Obnold Shipping Profiles
Privacy Policy
Effective 15 September 2026
This policy explains what Obnold Shipping Profiles (the “app”), provided by Obnold Pte Ltd, stores when you install it on your Shopify store, why it stores it, and how you can have it removed. It covers the app only — not Shopify itself, whose handling of your data is governed by Shopify’s own privacy policy.
1. Who this applies to
The app is installed by Shopify merchants and used by merchant staff inside the Shopify admin. Throughout this policy, “you” means the merchant who installs the app, and “your store” means the Shopify store it is installed on.
The app is not offered to, and is not designed for, your customers. It has no storefront component and no buyer-facing interface.
2. What the app stores
When installed, the app stores the following in its own database:
- Store information — your
.myshopify.comdomain, store name, Shopify plan name and currency, and the dates the app was installed or uninstalled. - Authentication and session data — the Shopify session record for your installation, including the granted access scopes and an offline Shopify access token used to call Shopify’s API on your behalf. The session record may also carry account identifiers that Shopify supplies at install time.
- Your configuration — the shipping rules and rule conditions you author, the shipping target each rule points at, and your app settings.
- Product references — Shopify product and variant identifiers, together with product titles and the product attributes your rules are evaluated against, such as vendor, type, tags, SKU, price and weight.
- Operational history — background job records, the assignment changes the app made (so they can be reviewed and undone), audit findings, and activity history.
- Webhook records — an inbox of the Shopify webhook events the app received, used to process each event once and to retry safely.
- Support conversations — the subject, category and message text you submit through the app’s support form, along with the store context attached to it.
3. Shopify access the app requests
The app requests only the permissions its features need. At install it requests:
- read_products — to read your catalog so rules can be evaluated against product and variant attributes.
- read_inventory — to read variant weight, which rules can match on.
- write_shipping — on stores that use delivery profiles, to move product variants between the delivery profiles you already own.
- write_products — on stores that use Shopify’s market-driven shipping, to create and maintain the collections for the shipping groups you set up in the app: Obnold creates its own collection and collection source for each group and adds or removes products in that source only. It is not used to edit your products, and never to change collections or collection sources you manage.
One further permission, read_markets, is optional. It is never requested at install. The app asks for it only if your store uses Shopify’s market-driven shipping and you choose to grant it, and it is used only to read your Markets shipping settings so the app can show whether a shipping rate uses a shipping group’s collection. The app does not request write_markets and does not change your markets, shipping options or rates.
The app does not manage shipping rates, zones or locations themselves, and it does not request access to orders, customers, or payment information.
4. How the data is used
The data above is used only to operate the app for your store:
- to authenticate your store with Shopify and keep your session valid;
- to evaluate your rules and show you a preview of which variants would move before anything changes;
- to apply the delivery-profile assignments you confirm, and to let you undo them;
- to audit your store’s current shipping configuration and explain the results;
- to determine your subscription entitlements and plan limits; and
- to respond to support requests you send us.
The app does not use your data for advertising, does not sell it, and does not build merchant profiles for any purpose beyond running the app.
5. Service providers and sharing
Your data is not sold or shared for marketing. It is processed by the providers that run the service:
- Shopify — the platform the app reads from and writes to, and the provider of the hosted billing flow described below.
- Amazon Web Services — hosting for the application, its database, its credential storage and its logs.
The app sends no data to analytics, advertising, profiling or error-reporting services; it integrates with none. Subscriptions are handled entirely through Shopify’s hosted billing, so the app never receives or stores your payment details. Data may also be disclosed where required by law.
6. Retention
Configuration and operational data is kept while the app is installed, so your rules, history and undo records remain available to you. Optional pruning of older operational history can be enabled for a deployment; where it is not enabled, that history is kept until the data is deleted as described below.
When the app is uninstalled, your Shopify session is deleted and the installation is marked as removed. Your configuration is retained so that reinstalling does not lose your rules. To have it deleted sooner, contact us at support@obnold.com.
7. Security
The app is served over HTTPS. Application credentials, including the Shopify API secret and database connection details, are held in a managed secret store rather than in source code, and are supplied to the running service at start-up. Access to your store’s data within the app is scoped to your store: every request is authenticated through Shopify and every query is restricted to the authenticated store’s own records.
No service can promise perfect security, and this policy does not claim to. If you believe there has been a security issue affecting your store, please write to support@obnold.com.
8. Customer and buyer data
The app’s shipping-profile functionality does not intentionally collect or store your customers’ personal information. It does not request access to orders or customers, and it has no storefront presence. The product data it holds consists of catalog records and identifiers, not buyer details.
9. Shopify privacy and compliance requests
The app implements Shopify’s mandatory compliance webhooks and responds according to the data it actually holds:
- customers/data_request — the app holds no customer personal data, so there is nothing to disclose in response.
- customers/redact — the app holds no customer personal data, so there is nothing to erase.
- shop/redact — the app deletes the store record and the data associated with it, including rules, job and assignment history, audit findings, activity, webhook records and support conversations, and deletes the store’s sessions.
10. Your choices and requests
You can edit or delete your rules and settings at any time inside the app, and you can uninstall it from your Shopify admin, which revokes its access to your store. To request a copy of the data the app holds about your store, or to ask for it to be deleted, write to support@obnold.com from an address associated with the store. Depending on where you are, you may have additional statutory rights over your data; this policy does not limit them.
11. Changes to this policy
This policy may be updated as the app changes. The effective date at the top of the page shows when the current version took effect, and material changes will be reflected here before they apply.
12. Contact
Questions about this policy, or about the data the app holds, can be sent to support@obnold.com. It is a monitored inbox and the official support channel for Obnold Shipping Profiles.