Last updated: June 23, 2026
Privacy Policy
This Privacy Policy explains how SwapTrak collects, uses, stores, and protects information when merchants, users, and authorized representatives use our app, website, Shopify integration, and related services.
For purposes of this Privacy Policy, “SwapTrak,” “we,” “us,” and “our” refer to the app operator. “You” refers to the merchant, store owner, administrator, authorized user, or other person using the service.
1. Information we collect
We collect and process information necessary to provide order, inventory, fulfillment, reporting, automation, and integration services.
Depending on the features you enable, we may collect or process:
- Account and workspace information, such as name, email address, login credentials, user roles, workspace settings, and authentication information.
- Shopify store information, such as shop domain, store name, installation status, granted permissions, Shopify user/session metadata, and app configuration.
- Order information, such as order numbers, order dates, line items, SKUs, quantities, prices, discounts, taxes, shipping charges, fulfillment status, tags, notes, and other order-related fields.
- Customer and delivery information, such as customer name, email address, phone number, shipping address, billing address, and delivery details when needed to provide order and fulfillment functionality.
- Product and inventory information, such as product names, variants, SKUs, inventory quantities, warehouse/location information, costs, and related operational data.
- Integration information, such as connected service settings, API authorization tokens, webhook configuration, sync status, error logs, and integration activity.
- Usage and diagnostic information, such as pages viewed, actions taken, imports started, syncs completed, errors encountered, device/browser information, IP address, timestamps, and security logs.
- Support communications, such as emails, messages, attachments, screenshots, and other information you choose to provide when requesting help.
We do not intentionally collect sensitive personal information unless it is included in merchant-provided business records or support communications.
2. Information from Shopify
When you install or connect SwapTrak through Shopify, Shopify may provide us with information required to authenticate the installation and operate the app.
This may include:
- Shop domain and store identifiers.
- App installation metadata.
- OAuth access credentials.
- Granted access scopes.
- Shopify session information.
- Webhook events.
- Store, order, product, inventory, fulfillment, and customer-related information within the permissions approved by the merchant.
We use Shopify data only to provide, maintain, secure, and improve the app features you choose to use.
3. How we use information
We use information to:
- Authenticate users and manage access to workspaces.
- Connect Shopify and other requested integrations.
- Import, synchronize, and display orders, products, inventory, fulfillment, and related business records.
- Create reports, operational views, workflows, invoices, exports, automations, and other app functionality.
- Register, verify, and process webhooks.
- Troubleshoot syncs, errors, integration issues, and support requests.
- Maintain security, prevent unauthorized access, monitor abuse, and protect the app.
- Improve app performance, usability, reliability, and feature quality.
- Communicate with you about support, service updates, technical notices, billing, security, and account-related matters.
- Comply with applicable legal, regulatory, platform, and security obligations.
4. AI and automation features
SwapTrak may include AI-assisted features, automation tools, mapping helpers, forecasting, summaries, workflow suggestions, or similar functionality.
When you use these features, relevant business data may be processed to generate outputs, suggestions, mappings, classifications, or summaries. We use these features to help you operate your business, but AI-generated outputs may be incomplete, inaccurate, or unsuitable for your specific use case.
You are responsible for reviewing AI-generated or automated outputs before relying on them for business decisions, customer communications, fulfillment actions, accounting, tax, or legal purposes.
We do not sell merchant or customer data to advertisers. We do not use Shopify customer data for unrelated advertising purposes.
5. How we share information
We may share information with service providers and integration partners only as needed to operate the app and provide requested functionality.
These may include:
- Hosting, database, storage, and infrastructure providers.
- Authentication and security providers.
- Shopify and other connected platforms you authorize.
- Shipping, fulfillment, email, reporting, analytics, or automation providers you choose to connect.
- Support, logging, monitoring, and error-tracking tools.
- Payment or billing processors, if paid features are enabled.
We may also disclose information if required to:
- Comply with applicable law, regulation, subpoena, court order, or legal process.
- Protect the rights, safety, and security of users, merchants, customers, the app, or others.
- Investigate fraud, abuse, security incidents, or unauthorized use.
- Enforce our Terms of Service or other applicable agreements.
We do not sell personal information.
6. Shopify customer data
Some Shopify data processed by SwapTrak may include personal information about a merchant’s customers, such as names, email addresses, phone numbers, shipping addresses, billing addresses, and order details.
Merchants are responsible for ensuring they have the right to use SwapTrak with their store data and for providing any required notices to their customers.
We process Shopify customer data only to provide app functionality requested by the merchant, such as order import, fulfillment workflows, reporting, inventory operations, customer service support, and related operational features.
7. Data retention
We retain information for as long as reasonably necessary to provide the service, maintain business records, comply with legal obligations, resolve disputes, enforce agreements, prevent abuse, and maintain security.
Retention periods may vary depending on:
- The type of data.
- Whether the app remains installed.
- Whether a workspace remains active.
- Whether the data is required for support, security, billing, tax, audit, dispute, or legal purposes.
- Whether deletion has been requested and verified.
When information is no longer needed, we may delete, de-identify, aggregate, or securely retain it as appropriate.
8. App uninstall and deletion
If you uninstall the Shopify app, Shopify access credentials are revoked or disabled immediately, and SwapTrak stops future Shopify sync, import, and writeback through that installation.
Shopify may subsequently send a shop redaction webhook. A valid shop redaction request automatically deletes or redacts Shopify-sourced personal customer and order data while allowing non-personal operational records to be retained where reasonably necessary.
Uninstalling does not delete the entire SwapTrak workspace or unrelated non-Shopify data. An authorized workspace owner may separately request full workspace or account deletion through support, subject to identity and authority verification and applicable retention obligations.
9. Shopify privacy webhooks
SwapTrak receives Shopify privacy-related webhook requests for customer data access, customer redaction, and shop redaction.
A valid customer or shop redaction webhook automatically deletes or redacts applicable Shopify-sourced personal data. A customer data request enters a verified merchant-support workflow so relevant stored personal data can be provided securely. Compliance event records contain safe identifiers and do not store the raw webhook payload or raw customer contact details.
10. Security
We use reasonable administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction.
These safeguards may include:
- Encrypted storage of sensitive integration credentials.
- Access controls.
- Authentication requirements.
- Server-side handling of access tokens and secrets.
- Webhook verification.
- Logging and monitoring.
- Least-privilege access practices where practical.
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your login credentials, controlling access to your workspace, and ensuring that only authorized users access your account.
11. International processing
Information may be processed and stored in locations where our service providers operate. These locations may have data protection laws different from those in your region.
By using SwapTrak, you understand that information may be transferred to and processed in such locations as necessary to provide the service.
12. Your choices and rights
Depending on your location and applicable law, you may have rights to access, correct, delete, restrict, or object to certain processing of personal information.
Merchants may request access, correction, export, or deletion of workspace data by contacting support. We may need to verify your identity and authority before fulfilling a request.
Shopify customers should generally contact the merchant that controls the Shopify store. If we receive a valid request through Shopify’s privacy webhook system, we will process it as required.
13. Children’s privacy
SwapTrak is intended for business use and is not directed to children. We do not knowingly collect personal information from children.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the “Last updated” date above.
If changes are material, we may provide additional notice through the app, website, email, or other reasonable means.
15. Contact
Questions, requests, or concerns about this Privacy Policy or data handling practices can be sent to:
Please include your Shopify shop domain, workspace name, and a description of your request. Do not send passwords, API keys, webhook secrets, or other sensitive credentials by email.