TCE Shopify Hub: privacy and data handling
This app is operated by The Canary Events. It stores your permanent Shopify store domain, installation status, TCE account email, encrypted TCE API secret, display settings, imported event content and posters, and synchronization activity.
Shopify ID tokens are verified for each administrative request. Online Shopify access tokens are used only to verify installation and permissions, then discarded. The app does not request or collect Shopify customer, order or payment data. Imported event descriptions and dates come from your TCE account.
Disconnecting your TCE account or uninstalling removes its credentials and event cache. Uninstall retains the store domain, uninstall status and job history until Shopify’s shop-redaction request removes the store record. Recent store activity is limited to 100 entries, and finished jobs and hashed webhook receipts are removed after 30 days. Shared poster files are removed when no store references them.
The operator must securely manage server backups and delete expired backups according to the published retention policy. Contact The Canary Events through thecanaryevents.com for access, correction or deletion requests. This page describes the app’s behavior; the operator should add its legal identity, privacy contact and backup retention before public launch.