WATCHWICK / YOUR DATA
Privacy Policy
Effective Date: October 1, 2026 · Version 2.0 (Updated October 2026)
1. Overview & Roles Under Data Protection Law
Watchwick ("we", "us", or "our") provides operational monitoring and revenue recovery detection for merchants on Shopify. This Privacy Policy governs how Watchwick accesses, processes, retains, and protects data when a merchant installs and uses our application.
Data Controller: The Merchant is the sole data controller of all store data accessed from Shopify.
Data Processor: Watchwick acts strictly as a data processor on behalf of the merchant, processing operational records solely to perform automated anomaly detection, baseline calculation, and alert delivery as instructed by the merchant.
Watchwick does not sell, rent, monetize, or trade merchant or customer data. We do not utilize merchant data for targeted advertising, cross-merchant benchmarking, or training public AI models.
2. Zero Customer PII Guarantee
Watchwick is engineered with strict data minimization principles. We intentionally exclude all customer personal identifiers:
- Customer names, email addresses, or phone numbers
- Physical billing, delivery, or shipping street addresses
- Payment card numbers, banking credentials, or financial tokens
- Customer order notes, IP addresses, or custom attributes
- Tracking number values (we record tracking counts, never the tracking IDs)
Automated Guardrails: Every database query and GraphQL operation in our codebase is guarded by automated CI regression tests that fail the build if any customer personal data field is queried.
3. Operational Data We Process (Strictly Read-Only)
To monitor operational flow and detect bottlenecks, Watchwick requests explicit read-only scopes:
read_orders: Trailing 60 days of order numbers, timestamps, financial and fulfillment statuses, totals in store currency, and SKU line items.read_fulfillments&read_merchant_managed_fulfillment_orders: Fulfillment order statuses, assigned locations, delivery methods, carrier names, and fulfillment timestamps.read_third_party_fulfillment_orders: 3PL fulfillment requests, rejection states, and response timing.read_inventory&read_locations: Stock quantities per location to detect stockouts and overselling.read_products: Product titles, variants, and price history to flag accidental price drops or zero-price errors.
4. Merchant Staff Personal Data
To authenticate store staff inside Shopify Admin and dispatch operational incident alerts, Watchwick collects:
- Shopify Staff User ID: To map user roles (Admin, Responder, Viewer) and track audit actions.
- Verified Staff Email Address: Provided via Shopify OAuth specifically to deliver incident alerts and digests.
- Audit Logs: Immutable records of actions taken inside Watchwick (acknowledging incidents, saving notes, modifying thresholds).
5. Data Retention & Automated Deletion Schedules
| Data Category | Retention Schedule | Disposal Method |
|---|---|---|
| Webhook deduplication receipts | 48 hours | Automated database TTL purge |
| Order and fulfillment records | 90 days from last Shopify update | Scheduled worker retention sweep |
| Monitor evaluation history | 30 days | Automatic rotation |
| Catalog and inventory current state | Duration of app installation | Purged upon uninstallation |
| Post-uninstallation store data | Maximum 48 hours post-uninstall | Hard-deleted on compliance webhook; hashed redaction audit retained |
6. Security Safeguards & Architecture
- PostgreSQL Row-Level Security (RLS): Multi-tenant isolation is strictly enforced by database kernel policies. A tenant connection can never view or modify another store's data.
- AES-256-GCM Token Encryption: All Shopify offline tokens and Slack bot credentials are encrypted at rest using AES-256-GCM authenticated encryption with key versioning.
- In-Transit Encryption: All web, API, and webhook traffic terminates via TLS 1.3 with HSTS and restrictive security headers.
- CWE-1236 Formula Sanitization: All CSV and JSON exports sanitize spreadsheet formula trigger characters to prevent spreadsheet code execution.
7. International Data Transfers & GDPR / CCPA Rights
Data Transfers: Data is hosted in the United States. When data is transferred from the European Economic Area (EEA), United Kingdom, or Switzerland to the US, Watchwick complies with Chapter V of the General Data Protection Regulation (GDPR) through the incorporation of the European Commission's Standard Contractual Clauses (SCCs Module 2, Controller-to-Processor).
Data Subject Rights: Under the GDPR, UK GDPR, and CCPA/CPRA, merchant staff have the right to access, rectify, restrict, or erase their personal data (verified email and staff user ID).
Because Watchwick never receives or stores customer PII, customer access and erasure requests sent via Shopify's mandatory privacy webhooks are verified and processed instantly with zero retained customer records.
8. Subprocessors
We engage vetted third-party subprocessors under strict contractual data protection agreements:
- Render Services, Inc. / Cloud Hosting: Cloud server hosting and managed PostgreSQL 18 database in the United States.
- Postmark (ActiveCampaign, LLC) / Resend, Inc.: Transactional email delivery for staff incident alerts and daily/weekly digests.
- Slack Technologies, LLC: Webhook alert delivery (strictly when connected and authorized by the merchant).
9. Contact & Data Protection Officer
Watchwick is operated by Duvvuru Shathwik Reddy as a registered Micro Enterprise under the Ministry of MSME, Government of India (Udyam Registration: UDYAM-TS-20-0220111).
Address: Flat No. 204, Venkatadri Towers, Dollar Hills, Pragathi Nagar, Bachupally, Hyderabad, Medchal-Malkajgiri, Telangana 500090, India.
To exercise data protection rights or contact our privacy lead, email privacy@watchwick.com or security@watchwick.com.