Skip to content
Legal

Privacy Policy

Effective date: August 23, 2026 | Last updated: August 23, 2026

1. Summary

  • We collect the minimum data required to operate the product for you.
  • We never sell personal data and never share it for advertising.
  • For Shopify we request protected customer data at Level 1 only. We do not receive or store customer names, email addresses, phone numbers, or addresses from Shopify.
  • Data is encrypted in transit and at rest, and marketplace tokens get an extra layer of encryption.
  • Retention periods are enforced automatically by scheduled deletion jobs, not just by policy text.

2. Information we collect

We collect the information you provide when creating an account or workspace, the data you enter into the product, the marketplace and financial data you authorize us to synchronize, information generated as you use the product, and any information you send us through support channels. We do not ask for and do not want passwords to third-party services, Seller Central credentials, API keys, or financial account credentials submitted through public forms.

3. Account and workspace data

Account data includes your name, email address, and authentication identifiers managed by our identity provider. Workspace data includes the business name, settings, team members, and role assignments you configure. Workspace data is isolated to your workspace and enforced at the database layer.

4. Shopify data we process, and why

When you connect a Shopify store, Corven OS acts as a processor on your behalf. We request Shopify protected customer data at Level 1 for two purposes: store management and analytics. Specifically, we process:

  • Orders — order identifier and number, creation and processing timestamps, financial and fulfillment status, currency, subtotal, shipping, tax, discount and total amounts, cancellation and closure state, refund amounts, and returns state. Used to show your orders, compute revenue and profitability, and reconcile finance.
  • Line items — variant and product references, SKU, barcode, quantity, and per-line amounts. Used to match Shopify sales to your Corven products and compute cost of goods and margin.
  • Fulfillments and shipments — shipment status, carrier, and tracking reference. Used for fulfillment tracking.
  • Products, variants and inventory — titles, variant identifiers, SKUs, barcodes, prices, and available quantities. Used for catalog and inventory synchronization.
  • Payouts and settlements — settlement amounts and dates. Used for financial reporting.

What we deliberately do not process. We do not request the optional protected customer fields (name, email, phone, address), and we do not request the read_customers or read_all_orders scopes. Our Shopify queries do not select buyer identity, contact details, or shipping addresses, and our database rejects those values on Shopify-sourced orders even if they were ever returned. We also do not store Shopify order tags, order notes, or refund notes, because those are free-text fields that could contain incidental personal information we do not need.

5. Other marketplace and financial data

Other connected marketplaces and providers may return buyer or shipping details required to fulfill orders through those channels; where they do, that data is processed for fulfillment and support only, under the same isolation and security controls. Marketplace and bank credentials are encrypted at rest with application-level AES-256-GCM and are never returned to a browser.

5a. Etsy data we process, and why

When you voluntarily connect an Etsy shop through OAuth authorization, Corven OS may process the Etsy data authorized by you for the features you choose to use. Etsy listing, inventory, order, and payout synchronization is not yet generally live; the descriptions below describe the data our current authorization scopes permit and the purposes for which it would be used when those features are enabled or available.

The current Etsy integration requests only the following authorization scopes:

  • Shop and account information — we access basic Etsy shop and account information necessary to identify and display your connected shop, such as your shop identifier, shop name, and listing currency.
  • Read listing information — we may read your Etsy listing information (for example listing titles, descriptions, images, variations, pricing, and inventory quantities) to display and reconcile your catalog when those features are enabled.
  • Create or update listings — when listing management features are enabled or available, we may create or update listings on your Etsy shop on your instruction, including creating, editing, or publishing listing content you provide.
  • Read transaction and order data — we may read Etsy transaction and order-related data needed for seller management and synchronization features, such as order receipts, line items, totals, and fulfillment state, when those features are enabled.

What this integration deliberately does not request. The current integration does not request buyer_email access, and does not request permission to send Etsy messages or email on your behalf. We do not request access to Etsy buyer contact details beyond what Etsy returns in the authorized transaction and order data above.

Token storage and security. Etsy OAuth access and refresh tokens are stored server-side only and encrypted at rest with application-level AES-256-GCM. Tokens are never exposed to the browser, never logged, and never stored in plaintext in the database.

Your choices and revocation. You can revoke Corven OS's access to your Etsy shop at any time through your Etsy account settings. Disconnecting the Etsy integration within Corven OS causes the stored authorization credentials and tokens to be removed according to our existing deletion and retention implementation described in this policy. You may also request deletion of your Corven OS workspace data in accordance with the process described in the "Your choices and rights" section below.

6. Application usage data

We record operational events needed to run the service: automation runs, decision lifecycle changes, sync job outcomes, error reports, and privileged administrative actions. These records exist to make the product auditable and debuggable. Webhook and API payload bodies are not written to logs, and diagnostics pass through a redaction layer that strips tokens, secrets, and raw provider payloads.

7. Analytics and automated processing

Our analytics, health scoring, intelligence, and advisory features operate on aggregated business data — orders, amounts, inventory levels, costs, and timing. They do not use customer personal data, do not profile individuals, and produce decision support for you rather than decisions about any individual. No automated decision produces legal or similarly significant effects on a customer. We do not use your data or your customers' data to train general-purpose AI models.

8. Demo data

Our demonstration workspace contains synthetic records that are labeled as demo data in the database and in the interface. Synthetic buyer details are fictional and are never mixed with, or presented as, marketplace-sourced customer data.

9. Support data

Messages you send us, and the context you include, are used to answer your request. Internal support access to a workspace is read-only, time-limited, requires a stated reason, and is recorded in an immutable audit log.

10. Cookies

We use cookies and equivalent browser storage that are necessary to keep you signed in and to remember your preferences. We do not use advertising or cross-site tracking cookies. See the cookie policy for details.

11. Data retention and deletion

Retention is enforced by scheduled database jobs, not by policy alone:

  • Marketplace order records, including line items, refunds, and shipments, are deleted 24 months after the order date.
  • When a store is disconnected or the app is uninstalled, its stored access tokens are destroyed immediately and its remaining synchronized data is purged within 30 days.
  • A Shopify shop/redact request deletes that shop's orders, order items, refunds, shipments, listings, payouts, and health records, and destroys its credentials.
  • Workspace data is retained while your workspace is active. On request we delete or anonymize it, subject to records we are legally required to keep. Audit records are append-only and contain no customer personal data.

11a. Bank connection data retention (Plaid)

  • When you disconnect a financial institution, we revoke the connection with Plaid and delete the stored Plaid access credentials and tokens immediately.
  • Plaid-derived financial data — account details, balances, transactions, and the related import records — may be retained for up to 30 days after disconnect to support reconciliation and recovery from an accidental disconnect. A daily scheduled job then deletes that data once it is no longer needed.
  • Certain records may be retained longer only where required for legal, tax, accounting, fraud-prevention, security, or regulatory obligations.
  • An account or data deletion request triggers revocation of your bank connections and deletion of Plaid-derived financial data, subject to those lawful retention requirements.

12. Security

All traffic is served over HTTPS/TLS. The managed database and object storage are encrypted at rest, and marketplace and bank access tokens carry an additional application-level AES-256-GCM encryption layer that is only ever decrypted server-side for a single API call. We apply workspace isolation enforced by row-level security, role-based access control, least-privilege server functions, credential redaction, and immutable audit logging. Details are on the security page. No system is perfectly secure, and we make no guarantee against every possible compromise.

13. Data sharing and subprocessors

We do not sell personal data, and we do not share it for advertising or cross-context behavioral advertising. We share data with the infrastructure providers strictly needed to operate the service: Supabase (database, authentication, storage), Cloudflare (hosting and TLS), Resend (transactional email), and Plaid (only where you connect a financial account). We also exchange data with the marketplaces you explicitly connect, at your instruction, and disclose data where required by law. We do not share your business data with other customers. The current subprocessor list is maintained in the data processing agreement.

14. Your choices and rights

You can access and correct your data in the product, invite or remove team members, adjust notification preferences, and request an export or deletion of your workspace data by contacting us. Depending on where you live, you may have rights to access, correct, delete, port, or restrict processing of your personal data, and to lodge a complaint with a supervisory authority. Because we hold no Shopify customer contact data, requests about a specific Shopify customer are best directed to the merchant, and we support the merchant in answering them.

15. Merchants as controllers

For data synchronized from your connected stores, you are the controller and Corven OS is the processor. Our processing obligations are set out in the data processing agreement, which forms part of our terms.

16. Changes

We may update this policy as the product develops. Material changes will be posted on this page with a new effective date before they take effect.

17. Contact

Privacy questions: hello@corvenos.com. Security reports: security@corvenos.com. Both mailboxes are monitored directly by the team.