What data is collected
- Shop domain, OAuth access token, granted scopes, install and subscription state.
- Order metadata needed to answer support requests, including order name, fulfillment status, and tracking information.
- Inbound email sender, subject, body, timestamp, and processing outcome.
- Merchant settings including language, greeting, signature, support email, and encrypted SMTP credentials.
Why data is collected
Valyn uses this data to classify incoming emails, find matching Shopify orders, generate order-support replies, send those replies through merchant SMTP, and show logs and statistics to the merchant.
How Shopify data is processed
Shopify data is requested only for installed merchants and only when needed for order support automation or dashboard display.
Customer and order data usage
Customer email and order data are used to identify the correct order and produce a relevant tracking or fallback response.
Email data usage
Forwarded emails are parsed so Valyn can detect intent and create an audit log. Raw inbound MIME files are retained in S3 for 30 days and then expire automatically.
Data retention
- Raw inbound MIME files expire after 30 days.
- Email logs are retained while the app remains installed unless deletion is requested.
- Shop data is deleted after Shopify shop/redact processing following uninstall.
Data deletion
Valyn responds to Shopify GDPR webhooks for customer redaction and shop redaction. Merchants may also contact support for data questions.
Third-party processors
- Shopify for app installation, billing, and order data.
- Vercel for application hosting.
- Amazon Web Services for S3, SNS, SES, and DynamoDB infrastructure.
Security measures
Valyn uses limited permissions, encrypted SMTP credentials, protected session-token APIs, webhook HMAC checks for Shopify webhooks, and structured logs for operational review.
Merchant rights
Merchants can request access, deletion, or clarification by contacting support. Customer data requests are handled through Shopify privacy webhooks and support follow-up.