FlowWitness
How it works Terms Contact

Privacy

Small data footprint, stated plainly.

FlowWitness checks whether a paid-order workflow reached its completion checkpoint. We do not need the contents of the order to do that.

Privacy Policy · Last updated September 20, 2026

We storeShop, order and workflow identifiers; timestamps and delivery status.
We do not storeCustomer contact details, addresses, payment details, line items, or order contents.
Default historyCompleted and overdue monitoring records are kept for 90 days.

This policy covers the FlowWitness website and Shopify app. We will update this page before making a material change to how data is used.

1. What the service does

FlowWitness monitors checkpoints that a Shopify merchant adds to a Shopify Flow workflow. The merchant decides to install the app, chooses the workflow and alert address, and remains responsible for the store and its customer relationship. FlowWitness processes store data only to provide, secure, and support this monitoring service.

2. Data we process and why

Data Why we need it
Shop domain, Shopify session, access token, and granted scope Install, authenticate, and operate the embedded app.
Monitor name, key, deadline, enabled state, and encrypted alert email Apply the merchant's monitoring and notification settings.
Order GID, merchant-facing order number, webhook ID, Flow action run ID, and timestamps Match a paid order to one completion check without copying the order body.
Expectation, incident, email delivery, and retry status Show history, avoid duplicate alerts, and support incident handling.
Plan handle and description, entitlement status, trial and billing-cycle dates, and cancellation status Confirm access to app features and show the merchant's Shopify-verified plan status.
Public website page path, App Store button clicks, campaign tags, and referring hostname Measure the anonymous visit-to-install funnel and understand which launch channels are useful. We do not store the full referring URL, IP address, or browser fingerprint in the analytics table.
Shopify App Store listing views, traffic source, device and browser information, listing interactions, and Shopify-reported app install events Compare listing visits with installs and improve the public listing. This measurement is limited to our Shopify App Store listing and does not include Shopify order or customer data.
Service health and security logs Keep the service available, investigate failures, and prevent abuse.
Messages and attachments sent to support Reply to the person who contacted us and resolve the request.

3. Data we deliberately do not collect

The monitoring database does not store customer names, customer email addresses, phone numbers, postal addresses, payment details, line items, or complete Shopify webhook payloads. The FlowWitness public website uses first-party, event-level counts without analytics cookies, local storage, cross-site tracking, or browser fingerprinting. Separately, our Shopify App Store listing uses Google Analytics through Shopify to measure listing visits and app installs. Shopify or Google may use cookies or similar identifiers for that measurement. Learn how Google processes information from sites and apps that use its services at Google's partner sites notice. Hosting infrastructure may process standard request metadata, such as an IP address, long enough to deliver and protect the site.

4. How we use and share data

We use the data above to authenticate the app, create and match checkpoints, detect missed deadlines, send incident emails, show event history, answer support requests, secure the service, and comply with verified Shopify privacy requests and applicable law.

We do not sell personal data, rent it, use it for targeted advertising, train machine-learning models on it, or make automated decisions that have legal or similarly significant effects on customers.

5. Service providers and data location

  • Shopify provides the commerce platform, app installation, authentication, webhooks, Shopify Flow, hosted plan selection, and billing. FlowWitness does not receive card or bank account details.
  • Tencent Cloud, Singapore hosts the application, database, and encrypted backup infrastructure.
  • Resend delivers incident emails and forwards support email.
  • Google hosts the private support inbox and provides Google Analytics for aggregate Shopify App Store listing traffic and install measurement.

These providers process data under their own security and contractual terms. Depending on the merchant's location, data may be processed in another country.

FlowWitness is currently operated by an independent developer based in China. The production application is hosted in Singapore.

6. Retention and deletion

Record Retention
Completed and overdue monitoring history 90 days by default.
Pending checkpoint Until it completes or reaches its deadline.
Encrypted customer data-access report Up to 45 days.
Support correspondence Only as long as needed to answer the request, keep necessary business records, or meet legal obligations.
Cached Shopify plan entitlement While the app remains installed; deleted on uninstall or a verified shop-redaction request.
Anonymous public website analytics events Up to 180 days.
Shopify App Store listing analytics Event-level data follows the Google Analytics retention setting for the FlowWitness property. Aggregated reports may remain available for longer.
Encrypted operational backups A separate limited backup schedule; backups are not used for analytics or product development.

Uninstalling the app stops future monitoring and deletes the shop's application sessions, monitor settings, monitoring records, and the cached Shopify plan entitlement. Verified Shopify customer and shop redaction webhooks are also handled, including when Shopify retries them.

7. Privacy requests

Depending on applicable law, a person may have rights to access, correct, delete, or restrict the use of personal data. Merchants can update monitor settings in the app or uninstall it. Shopify customers should send privacy requests to the merchant they purchased from.

When Shopify sends us a verified customer data request, customer redaction request, or shop redaction request, we create the required minimal report or delete the matching records. We aim to complete verified requests within the period required by Shopify and applicable law.

8. Security

We use HTTPS, restricted network access, encrypted alert destinations, signed webhook verification, protected internal endpoints, least-privilege credentials, encrypted off-site backups, and retry-safe database operations. No internet service can guarantee absolute security. Contact us promptly if you suspect unauthorized use.

9. Changes and contact

We may update this policy as the service changes. The date at the top will be updated before a material change to data use takes effect.

Questions or privacy requests may be sent to support@getflowwitness.com. We may need to verify the requesting merchant or Shopify store before disclosing or deleting protected information.

© 2026 FlowWitness.
HomeTermsContact