Privacy Policy
Last updated: 2 September 2026
Freight Margin Guard (“the app”, “we”) helps Shopify merchants reconcile carrier invoices against their store’s shipping revenue. This policy describes what data the app processes, why, and for how long. The merchant who installs the app is the data controller for their store’s data; we process it on their behalf.
Data we collect
- Order and fulfillment data from the Shopify Admin API under the
read_ordersscope only: order number, currency, shipping amounts collected and refunded, fulfillment tracking numbers, carriers and ship dates, for the last 60 days by default. We do not request access to customer profiles. We do not ask Shopify for buyer names, delivery addresses, phone numbers or email addresses, and we store none of them. We use this data only to match your carrier invoices to the orders they belong to and to calculate your shipping margin. - Carrier invoice files the merchant uploads (CSV or XLSX). The original file is stored unmodified and treated as an immutable record, so it contains whatever columns the carrier included. When we read the file we keep only the columns the app uses: tracking reference, service, charge description and amount, ship and delivery dates, weights and invoice number. Any other column, including recipient names or delivery addresses if the carrier supplies them, is discarded and never stored in our database. Access to the original files is restricted to the merchant who uploaded them.
- Account data: the store domain, the store’s contact email (used for report delivery), and the internal staff-user identifier and role of people who use the app, for access control.
- Product analytics: pseudonymous usage events (identified by internal organization and store identifiers) that record which stages of the product were reached. Analytics events never contain tracking numbers, invoice contents, file names or any buyer information.
How we use data
- Matching carrier invoice lines to the store’s shipments.
- Detecting shipping-cost findings (for example, a shipment billed for more than the buyer paid) with a full calculation trace.
- Preparing dispute evidence packages at the merchant’s request.
- Sending the merchant summary reports and service emails.
- Operating, securing and improving the service.
We do not sell data, use it for advertising, or share it with third parties except the subprocessors below.
Subprocessors
- Oracle Cloud Infrastructure — application hosting and file storage
- Shopify — commerce platform, authentication and billing
- Cloudflare — DNS and network security
- Resend — transactional email delivery
Security
Data is isolated per merchant organization and every request is authorized server-side against the caller’s store and role. Original invoice files are write-once. All configuration changes, decisions and calculations are recorded in an append-only audit trail. Monetary values are processed as exact integer amounts. Data is encrypted in transit using TLS, and encrypted at rest in both the database and the file storage.
Retention and deletion
While the app is installed, data is retained to provide the service. After uninstalling, data is kept for 30 days so a reinstall can restore your workspace. After 30 days all commerce data is permanently deleted: orders, shipments, uploaded invoice files, invoice lines, charges, matches, findings, disputes, evidence packages and saved column mappings. What we keep is an install record carrying no contact details, and the audit trail, which records what the app did and contains no buyer data.
Shopify’s privacy webhooks are honored. shop/redact runs the same deletion described above, immediately rather than after 30 days. customers/redact deletes the order and shipment records for the orders Shopify names in the request. We record that a request was received and how many records it removed, without storing the customer or order identifiers it referred to. customers/data_request is answered by our support team within 30 days. You can request an export or earlier deletion at any time via the contact address below.
We also keep pseudonymous usage events (which organization used which feature and when) to operate and improve the app. These carry no buyer data and are retained for up to 25 months.
Your rights
Depending on your jurisdiction you may have rights to access, correct, export or delete personal data. Merchants can exercise these for their store data by contacting us; buyer data requests flow through the merchant and Shopify’s privacy tooling, which we honor automatically.
Changes and contact
We will update this page when our practices change and note the date above. Questions and requests: [email protected].