ProfitLeak Privacy Policy
Effective date: September 18, 2026
ProfitLeak is a Shopify app that helps merchants understand order profitability and identify missing costs, discounts, refunds, and low-margin orders.
Information ProfitLeak processes
ProfitLeak reads only the Shopify data needed to calculate and explain profitability. This includes order identifiers and timestamps, order financial totals, discounts, refunds, line items, product and variant identifiers, product titles, quantities, and inventory unit costs.
The profitability queries used by ProfitLeak do not request customer names, customer email addresses, shipping addresses, or billing addresses.
Authentication and account data
ProfitLeak uses Shopify authentication. Shopify session storage can contain technical session identifiers, access tokens, shop identifiers, granted scopes, expiry information, and merchant administrator account details that Shopify supplies for the authenticated session, such as user ID, name, email address, locale, and account-owner status.
What ProfitLeak stores
ProfitLeak stores Shopify session data required to keep the app authenticated, plus limited app state such as onboarding completion and billing entitlement status. Order and product data used by the profitability dashboard is fetched from Shopify when needed and is not stored in ProfitLeak's application database as a historical order warehouse.
How information is used
Information is used to authenticate the merchant, retrieve the Shopify data required for the dashboard, calculate profitability, show actionable profit-leak findings, maintain onboarding state, and enforce the app's subscription entitlement.
Sharing
ProfitLeak does not sell merchant or customer data. Information is processed only as needed to operate the app and its hosting, authentication, and Shopify integration.
Retention and deletion
When a shop uninstalls ProfitLeak, the app handles Shopify's uninstall and mandatory privacy webhooks to remove the shop's application session and state. Shopify privacy requests are processed through the app's compliance webhook endpoints.
Security
Production traffic is served over HTTPS. Application secrets are kept outside the source repository and access to the production service is restricted to the minimum required runtime components.
Changes to this policy
This policy may be updated when ProfitLeak's data use or features materially change. The effective date above will be updated when that happens.
Support
For privacy or support requests, use the ProfitLeak support contact provided through its Shopify App Store listing.