Privacy Policy

Effective date: September 27, 2026
Operator: Apperandi (“we”, “us”)
Contact: Support form

Summary

Apperandi provides Shopify Admin apps (including CombineReady). We process shop and order data only to provide the app you install, and we do not sell personal data.

Who this covers

Merchants who install our Shopify apps, and the customer/order data those merchants already store in Shopify that our apps must read to function.

Data we process (CombineReady)

When you install CombineReady, we access Shopify Admin API data required for the job.

Live OAuth scopes (MVP): read_orders, write_orders, read_customers
We do not request fulfillment-write or draft-order scopes for the tags-only MVP.

Protected Customer Data (PCD): CombineReady requested Shopify Protected Customer Data access so order webhooks and Admin APIs can include customer name, email, phone, and address fields when Shopify returns them. We use that only to identify the same logged-in customer across open orders (sibling detect) and to show sibling context in Admin. Guest ship-to matching stays off by default and is not required for MVP.

Data categories:

  • Orders: id, name, created time, fulfillment/financial status, tags, line items as needed for display; shipping address only if a future guest-match setting is enabled (default off)
  • Customer: id plus PCD fields Shopify allows under our approval (name/email/phone/address as granted), for logged-in customers, to find sibling open orders
  • Shop: domain, and session/token material Shopify provides to keep the app installed

We write order tags (e.g. combine-ready, combine-group:…) that you configure or that ship as defaults.

How we use data

  • Detect multi-open orders and apply/remove tags
  • Show sibling open orders in Admin
  • Provide Scan / settings in the embedded app
  • Operate webhooks (orders/create, orders/updated, orders/cancelled)
  • Diagnose support requests you send via our Support form
  • Meet legal obligations

We do not use order or customer data for advertising. We do not sell personal information.

Storage and processors

App hosting, database, and logs run on infrastructure we control or contract (e.g. Shopify app hosting / cloud providers). Shopify is the system of record for your store data. Webhook and session credentials are stored only as needed to run the app.

Retention

  • Operational data and logs: retained only as long as needed to run and secure the app, then deleted or anonymized
  • On uninstall: we stop processing; we delete or de-identify stored shop credentials and derived app data within a reasonable period (target: 30 days), except where we must keep records for legal/accounting reasons

Sharing

We share data only with:

  • Shopify, as required to operate a Shopify app
  • Service providers who process data on our instructions (hosting, error monitoring, Cloudflare for the site/form delivery, Apple iCloud for our support mailbox)
  • Authorities when required by law

Your choices (merchants)

Uninstall the app in Shopify Admin to revoke access. Use the Support form (topic: Privacy) for deletion requests related to data we store outside Shopify.

Children

Apps are for merchants operating businesses, not directed at children under 13.

International

If you are in the EEA/UK, we process data to perform the contract to provide the app and for legitimate interests in securing and improving it. Use the Support form (topic: Privacy) for privacy requests.

Changes

We may update this policy. We’ll post the new effective date on this page.

Contact

Privacy and support requests: Support form (choose topic Privacy when relevant).