Privacy
What we read, and what we never receive
Autopsify reads a Shopify store's order economics to produce a diagnostic. It does not receive your customers' names, addresses, phone numbers or email addresses, and it is built so that it cannot.
Read-only Shopify access · 180-day retention
Status
What is settled, and what is not
The statements on this page describe the software and are checked against it by an automated test suite. The parts of a privacy notice that depend on a legal entity are not settled, and are listed below as outstanding rather than filled in. This page has not been reviewed by a lawyer.
Outstanding
These are not yet settled. They are named here rather than left blank or filled with a placeholder.
- Contracting entity
- Autopsify is operated by its founder. No company has been incorporated, so no company name, number or registered address is stated on this site. None is invented in the meantime.
- Legal review
- These pages have not been reviewed by a lawyer and are not presented as if they had been.
- Sub-processors
- The infrastructure providers used to host the application and its database are not yet published as a list, and no data processing agreement has been signed with any of them.
- International transfers
- The transfer basis depends on the hosting region and the contracting entity's jurisdiction, neither of which is settled.
- Backup retention
- Deletion described on this site refers to the live database. Whether, and for how long, data persists in the hosting provider's backups has not been verified, so nothing is claimed about it.
Shopify data
What a connected store gives us
Autopsify requests two read-only Shopify scopes and no others: read_orders and read_products. There are no write scopes, and read_customers is deliberately not requested.
What we store
Order totals, tax, discounts, refunds, line items and quantities; the product catalogue; abandoned-checkout counts; the unit costs you enter yourself; and advertising spend at account level if you connect an ad account.
What we never store
Customer names, email addresses, phone numbers, billing and shipping addresses, and IP addresses. Personal fields are stripped from every Shopify payload before it reaches the database; what is kept from a customer record is an opaque Shopify identifier and nothing else.
Why it cannot arrive later
This is a scope decision, not a filter over data we hold. Fields we do not request are not returned to us by Shopify at all, and the app operates under Shopify Protected Customer Data Level 1.
About you
Information you give us directly
Your business contact details — name, business email, company — when you get in touch or buy a diagnostic, and the unit costs you enter. Used to correspond with you, produce your Blueprint and keep ordinary business records.
Retention
How long order data is kept
Order and abandoned-checkout data is kept for 180 days, then deleted automatically by a scheduled job. A record ages from the date the order was placed, not from the last time we touched it, so an order that is edited or re-synced later does not restart its own clock. Deleting an order also deletes its line items, refunds and related records.
Product catalogue data is kept while the app is installed. Business correspondence is kept for as long as the relationship and any legal obligation require.
If you uninstall
We stop reading your store immediately and discard the access credential as soon as Shopify tells us the app was removed. Your stored store data is deleted when Shopify sends the shop redaction request, which follows within a few days. You can also ask us to delete everything at any time, and we will confirm when it is done.
Sharing
Who else sees it
We do not sell your data, we do not share it with other customers, and we do not use it to train any model — Autopsify's analysis is deterministic arithmetic and no part of a Blueprint is generated by a language model. Infrastructure providers that process data on our behalf are listed in the outstanding items above; that list is published before any merchant data is processed under a signed agreement.
Your rights
What you can ask for
Access, correction, deletion, restriction, objection and portability, and the right to complain to a data protection supervisory authority. To ask for any of them, or to ask us to delete everything, use the contact page.