Privacy Policy

Effective August 25, 2026

CodeWomplers ("we", "us", or "our") provides Codewomplers iGraphQL, an embedded development tool for authenticated Shopify store users. This policy explains how the app processes information.

Information we process

  • Store and user information. We process the shop domain, installation and session information, Shopify user information supplied to the app, and authorization credentials needed to provide the service.
  • GraphQL workspace information. The app processes queries, variables, API selections, and responses when a store user chooses to run an operation. Admin API requests normally execute directly between the user's browser and Shopify through Shopify App Bridge and do not pass through CodeWomplers' hosting infrastructure. Storefront requests and Admin API requests made when Direct API access is unavailable pass through Vercel, where the request and response are processed transiently and forwarded to and from Shopify. We do not log or retain raw ordinary interactive GraphQL queries, variables, or response bodies on Vercel or in Upstash Redis.
  • Saved workspace information. Queries, variables, tabs, and other workspace preferences can be stored in the user's browser, but ordinary response bodies are excluded from persisted tab records. Bulk-operation queries, staff identifiers, queue status, and temporary result URLs can be stored in app-owned Shopify metaobjects in the merchant's store. Actual bulk-result files remain hosted by Shopify and are downloaded directly from Shopify; Vercel and Upstash do not store their contents.
  • Support information. If a user contacts support, we process the user's contact information, description, sanitized diagnostics, and support replies. Query text included by the user is sanitized before server-side storage, and variables are omitted from stored diagnostics. If the user chooses to include a response diagnostic, we retain only a limited status and error-code summary, not the raw response content.
  • Operational information. We process limited request, status, and error information to secure and operate the service. The application logger uses hashed identifiers and does not accept raw GraphQL queries, variables, response bodies, email addresses, phone numbers, or Shopify global IDs as log fields.

Protected customer data

Store users choose the GraphQL operations they run and the optional Shopify permissions they request. A merchant-authored operation can include customer or order information when the merchant has granted the required permission. We process that information only to execute the requested operation, display the result to the authenticated store user, provide a user-requested bulk operation, respond to support requests, or meet legal obligations. The app does not include features for third-party advertising, customer profiling, automated customer decisions, or the sale of personal information.

Why we process information

  • Authenticate users and maintain secure Shopify sessions.
  • Execute merchant-directed GraphQL and bulk operations.
  • Save workspace settings selected by the user.
  • Provide support, diagnose errors, and protect the service.
  • Respond to privacy requests and comply with legal obligations.

Service providers and disclosures

We use Shopify to provide app authentication, APIs, and merchant-owned app storage; Vercel to host the application and transiently process Storefront, Admin API fallback, and bulk-operation requests; and Upstash to provide Redis storage for sessions, support, privacy-request processing, and operational coordination. Upstash does not store raw ordinary interactive GraphQL queries, variables, or response bodies. We may also use an email delivery provider to deliver a privacy report requested through Shopify. Each provider processes information in connection with the service it supplies. We may disclose information when required by law or reasonably necessary to protect the service, users, or rights.

Where information is processed

Information handled by CodeWomplers' infrastructure and the providers named above may be processed in the United States and other countries where they operate. Normal Admin API query and response traffic goes directly between the user's browser and Shopify. Depending on the merchant's or user's location, other processing can occur outside the country where the information originated.

Retention and deletion

  • The app does not persist ordinary interactive GraphQL response bodies. Responses processed through our service are returned with no-store cache controls and are not logged, stored in Upstash, or included in persisted tab records.
  • Browser workspace data remains until the user deletes it, performs an app factory reset, or the browser removes its local data.
  • User access records can include a Shopify user ID, email address, display name, assigned permissions, administrator notes, and created and last-seen times. They remain in app-owned Shopify metaobjects while needed to administer app access and have no automatic fixed expiration. A store administrator can delete a user record through the app.
  • Support tickets are retained for no more than 90 days while open. Closing a ticket limits its remaining retention to 30 days.
  • Application error records expire after 7 days.
  • Temporary bulk-result URLs are removed after 7 days, and terminal bulk queue items are removed after 30 days. Nonterminal items remain while needed to complete or recover the merchant's requested operation.
  • Shopify session information is retained while needed to operate the installed app and is deleted through applicable uninstall and shop-redaction workflows.
  • Privacy-request processing jobs expire after 35 days. Limited delivery and audit records can be retained longer when needed to document compliance, security, or delivery of the request.

If a store user includes personal information in a saved query, variable, bulk operation, or support request, that information remains in the selected storage location until it is deleted under the rules above.

Security

We use HTTPS for the public app and apply access controls, secure session cookies, data minimization, diagnostic sanitization, and restricted logging. Access to the support administration system is role-limited and requires a strong password and multi-factor authentication. No security measure can guarantee absolute protection.

Privacy requests

Depending on their location, individuals may have rights to access, correct, delete, or restrict processing of their personal information. Customers should direct requests about store data to the Shopify merchant that controls that data. Shopify sends applicable access and deletion requests to the app through its mandatory privacy webhooks. Merchants and store users can contact us about app data using the address below.

Changes to this policy

We may update this policy as the service or legal requirements change. We will update the effective date on this page when we make a material change.

Contact

CodeWomplers
Email: chris@codewomplers.com