Privacy policy
Effective date: July 16, 2026
Custory Timeline Exporter is operated by the developer identified in its Shopify App Store Business Imprint. Privacy questions and data requests can be sent to hakan.olcer@web.de.
Roles
The Shopify merchant determines why customer information is processed. Custory processes that information only to provide the merchant-requested timeline and export workflow and to comply with Shopify privacy requests.
Information processed
- Shop domain, Shopify shop and app identifiers, installation status, billing plan status, and job metadata. The app requests only the
read_customersandread_ordersShopify API scopes. - Shopify customer identifier, available first and last name, email address, and source timestamps.
- Recent order identifiers, order names, customer link, dates, financial and fulfillment status, currency, subtotal, total, discounts, refunded total, cancellation or closure time, and limited line-item title, SKU, and quantity summaries.
- Sync and export job status, short-lived export artifacts, privacy-webhook records, and operational security logs.
Information not requested
Custory does not request customer phone numbers, billing or shipping addresses, geolocation, payment details, customer or order notes, tags, returns, theme access, checkout access, or write access to customers and orders.
Purposes
Information is used to authenticate merchant staff, sync the approved data, find a selected customer, build and export a timeline, display billing and job state, secure downloads, investigate failures, prevent abuse, and honor deletion requests. Custory does not sell customer information or use it for advertising.
Storage and subprocessors
The app runs on Cloudflare Workers and uses Cloudflare D1 and R2 for application records and export artifacts. Shopify provides the source APIs, authentication, billing, and compliance webhooks. These providers may process data in countries where they operate, subject to their contractual and security safeguards.
Security
Customer name, email, line-item summaries, and timeline content are encrypted at rest. Search tokens use keyed hashes. Merchant endpoints and downloads require an active Shopify Admin session token. Application secrets are stored outside source control, access is limited, and operational logs are designed not to contain decrypted customer timeline content.
Retention and deletion
Export artifacts expire within 24 hours, and merchants can delete them earlier. Cached customer, recent-order, and timeline records are retained for no more than 90 days and are refreshed by later syncs. Applicable customer-redaction, shop-redaction, and uninstall workflows remove records earlier when required. Limited security and privacy-request audit records may be retained only as necessary to demonstrate compliance and do not contain decrypted timeline content.
Privacy requests
Customers should normally contact the Shopify merchant that controls their data. Merchants and Shopify can submit access or deletion requests through Shopify’s required compliance webhooks. Questions can also be sent to hakan.olcer@web.de. We verify the requester and coordinate with the merchant or Shopify before disclosing protected information.
Changes
This page will be updated when the app’s data practices materially change. The effective date above identifies the current version.