Privacy Policy
Last updated: July 31, 2026
Who we are
Hushwork ("we", "us") provides SEO content generation and hosting for Shopify merchants, operated by an independent developer. Content is served on the merchant's own domain via the Shopify App Proxy. This policy covers three surfaces: this website (hushwork.co), the merchant dashboard, and the pages we host on merchants' storefronts.
Data we collect from merchants, and why
- Account data, via our authentication provider: name, email, and login credentials — used to operate your account.
- Store data, via the Shopify Admin API under read-only scopes (
read_products,read_content,read_online_store_pages,read_orders): product catalog, store pages and blog content, and brand/theme settings — used to generate SEO content, match your storefront's visual theme, and build your content feed. - OAuth access tokens, encrypted at rest (Fernet: AES-128-CBC with HMAC-SHA256).
Data about your customers (shoppers)
We practice data minimization at ingestion. From Shopify's orders/create webhooks we retain only: order id, order number, totals, currency, landing/referring URL, and UTM parameters — used solely to attribute orders to Hushwork-hosted pages so you can measure our contribution. Customer names, emails, phone numbers, and addresses are stripped before storage and are never persisted.
On hosted pages we collect first-party, cookieless analytics: page path, a pseudonymous visitor/session identifier, referrer, clicked product URL, and user agent. No IP addresses are stored. Where a shopper has declined analytics consent under Shopify's Customer Privacy settings, the visit is counted anonymously with no identifiers stored. There is no cross-site tracking, no advertising identifiers, and no sale of data — we do not sell merchant or shopper data, and we do not use one merchant's data to benefit another.
Cookies and this website
This website (hushwork.co) sets no advertising or analytics cookies. The merchant dashboard uses strictly necessary cookies from our authentication provider for sign-in sessions. Pages we host on merchant storefronts are cookieless by design.
Your rights, and Shopify privacy webhooks
Depending on where you or your customers live (for example under the GDPR or CCPA), you may have rights to access, correct, delete, or export personal data. We honor these through Shopify's mandatory privacy webhooks, automatically:
- customers/data_request — we compile everything we hold linked to the customer's orders (attribution records only) and make it available to the merchant within 30 days.
- customers/redact — we delete attribution records and stored webhook payloads for the listed orders within 30 days of the request (in practice, immediately).
- shop/redact — 48 hours after a merchant uninstalls, we erase all of the store's data: database records, generated content, and hosted page artifacts. As a backstop, any uninstalled store is fully purged no later than 30 days after uninstall.
Merchants can also request deletion at any time by writing to support@hushwork.co.
Retention — and cancelling vs. uninstalling
- Active stores: data is retained while the app is installed.
- Cancelling a subscription does not delete your data: while the app stays installed, your store's data is retained so resubscribing can restore your feed. What ends with the subscription is content generation and hosting entitlement, as described in our Terms of Service.
- Uninstalling the app is what triggers erasure: access tokens are deleted immediately, and all remaining store data is erased on
shop/redact(typically 48 hours), or at the latest 30 days after uninstall. - Compliance audit records (what was deleted and when — containing no personal data) are retained as evidence of compliance.
International transfers
Our infrastructure is hosted in the Asia-Pacific region. Because Shopify merchants and their customers are worldwide, data may be processed outside your own country; we apply the same safeguards described in this policy wherever it is processed.
Security
- OAuth tokens encrypted at rest; TLS in transit everywhere.
- App Proxy requests are HMAC-signature-verified; webhooks are HMAC-verified before processing.
- Access to production systems is restricted to authorized personnel.
Subprocessors
We use a small number of third-party service providers to operate the service — for cloud hosting and storage, authentication, content generation, and the Shopify platform integration itself. Each processes only the data needed for its function, and none receives shopper personal data for content generation. A current list of subprocessors and a data processing addendum are available on request via support@hushwork.co.
Children
The service is offered to businesses and is not directed at children. We do not knowingly collect data from anyone under 16.
Changes to this policy
We will post updates to this page and, for material changes, notify merchants by email.
Contact
Questions about this policy — or anything else: support@hushwork.co.