Autolert (“the app”, “we”, “us”) is operated by AddOnePlugins. This policy explains what information the app collects when you install it on your Shopify store, how it is used, how long it is kept, and the choices you have. Questions any time: support@addoneplugins.com.
What we collect
When you install Autolert, we store:
- Store information — your myshopify.com domain and a Shopify API access token that lets the app read the events your rules subscribe to. Tokens are encrypted at rest (AES-256-GCM).
- Your configuration — the notification rules, destinations (Slack channels, email addresses, webhook URLs), message templates, and settings you create in the app.
- Slack connection — if you connect Slack, the workspace id and a bot token (also encrypted at rest) used solely to post the alerts you configure.
- SMTP credentials — if you connect a custom email sender (Pro), the SMTP details you provide; the password is encrypted at rest.
- Notification history — a record of each alert the app sent or attempted (status, destination, timestamps, and the rendered message text). Because messages can reference order details, this history may include order numbers, totals, item names, and customer names as they appeared in the alert.
- Audit log — a record of configuration changes (who changed which rule and when) and delivery outcomes, kept so you have an accountable history of the app’s activity.
What we do NOT do
- We do not sell, rent, or share your data with advertisers — ever.
- We do not read or process storefront visitor data. The app adds no code to your theme.
- We do not keep raw Shopify webhook payloads. Events are processed transiently to evaluate your rules and build the alert, then discarded — only the resulting notification record described above is retained.
- We do not use your data to train machine-learning models.
How we use the data
Exclusively to operate the service: receiving store events from Shopify, evaluating them against your rules, delivering notifications to the destinations you chose, showing you delivery history and audit trails, and sending you service emails (such as onboarding tips and delivery-failure alerts) at the store’s contact address.
Who we share it with
Only the processors needed to deliver your alerts:
- Slack — receives the alert content you configured, posted to your chosen channels via your own workspace connection.
- Email delivery provider — relays alert emails (or your own SMTP server, if you configured one).
- Your webhook endpoints — receive the JSON payload for rules you point at them. You control where these go.
- Hosting infrastructure — the servers and database where the app runs, protected as described below.
Retention & deletion
- Notification history and audit logs are pruned automatically on a rolling window of 30, 90, or 365 days depending on your plan.
- Uninstalling the app deletes your store’s data — rules, destinations, tokens, history, and logs — after a 48-hour grace window (so an accidental uninstall/reinstall doesn’t lose your setup).
- We honor all of Shopify’s mandatory privacy webhooks: shop/redact triggers a complete purge of the store’s data, and customers/data_request / customers/redact are answered from the data described above. You can also request deletion any time by email.
Security
- All traffic is encrypted in transit with TLS.
- Shopify access tokens, Slack tokens, and SMTP passwords are encrypted at rest with AES-256-GCM.
- Access to production systems is restricted and key-based.
Your rights
Depending on where you operate, you may have rights to access, correct, export, or erase personal data (e.g., under GDPR or CCPA). Because Autolert acts as a processor for your store’s data, we fulfil these requests both via Shopify’s privacy webhooks and directly — email support@addoneplugins.com and we’ll respond promptly.
Changes to this policy
If we make material changes, we’ll update the date at the top of this page and, for significant changes, notify you by email or in-app notice.
Contact
AddOnePlugins · support@addoneplugins.com