Last updated: 2026-07-13
ruli provides store and checkout monitoring for Shopify merchants. This policy explains what data ruli accesses, why, and how it is handled.
This policy is for Shopify merchants who install ruli. ruli does not collect data about your customers (buyers).
.myshopify.com domain and a
Shopify access token, used to call the Shopify Admin API on your behalf.Our OAuth scopes are limited to read_products and
read_inventory — read-only. ruli never modifies your store.
ruli does not request, collect, or store any customer personal data. We do not access orders, customer records, checkout personal details, or payment information. Our monitoring exercises the checkout path without creating orders or reading buyer information.
Shopify's mandatory privacy webhooks are handled accordingly:
customers/data_request and customers/redact have nothing to
return or erase (no customer data is held); shop/redact permanently
deletes all data associated with your store.
Solely to provide the service: run probes and reconciliation, detect problems, open incidents, and deliver alerts to the channels you configure. We do not sell your data or use it for advertising.
We retain your data while ruli is installed. On uninstall, monitoring stops; on
the subsequent shop/redact request (~48h later) all of your store's data
is permanently deleted. You may request deletion any time via the contact below.
Access tokens and secrets are stored server-side and never exposed to browsers. All traffic is served over HTTPS. Webhooks are verified with HMAC-SHA256 before processing.
You may request access to, or deletion of, your store's data at any time by
emailing the contact below. Uninstalling also triggers deletion via
shop/redact.
Questions or requests: r_emil@live.dk