Ops Console — Privacy notice
This notice covers data processing specific to the Ops Console Shopify app. The sico-wide privacy notice applies in addition.
1. What data we collect
When you connect your store to Ops Console — through Shopify's approval screen, or by pasting an existing Custom App token — we read and store the following data through the Shopify Admin API. The connection is read-only (products, orders, inventory, fulfilments) unless you enable inventory management, which also asks for permission to update inventory levels:
- Shop identity — shop domain, shop name, currency, timezone.
- Orders — order IDs, line items, channel attribution, fulfilment status, and financial summaries. An order may carry the Shopify customer ID and a one-way SHA-256 hash of the customer's email address. We do not store end-customer names, addresses, or payment details.
- Products and variants — product titles, SKUs, variant IDs, and inventory levels from connected locations.
- COGS and margin data — cost-of-goods entries you create or import within the app.
- Purchase orders and suppliers — supplier names, contact emails, and PO line items you create within the app.
If you connect optional integrations, we additionally store:
- Encrypted credentials for Google Ads, Meta Ads, Klaviyo, Mailchimp, Xero, and QuickBooks (OAuth tokens, or the Klaviyo private API key you paste) — used only to pull attribution, email and accounting data on your behalf.
- Aggregated ad-spend and attribution data pulled via those tokens.
2. Legal basis
Processing is necessary to perform the contract you entered when signing up (UK GDPR Art. 6(1)(b)). Optional integration data is processed on the basis of your consent, which you give by connecting the integration and may withdraw at any time from Settings.
3. How we use the data
Solely to provide the Ops Console features: margin analysis, inventory health dashboards, purchase order management, and the morning brief. We do not use your store data to train models, benchmark across merchants, or share with third parties beyond the processors listed below.
4. Data retention
Your store data is retained while your store is connected. If you connected through Shopify's approval screen and then uninstall the app, Shopify sends us a GDPR erasure webhook 48 hours later and we purge all store-specific records within 30 days. Shopify sends no such webhook for a store connected with a pasted token: disconnecting removes the stored token, and you can ask us to delete the rest at the address below. Integration tokens are deleted immediately when you disconnect an integration from Settings.
5. Sub-processors
- Hetzner — VPS hosting; data stored in EU.
- Stripe — billing for your Ops Console subscription.
- Resend — transactional email (receipts, alerts).
- PostHog (EU) — product analytics (page-level, no order data).
- Anthropic — writes the morning brief and reorder explanations; prompts contain aggregated order, margin and stock figures only, no customer personal data.
6. Contact
Privacy queries: privacy@sico.software.