and treats it with the same sensitivity as the data it protects. The retained records contain no customer information and no Merchant-entered text, as described in Section 4.5.
9.4. Shopify compliance webhooks. The Company honors the mandatory Shopify compliance webhooks. Because the Company does not store customer personal information: a customers/redact request is satisfied without further action, as there is no customer personal information to erase; a customers/data_request is answered accordingly; and a shop/redact request results in deletion of the store’s data on the terms set out in Sections 9.2, 9.3, and 9.5.
9.5. A store that returns discharges an erasure request, and the Company states that plainly rather than omitting it. Shopify issues a shop/redact request approximately forty-eight (48) hours after an uninstallation, and delivers it only once. It therefore routinely reaches stores whose Merchant has since reinstalled the Service. Because deleting a reinstalled store’s data is not recoverable, the Company does not act on such a request immediately. It records the request durably and then observes the store for a period of up to twenty-one (21) days, which is within the thirty (30) day period Shopify allows for completing the request.
If, during that period, the store demonstrates that the Service is installed and in use, the request is treated as discharged: the store’s data is retained, and the lifecycle electronic mail described in Section 5 resumes. A store demonstrates use in either of two ways, both of which require a request authenticated by Shopify: a Merchant opening the Service in the Shopify admin, or Shopify delivering an order, refund, product, inventory, or shop-update webhook for that store, which Shopify does only for installed applications. If the period elapses with no such demonstration, the store’s data is deleted on the terms set out in Sections 9.2 and 9.3.
The Company states this exception because a policy asserting unconditional deletion within thirty (30) days would be inaccurate in the reinstallation case, and an inaccurate statement in a privacy policy is a more serious defect than an omitted one.
9.6. Advertising-account credentials. Disconnecting an advertising account within the Service deletes the stored credentials for that account from the Company’s systems, and uninstalling the application deletes them for every connected account. Because the underlying authorization is held by the advertising platform rather than by the Company, a Merchant who wishes to revoke the grant at its source should also remove the Company’s application from the security or connected-applications settings of their Meta or Google account. Advertising-spend figures already imported are retained as part of the Merchant’s historical profit records, and are removed by the erasure processes described above rather than by disconnection, so that disconnecting an account does not silently alter previously reported profit.
10.1. Merchants. A Merchant may (a) uninstall the Service at any time, which initiates deletion of the store’s data as described in Section 9; (b) request access to, correction of, or deletion of the Merchant account and contact information the Company maintains; and (c) contact the Company with any question concerning this Policy. Requests may be submitted to [email protected].
10.2. Individuals whose data appears in store records. Because the Company processes store data as a processor on the Merchant’s behalf, and does not store customer-identifying information, an individual seeking to exercise rights with respect to a store’s records should direct the request to the Merchant that operates the store, which is the controller of such records. The Company will assist the Merchant in responding to such requests as required by applicable law and by the Company’s obligations to Shopify.
The Service is operated from the United States, and information is processed and stored in the United States, where data-protection laws may differ from those of your jurisdiction. By installing or using the Service, you acknowledge that information will be transferred to and processed in the United States as described in this Policy.
The Company may amend this Policy from time to time. In the case of a material amendment, the Company will indicate the change by an updated “Last Updated” date and, where appropriate, provide notice to Merchants by electronic mail or within the Service. Your continued use of the Service following the effectiveness of an amendment constitutes your acknowledgement of the amended Policy.
Inquiries and requests concerning this Policy or the Company’s data practices may be directed to:
Privacy and data requests: [email protected]
Legal matters: [email protected]
General support: [email protected]
Mailing address: ` WeLynk LLC c/o Northwest Registered Agent Service, Inc. 212 W. Troy St. STE B Dothan, AL 36303 `
© 2026 WeLynk LLC. All rights reserved.