How Obarito and its apps collect, use, and protect data. This policy is shared across all Obarito apps; where an app differs, its App Store listing says so.
This Privacy Policy explains how Obarito ("we", "us") handles information when you visit obarito.com or install one of our Shopify apps. Our apps are built to collect as little as possible and to keep your store's data under your control.
Rewindly, our first app, is a catalog change watchdog. It requests only the read_products and write_products Shopify scopes. It does not request, access, or store any Shopify customer personal information, order data, or payment details.
To operate the app, we process:
We do not collect Shopify customer names, emails, addresses, orders, or payment information.
We do not sell personal data and we do not use your store data for advertising.
We do not sell or rent your data. We share it only with the service providers needed to run the app, each bound by a data-processing agreement, and with destinations you choose (for example, your own Slack workspace or email address when you enable notifications):
We may also disclose data where required by law.
Because Rewindly does not access Shopify protected customer data, Shopify's Protected Customer Data requirements do not apply to it. We still follow data-minimization, encrypt data in transit and at rest, and limit retention as described above.
We implement Shopify's three mandatory compliance webhooks:
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise any right, contact us using the details below; the fastest route to deletion is to uninstall the app, which triggers the erasure flow above.
We protect data with encryption in transit and at rest, store your access token securely, and apply least-privilege access controls with regular review. No method of transmission is perfectly secure, but we work to protect your information and to notify you of material incidents as required by law.
Questions or requests about this policy or your data: privacy@obarito.com. The data controller is Obarito. We aim to respond within a reasonable period.