Made To Studio for Shopify apps and themes
App Support

Legal

Privacy policy

Effective: 9 September 2026

Operator: Made To

Privacy contact: anhtnt09@gmail.com

Scope

Statuscraft is a Shopify app that lets a merchant define custom pre-shipment order stages, update an order's stage and due date, send status emails, and give buyers a merchant-branded order-status lookup page. This policy describes the Release 1 behaviour represented by this repository. The merchant remains responsible for its own buyer-facing privacy notices and lawful use of Shopify customer data.

Data Statuscraft processes

Statuscraft stores the minimum records needed to provide the service:

  • the merchant's myshopify.com shop domain, installation state, selected plan name and optional merchant reply-to email;
  • Shopify authentication sessions and access tokens, including optional Shopify account metadata supplied to the session library, for authenticated admin use;
  • Shopify order GID and display number;
  • merchant-defined status names, colours, order status, status history, actor, optional history note, and due date;
  • a normalised customer email transformed with a deployment-secret salt and SHA-256. The salt is not stored with the hash. The hash supports exact lookup matching and customer redaction; it is not displayed. Statuscraft treats this hash as pseudonymous personal data, not anonymous or non-personal data;
  • email template subject and body, and whether sending is enabled; and
  • delivery records containing order and status references, state, retry timestamps, a provider identifier and a safe failure category. Delivery records deliberately contain no recipient address.

For customer lookup, the submitted order number and email are processed only to find the merchant's order. The email is normalised and hashed for comparison. Lookup IP address and shop domain are transient rate-limit keys held in one-minute windows. They are not written to application logs.

For a real status email, Statuscraft resolves the current recipient from Shopify at send time, transmits the address and email content to the delivery provider, then discards the plaintext address instead of persisting it in Statuscraft's database. A test recipient entered by a merchant is likewise sent to the provider but not persisted by the application. Email replies can be directed to the merchant's configured reply-to address.

Data Statuscraft does not store for lookup or search

Statuscraft does not store customer names, postal addresses, phone numbers, plaintext customer email addresses, line items, order totals, tags or SKUs for lookup or search. It does not sell customer data or use customer order data for advertising. Public lookup responses are private and no-store, and return the same not-found result for a wrong email and a nonexistent order.

Why the data is used

The data is used to authenticate merchants, keep tenant-separated order status records, render status timelines, meter plan usage, synchronise the current status to a Shopify order metafield, prevent abusive lookup attempts, deliver requested status emails, diagnose delivery, respond to support, and satisfy Shopify privacy webhooks.

Marketing-site analytics

With a visitor’s consent, the public Statuscraft marketing site uses Google Analytics to measure page visits, traffic source and interaction with early-access links. Google may set or read identifiers in the visitor’s browser for this purpose. We do not send customer order details, email addresses, order numbers, or Shopify shop domains to analytics.

Visitors can reject analytics when the privacy prompt appears. Analytics is not loaded until consent is given, and is not used on Statuscraft’s customer order-lookup page.

Processors and transfers

Release 1 uses these service providers solely to operate Statuscraft:

  • Shopify — installation and authentication, Admin GraphQL API, app proxy, webhooks, extension hosting, order data and recipient resolution;
  • Fly.io — application and background-worker hosting;
  • Neon — PostgreSQL database hosting;
  • Upstash — Redis rate limiting; and
  • Resend — status and test-email delivery plus delivery-event webhooks.
  • Google — consent-based marketing-site analytics and Shopify App Store listing measurement.

Those providers may process data in the locations described in their own terms and privacy documentation. If we add or replace a subprocessor, we update this page and, on request, notify merchants who have asked to be told at the privacy contact above.

Retention and deletion

Application data is retained while needed to provide the merchant's installed service and maintain its status and delivery history. Release 1 has no paid retention tier and no automatic history-expiry job.

On uninstall, authentication sessions are deleted and the shop is marked uninstalled. Status configuration and merchant business records are temporarily preserved so an immediate reinstall can restore the workflow. Shopify later sends the mandatory shop/redact webhook, normally 48 hours after uninstall; Statuscraft then deletes the shop and its dependent status, order, history and delivery records. On customers/redact, matching salted email hashes are cleared and pending email obligations for that customer are cancelled. Provider copies and backups expire according to the applicable processor's retention and recovery controls.

Customer privacy requests

The signed customers/data_request webhook authenticates and acknowledges Shopify's request. It does not automatically create a case, export records, or delete data. Requests are handled by the owner and support team using this controlled manual process:

  1. receive the Shopify request through the approved owner or support channel and create an access-controlled case with a unique record ID, request scope and due date;
  2. verify the shop, customer identifier, request authority and requested action before granting production-data access;
  3. have an authorised operator use the deployed email-hash secret only inside the controlled production environment to derive the normalised salted hash, then run a reviewed, shop-scoped lookup for associated order-status, status-history and recipient-free delivery records;
  4. for access or portability, review the result and deliver only the applicable records through an approved secure channel; raw email, secrets, order contents and exports never go into source control or ordinary logs;
  5. for deletion, prefer the signed customers/redact flow. If Shopify or the verified requester requires manual escalation, a second-person approval is required before a shop-scoped operation that clears the matching hash and cancels pending delivery obligations; and
  6. record the operator, approver, timestamps, record counts, disposition and redacted evidence reference in the case, then close it only after verification.

Requests are acknowledged within the period Shopify requires and completed as promptly as verification allows.

Security

Statuscraft verifies Shopify authentication or signed app-proxy requests, tenant-scopes database operations, requests only documented Shopify scopes, uses encrypted HTTPS connections in production, keeps credentials in deployment secrets, escapes merchant-authored content, rate-limits public lookup, avoids logging customer lookup values or provider bodies, and uses idempotent leased email delivery. No system can guarantee absolute security. Report a suspected incident to the verified privacy contact once it is published.

Merchant and buyer rights

Merchants can change their Statuscraft configuration, request support, uninstall the app, and ask for access, correction or deletion where applicable. Buyers should normally contact the merchant that controls their order. Signed Shopify redaction webhooks perform the scoped lifecycle actions described above; signed customer data requests are acknowledged and handled through the controlled manual process described above. Depending on location, a person may have rights to access, correct, delete, restrict, object, or receive a copy of personal data, and to complain to a regulator. Identity and authority must be verified before acting on a request.

Changes and contact

Material changes are dated here and published at this same address. Questions about this policy, or a request under it, go to anhtnt09@gmail.com.