Privacy Policy
This policy explains what data Green Claims collects from your Shopify store, why, how long it's kept, and how to reach us. It applies to the Green Claims app only — for Paxworks Track and Paxworks Plan, see their own privacy policy.
What we collect
When you install Green Claims, we access and store:
- Store information: your shop domain and an access token (encrypted at rest) that lets us call the Shopify Admin API on your behalf.
- Product and content copy: product titles and descriptions, and blog article/page titles and body text — the copy we scan for flagged terms.
- Generated claims data: the specific phrases we flag, their risk category, and whatever status you or a teammate give them (unsubstantiated, substantiated, dismissed).
- Evidence you upload: certificates, lab results, LCA reports, or other files you attach to a claim, plus whatever expiry date you set.
- Generated audit exports: CSV reports you request, listing your claims and their evidence status.
What we don't collect
Green Claims does not request or store any of your customers' personal data — no names, emails, addresses, or order history. The app's Shopify permissions are limited to product and content ("read_products", "read_content") for exactly this reason.
How we use it
Solely to run the app: scanning your copy for risky environmental claims, letting you attach and track evidence against those claims, and generating the audit exports you request. We do not use your store data, or anything derived from it, to train or improve any AI or machine-learning model — this app's claim detection is rules-based, not AI-driven.
Where it's stored
- Structured data (claims, product copy, store settings) is stored in a PostgreSQL database hosted on Railway.
- Uploaded evidence files and generated audit exports are stored in a private Cloudflare R2 bucket. Files are never publicly accessible — every download link is a short-lived, signed URL generated on request.
- Your Shopify access token is encrypted before it's stored, using a key that's never stored alongside the data it protects.
Data retention and deletion
When you uninstall Green Claims, Shopify notifies us and requires that we delete your store's data within 48 hours — this is a Shopify platform requirement, not a Paxworks policy choice. We apply this uniformly: every record tied to your store — products, content, claims, uploaded evidence, and generated exports — is permanently deleted within that window. There is no extended retention or grace period for uploaded evidence. If you think you might reinstall later, download anything you need before uninstalling.
You can also request deletion of your data at any time by uninstalling the app, or by emailing us at the address below.
Third parties
We use the following subprocessors to run the app. None of them receive your data for any purpose beyond hosting/processing it on our behalf:
- Shopify — the platform Green Claims runs on; see Shopify's own privacy policy for how they handle data.
- Railway — application and database hosting.
- Cloudflare — R2 object storage for uploaded files and exports.
We do not sell your data, and we do not share it with any other third party.
Your rights
Depending on where you're located, you may have rights to access, correct, or delete your data (e.g. under GDPR or similar regional laws). Since Green Claims holds no customer personal data, these rights apply to your own store's data as a merchant. Contact us to exercise them — most requests are satisfied simply by uninstalling the app, which triggers full deletion as described above.
Changes to this policy
We'll update the "last updated" date above if this policy changes, and post the new version at this same URL. Material changes will be communicated via the app or by email where we have one on file.
Contact
Questions about this policy or your data: [email protected].