Shopify App Privacy & Data Use Notice

Effective date: July 18, 2026

This notice explains how ATTN Labs LLC processes data through the ATTN Labs Data Connector for merchants who authorize the app.

Data we process

With merchant authorization, the connector may process shop and session identifiers; historical order identifiers, timestamps, line items, pricing, refunds, tags, and source or landing-page context; stable Shopify customer IDs; product and variant metadata; inventory information; and unit-cost information when available.

The app does not request customer names, email addresses, phone numbers, physical addresses, payment-card information, passwords, or storefront browsing data.

How we use data

We use authorized data to synchronize commerce information; provide merchant reporting; calculate revenue, product, cohort, retention, attribution, and contribution analyses; perform authorized historical backfills and aggregates; maintain security and reliability; and respond to applicable privacy requests. ATTN Labs does not sell merchant or customer personal data.

Infrastructure and subprocessors

Data may be processed using Google Cloud Platform services, including Cloud Run and Cloud SQL; Amazon Web Services, including S3; and ATTN-controlled PostgreSQL and application-state systems. These systems support app hosting, durable privacy-request handling, reporting pipelines, storage, backup, and operational monitoring.

Retention and deletion

  • Raw or customer-level reporting artifacts are generally retained for up to 180 days, unless an active merchant reporting engagement requires agreed historical continuity.
  • Logs and transient operational state are generally retained for 90 days or less where practical.
  • Aggregated or pseudonymized reporting may be retained while the merchant relationship remains active or as otherwise agreed.
  • Applicable customer or shop redaction requests are recorded in a durable compliance queue and targeted for deletion or anonymization within 30 days, unless retention is legally required.

Security

Controls include OAuth authorization, least-privilege read-only scopes, webhook HMAC verification, TLS in transit, encryption at rest, access controls, service accounts, logging, and monitoring. The connector does not modify checkout, orders, products, customers, or inventory.

Merchant control and privacy rights

Merchants can review connection and permission status, reauthorize permissions, or uninstall the connector. Shopify privacy webhooks are used to receive customer data requests, customer redaction requests, and shop redaction requests. To ask a question or exercise an applicable privacy right, contact us below.

Contact

ATTN Labs LLC
Austin, Texas
ian@attnlabs.com