Checkout Canary is a Shopify app made by Enviola Labs ("we", "us"). It checks that a store's checkout works by building test carts and reviewing shipping settings, then alerts the merchant when something breaks. This policy explains what information the app collects, how we use it, and how it is deleted.
Information we collect
When a merchant installs Checkout Canary, we collect and store:
- Store details: the store's myshopify.com domain, the access token Shopify issues to the app, and the store contact email, which we use as the default alert address.
- Settings the merchant enters: the alert email address, an optional Slack webhook URL, the chosen test product, test addresses, and the discount codes to monitor.
- Check results: the outcome of each check, such as which shipping options appeared or whether a discount code applied.
- Billing status: which plan the store is on, as reported by Shopify. Payments are handled entirely by Shopify; we never see card details.
Information we do not collect
Checkout Canary does not access or store any information about a store's customers or orders. Test carts use public landmark addresses or addresses the merchant enters, no order is ever placed, and no inventory is reserved.
How we use information
- To run the checks the merchant has set up and show the results in the app.
- To send alert emails, and Slack messages if the merchant adds a webhook.
- To apply the limits of the merchant's plan.
- To provide support when a merchant contacts us.
We do not sell information, use it for advertising, or share it with anyone except the service providers below.
Service providers
- Shopify, which runs the store, the app platform and billing.
- Fly.io, which hosts the app and its database in the United States.
- Resend, which delivers alert emails.
- Slack, only if the merchant adds a Slack webhook.
Retention and deletion
- Check history older than 30 days is deleted automatically.
- When a store uninstalls the app, scheduled checks stop immediately.
- Shopify asks us to erase a store's data 48 hours after uninstall. At that point we delete all of the store's settings, check history and access tokens.
- Merchants can ask us to delete their data sooner by emailing us.
Security
Data is sent over encrypted connections and stored on an encrypted disk. Access tokens are used only to run the checks described above.
Your rights
Depending on where you live, you may have the right to access, correct or delete your information. Email us and we will respond within 30 days.
This website
enviolalabs.com does not use cookies, analytics or tracking scripts, and collects no personal information.
Changes
If we change this policy, we will update the date at the top of this page. Significant changes will be announced in the app.
Contact
Enviola Labs
support@enviolalabs.com