TrueMargin Privacy Policy

Effective Date: July 19, 2026  ·  Last Updated: July 24, 2026  ·  Version: 1.1

1. Introduction; Scope

1.1. This Privacy Policy (this “Policy”) describes the practices of WeLynk LLC, a limited liability company organized under the laws of the State of Alabama (the “Company,” “we,” “us,” or “our”), with respect to the collection, use, processing, retention, and disclosure of information in connection with TrueMargin, a Shopify application that presents merchants with their net profit after cost of goods sold, payment-processing fees, shipping, and advertising spend, together with the Company’s related servers, websites, and electronic mail communications (collectively, the “Service”).

1.2. The Service is a business-to-business application made available to merchants (“Merchants,” “you,” or “your”) that operate online stores on the Shopify platform (“Shopify”). This Policy applies to information processed through the Service. It does not apply to Shopify’s own processing of your data, which is governed by Shopify’s agreements and privacy policy, nor to any other product or service of the Company.

1.3. Controller and processor roles. With respect to a Merchant’s account and contact information, the Company acts as a controller. With respect to the store data that the Company accesses from a Merchant’s Shopify store in order to provide the Service, the Company acts as a processor and service provider on the Merchant’s behalf and under the Merchant’s instructions, and processes such data solely to provide the Service and for no independent purpose of the Company. As between a Merchant and the individuals whose data may appear in store records, the Merchant is the controller.

2. Information the Service Accesses from Shopify

2.1. Authorized scopes. Upon installation, the Service requests only two Shopify access scopes and no others: read_orders and read_products. The Service does not request write access to any store resource, and does not request access to customer accounts, marketing, finance, or any other scope.

2.2. Order data. Under the read_orders scope, the Service accesses order records for a trailing sixty (60) day window, limited by field selection to financial and line-item information only, namely: order and line-item identifiers, timestamps, financial status, cancellation status, test-order status, currency, subtotal, discounts, taxes, shipping charges, total amounts, refunds, and line-item titles, quantities, prices, and product and variant identifiers. Access to order data constitutes access to Protected Customer Data at Level 1 under Shopify’s Protected Customer Data requirements, and the Company maintains the corresponding data-use declaration with Shopify.

2.3. Product data. Under the read_products scope, the Service accesses the Merchant’s product catalog, including product and variant titles, prices, vendors, product types and categories, images, stock-keeping units, barcodes, weights, and Merchant-entered unit costs.

2.4. Store record. On each authenticated load, the Service reads the store’s own record, namely its Shopify store identifier, time zone, currency, and the store and contact electronic mail addresses that the store publishes to installed applications. The time zone and currency are required to compute a Merchant’s figures in that store’s local day and currency. The electronic mail address is retained only as described in Section 4.1 and is used only as described in Section 5.5. Where a store does not make these electronic mail addresses available, the Service continues to operate without them.

3. Information the Service Does Not Collect

3.1. The Service is designed so that it does not receive, process, or store the personal information of a Merchant’s customers. The Company does not access, request, or store customer names, electronic mail addresses, physical or billing addresses, or telephone numbers. The Service’s order-data feed is restricted by field selection to the financial and line-item fields enumerated in Section 2.2, and order records are stored without any customer-identifying field. The Company does not construct profiles of, and does not track, any Merchant’s individual shoppers.

3.2. The Service is embedded within the Shopify administrative interface and authenticates each request using Shopify session tokens. The Service does not employ advertising cookies, cross-site tracking technologies, third-party behavioral analytics, or tracking of individuals across websites or services. The Service does measure its own product usage and its own electronic mail, as described in Section 4.5: this measurement is first-party, is recorded against the store’s domain rather than any individual, uses no third-party analytics provider, sets no cookies, and does not follow anyone beyond the Service’s own pages and messages.

4. Information Stored by the Service

The Company stores the following categories of information for the purpose of providing the Service:

4.1. Merchant and store information: the store’s myshopify.com domain, Shopify store identifier, time zone, currency, plan status, and installation state; the electronic mail address that a Merchant optionally provides in order to receive the daily profit digest; and the store or contact electronic mail address read from the store record at installation as described in Section 2.4, which the Service retains as a fallback recipient for the messages described in Section 5.5;

4.2. Order financial records: the order and line-item financial fields enumerated in Section 2.2, stored without customer-identifying information, together with associated refunds;

4.3. Product and cost records: product and variant catalog data, unit costs, and the source and confidence of each cost (Merchant-entered, imported from Shopify, or estimated as described in Section 6); and

4.4. Derived figures: daily profit rollups computed from the foregoing, and the flat shipping cost and advertising-spend figures that a Merchant enters;

4.5. Product-analytics events: a record of significant events in the Service’s own lifecycle, so that the Company can measure whether the Service works for the Merchants who install it. Each record consists of the application name, the store’s myshopify.com domain, an event name drawn from a fixed list (for example, that the application was installed, that the initial import finished, that costs were confirmed, that a profit figure was first viewed, that a subscription began, that a digest was sent, opened, or clicked, or that the application was uninstalled), a timestamp, a small set of non-textual properties limited to numbers, true/false values, and values from fixed lists, and a de-duplication key. These records contain no customer information, no free text, and nothing a Merchant types. They are stored in the Company’s own database and are not sent to any third-party analytics provider. Where an event relates to electronic mail, it is recorded by a one-pixel image or a redirect through the Company’s own servers, as described in Section 3.2; and

4.6. Outreach list: where the Company has contacted a store directly, the store’s myshopify.com domain and a campaign label, entered by the Company by hand, so that an installation can be attributed to that outreach. This list contains publicly available store domains only.

5. Purposes of Processing

The Company processes the information described in this Policy solely for the following purposes:

5.1. to compute and present the Merchant’s net profit, product margins, cost breakdowns, and related figures within the Service;

5.2. to estimate missing product costs by the automated means described in Section 6;

5.3. to compose and deliver the optional daily profit digest to the electronic mail address a Merchant provides;

5.4. to operate, secure, maintain, and support the Service, and to comply with applicable law and with the Company’s obligations to Shopify;

5.5. to send a single message after a store uninstalls the Service, asking why, so that the Company can improve the Service. That message is sent at most once per installation, is never followed by any further message or sequence, is plain text, identifies the Company and states why it was received, and is addressed to the digest address where one was provided and otherwise to the address described in Section 2.4. The Company honors a reply asking that it not write to an address again; and

5.6. to measure, in aggregate and by reference to the store’s domain rather than to any individual, whether Merchants successfully activate and continue to derive value from the Service, using the records described in Section 4.5.

The Company does not sell information, does not share information for advertising, and does not use store data for any purpose other than providing the Service.

6. Automated Cost Estimation

6.1. Where a product lacks a Merchant-entered or Shopify-imported cost, the Service may estimate that cost using an artificial-intelligence service provided by Anthropic, PBC (“Anthropic”). For this purpose, the Company transmits product-catalog information only, namely: product and variant titles, vendor, product type and category, product tags, an excerpt of the product description, stock-keeping unit, barcode, weight, price, and the product image. To make estimates accurate for the Merchant’s own catalog, the Company also transmits a small sample of that Merchant’s own confirmed unit costs, together with the corresponding product titles and prices, as reference examples. The Company does not transmit order data, sales or financial totals, refund data, or any customer information to Anthropic.

6.2. Anthropic processes such data on the Company’s behalf as a service provider, subject to contractual restrictions that prohibit use of the data to train Anthropic’s models or for Anthropic’s own purposes. Estimated costs are identified as estimates within the Service, and a Merchant may override any estimate at any time.

7. Sub-processors and Disclosures

7.1. Sub-processors. The Company engages the following categories of service providers, each of which processes information on the Company’s behalf, for the purposes described in this Policy, under written contracts that restrict processing to the Company’s instructions and require appropriate confidentiality and security:

Sub-processorPurposeLocation
Amazon Web Services, Inc.Cloud hosting (compute and database) and transactional electronic mail deliveryUnited States (us-east-1)
Cloudflare, Inc.Edge network, transport-layer security, and denial-of-service protectionUnited States / global
Anthropic, PBCAutomated product-cost estimation (product metadata only; see Section 6)United States
Google LLCWeb-font delivery on the Company’s public marketing page only. Not used by, and not loaded within, the embedded application. A visitor’s internet-protocol address is disclosed to Google when that public page is loadedUnited States / global

7.2. Legal disclosures. The Company may disclose information where it believes in good faith that disclosure is required or permitted by applicable law, including in response to valid legal process, to protect the rights, property, or safety of the Company or others, or to enforce the Company’s agreements.

7.3. Corporate transactions. In connection with any merger, acquisition, financing, reorganization, or sale of all or a portion of the Company’s assets, information may be transferred to the parties to such transaction and to a successor entity, subject to this Policy or a successor policy.

7.4. No sale; no advertising. The Company does not sell information, does not share information for cross-context behavioral advertising, and does not disclose information to any third party for such third party’s own marketing or advertising purposes, and has not done so during the twelve (12) months preceding the Effective Date of this Policy.

8. Data Location and Security

8.1. Information processed by the Service is stored on infrastructure operated by Amazon Web Services in the United States (the us-east-1 region).

8.2. The Company maintains administrative, technical, and physical safeguards designed to protect information against unauthorized access, disclosure, alteration, and destruction, including: encryption of data in transit using Transport Layer Security; encryption of data at rest on the Company’s database volume; restriction of the application origin so that it is reachable only through the Company’s edge network; verification of the authenticity of Shopify webhooks by cryptographic signature; and access controls limiting personnel access to information necessary to their functions. No security program eliminates risk entirely, and the Company does not warrant or guarantee the absolute security of any information.

8.3. Security incidents. In the event of a breach of security resulting in the unauthorized access to or disclosure of information processed through the Service, the Company will notify affected Merchants and, where required, applicable regulators, in the manner and within the time periods required by applicable law, and will take reasonable measures to contain and remediate the incident.

9. Data Retention and Deletion

9.1. The Service computes and displays a Merchant’s profit for a trailing sixty (60) day window and does not surface order history beyond that window. Order, product, and derived records are retained for so long as the Service remains installed on the store, and are deleted upon uninstallation as described in Section 9.2.

9.2. Uninstallation. When a Merchant uninstalls the Service, the Company marks the store for deletion and, after a short window, purges the store’s data from its active systems: the store record, its order, product, cost, and derived records, the outreach-list entry for that store if any, and the stored Shopify access credentials are deleted outright. Reinstallation within that window cancels the pending deletion, so that a Merchant who uninstalls and reinstalls does not lose configured costs and settings.

9.3. Product-analytics events are pseudonymized, not deleted. The records described in Section 4.5 are treated differently, and the Company states the difference plainly. At deletion, the store’s myshopify.com domain in those records is replaced with an irreversible-in-practice keyed hash and the de-duplication key is cleared; the rows themselves are retained indefinitely, so that historical measurements of the Service do not disappear. This is pseudonymization, not anonymization. myshopify.com domains are public and can be enumerated, so a party holding the Company’s hashing key could reconstruct the mapping. The Company therefore holds that key only on its own servers and treats it with the same sensitivity as the data it protects. The retained records contain no customer information and no Merchant-entered text, as described in Section 4.5.

9.4. Shopify compliance webhooks. The Company honors the mandatory Shopify compliance webhooks. Because the Company does not store customer personal information: a customers/redact request is satisfied without further action, as there is no customer personal information to erase; a customers/data_request is answered accordingly; and a shop/redact request results in deletion of the store’s data on the terms set out in Sections 9.2 and 9.3.

10. Rights

10.1. Merchants. A Merchant may (a) uninstall the Service at any time, which initiates deletion of the store’s data as described in Section 9; (b) request access to, correction of, or deletion of the Merchant account and contact information the Company maintains; and (c) contact the Company with any question concerning this Policy. Requests may be submitted to [email protected].

10.2. Individuals whose data appears in store records. Because the Company processes store data as a processor on the Merchant’s behalf, and does not store customer-identifying information, an individual seeking to exercise rights with respect to a store’s records should direct the request to the Merchant that operates the store, which is the controller of such records. The Company will assist the Merchant in responding to such requests as required by applicable law and by the Company’s obligations to Shopify.

11. International Users

The Service is operated from the United States, and information is processed and stored in the United States, where data-protection laws may differ from those of your jurisdiction. By installing or using the Service, you acknowledge that information will be transferred to and processed in the United States as described in this Policy.

12. Changes to This Policy

The Company may amend this Policy from time to time. In the case of a material amendment, the Company will indicate the change by an updated “Last Updated” date and, where appropriate, provide notice to Merchants by electronic mail or within the Service. Your continued use of the Service following the effectiveness of an amendment constitutes your acknowledgement of the amended Policy.

13. Contact

Inquiries and requests concerning this Policy or the Company’s data practices may be directed to:

Privacy and data requests: [email protected]
Legal matters: [email protected]
General support: [email protected]

WeLynk LLC c/o Northwest Registered Agent Service, Inc. 212 W. Troy St. STE B Dothan, AL 36303