Order Profit Protector — privacy notice
Development-store pilot notice, 2026-10-06. Order Profit Protector is operated by SoftStudioX at https://app.allarabi.com. Contact softstudix@gmail.com for support or privacy questions. The service is not yet open for a real-merchant beta; infrastructure backup, monitoring and Shopify production-review checks remain in progress.
The pilot is hosted on the operator's VPS at DigitalOcean in Frankfurt, Germany (fra1, verified from the server's provider metadata). The app uses a dedicated PostgreSQL database and verified encrypted database connections. Shopify session tokens are encrypted in application storage. Complete infrastructure encryption, off-server backup retention and recovery verification remain release requirements; this notice does not claim those controls are completed.
Order Profit Protector processes Shopify order identifiers, financial values, line item quantities and catalog identifiers, payment/fulfillment status, store settings, configured costs and saved financial risk explanations. Store-specific customer identifiers connect descriptive order history. This processing supports the merchant's contribution-profit estimates and order financial review.
The app does not request customer names, email addresses, phone numbers, full shipping/billing addresses or payment card details. Shopify can send contact details in privacy webhook payloads; the app discards those fields instead of retaining the raw payload. Shopify access/refresh tokens enable authorized API calls and are encrypted in application storage. Credentials are never included in customer exports.
Customer/order data belongs to the merchant's store. The app does not share customer history between stores, create a shared blacklist or sell that history. It does not implement marketing tracking. Shopify and the operator's disclosed hosting providers process data as needed to provide the service.
AI review is currently disabled in this hosted pilot. When enabled, the optional AI review sends limited financial values and current financial-rule findings to Groq, using openai/gpt-oss-20b. Customer details/identifiers/history, store/order identifiers, product names and Shopify credentials are excluded. Groq prioritizes existing findings; the app supplies verified figures and review steps. Reviews are not stored in our database. Groq may retain requests for reliability/abuse monitoring for up to 30 days unless its Zero Data Retention controls are enabled. Retained provider data is located in the United States under its current data policy. Account retention settings have not been verified. Groq must be disclosed as a subprocessor and reviewed for production use; do not promise zero provider retention.
Order history is retained for one year after the order's Shopify creation date. Linked cost/risk records expire with their order. A Shopify customer deletion request removes matching orders and their linked records sooner. Uninstall stops ingestion, revokes local sessions and queues store-data deletion. Keyed deletion markers prevent stale workers/imports from restoring erased information; they are limited to one year for customer/order markers and 90 days for inactive installation markers. Completed inbox receipts and data-access selectors are limited to 30 days. Infrastructure backup expiration must be added before production publishing; restored data must have deletion requests reapplied before access resumes.
Customers should contact the merchant where they placed their order to request access or deletion. Shopify forwards those requests to the app. An authenticated merchant can prepare a scoped data export from Data privacy even without a subscription and must provide it securely to the requester within 30 days. The app does not automatically email the customer. The operator must monitor failures/deadlines and handle cases requiring identity reconciliation or requests that exceed supported limits.
HTTPS, operator/support details and the pilot hosting location are configured during Phase 14. Backup retention/recovery, infrastructure security verification and notices applicable to the operator must be finalized before real-merchant use. The implementation and test evidence are described in our support team.