Privacy policy

Last updated: 2026

Data we access

RuleWorks requests the read_customers, write_customers, read_orders and write_orders scopes. Customer and order data is read from the Shopify Admin API at the moment a rule runs and is used only to decide which tags and internal notes to apply back to your store.

Data we store

We store your shop domain, the offline access token needed to call the Admin API, your subscription state, your rule configuration, and an activity log containing the rule name, the applied tag, a timestamp and a display label (order number or customer name). We do not store customer addresses, payment details or full order contents.

Retention and deletion

Uninstalling the app marks your shop inactive and stops all processing. Shop and customer redaction webhooks from Shopify delete the corresponding records. You can also request deletion at any time.

Sharing

We do not sell or share store data. Data is processed only by RuleWorks and its hosting and database providers.

Contact

For any privacy request, contact the app support address listed on our Shopify listing.