Privacy Policy
PerishShield ("we", "us", "the app") is a Shopify admin application that assesses weather-related risk for perishable orders and helps merchants decide when to hold or ship them. This policy explains what data the app processes, why, where it is stored, and how it is deleted. It covers data the app handles on behalf of the merchant who installs it; it does not describe the data practices of Shopify or of any merchant's own store.
Who controls the data
The merchant who installs PerishShield is the controller of their store's data. PerishShield acts as a processor: we process store data only to provide the app's features to that merchant. We do not sell data, and we do not use it for advertising.
What we collect and store
When installed, PerishShield reads data from the merchant's Shopify store through the Shopify Admin API and stores the following in its own database:
- Order assessment data — order ID and order number, fulfillment status, line-item product IDs, ship/arrival dates, the shipping method name, computed risk level, and the forecast temperatures used in the assessment.
- Location of origin and destination — the city, region/state, and country of an order's origin and shipping destination, derived from the order's addresses. Where a city is unavailable, a postal code or approximate coordinates may be used as a fallback. This is used solely to retrieve a weather forecast for the route.
- Product catalog mirror — product ID, title, handle, status, tags, vendor, product type, and inventory totals, used to identify perishable items and power the in-app product picker.
- Merchant configuration — temperature categories and ranges, product-to-category assignments, shipping departure/arrival windows, reassessment schedule, display preferences, and an (encrypted) WeatherAPI key if the merchant provides one.
What we do not collect
PerishShield does not store customer names, email addresses, phone numbers, street addresses, payment or card information, or any storefront/buyer-facing data. The app has no checkout, post-purchase, or storefront component. Assessments reference order IDs and a coarse origin/destination location — not customer identities.
Third parties we share data with
We share minimal queries to provide routing forecasts. No order, customer, or product information is sent:
- WeatherAPI.com — we send a location query (city/region/country, or a postal code or coordinates) and a date to retrieve a weather forecast. See WeatherAPI's privacy policy.
- Fly.io — our application and database are hosted on Fly.io infrastructure. Data is stored in a managed PostgreSQL database. (Hosting region: Singapore.)
- Shopify — the app runs inside the Shopify admin and exchanges data with the Shopify Admin API under the access scopes the merchant grants at install.
How data is secured
HMAC Signed
SSL/HTTPS Forced
Data is transmitted over HTTPS[cite: 2]. Any API key a merchant stores in the app is encrypted at rest using AES-256-GCM. Access to the production database is restricted to the app's own services. Webhook requests from Shopify are verified by HMAC signature before they are processed.
Data retention and deletion
We keep store data only while the app is installed. When a merchant uninstalls PerishShield, the app's uninstall handler deletes that store's data. Shopify also sends the standard compliance requests, which we honour:
- shop/redact — we delete all data associated with the store.
- customers/redact and customers/data_request — because we do not store customer personal data, there is no customer data to return or erase; we acknowledge these requests.
Accessing, deleting, or questions
A merchant can remove all stored data at any time by uninstalling the app. For any access or deletion request, or any privacy question, contact us at support@perishshield.com.
Material changes to this policy will be reflected by the "Last updated" date at the top of the page.