CopyHush
Privacy Policy
Effective date: July 31, 2026
CopyHush helps Shopify merchants discourage casual copying on their storefronts. This policy explains how we handle merchant and app information.
What information CopyHush collects
CopyHush uses Shopify APIs only to authenticate merchants and store app configuration settings. We collect and process only the information needed to provide those functions:
- Shopify authentication and session information: Shopify session identifiers, access tokens, granted scopes, and token expiry information needed to securely operate the app.
- Store identification information: the shop domain and technical identifiers needed to associate a session with the merchant's Shopify store.
- App configuration settings: the protection preferences a merchant saves, such as right-click, copy, text selection, keyboard shortcut, and warning-message settings.
Information CopyHush does not collect
CopyHush does not access or collect customer names, email addresses, phone numbers, postal addresses, payment details, or order data. CopyHush does not use Shopify APIs to read products, customers, orders, or checkout information.
How information is used
We use the limited information described above to:
- authenticate a merchant and maintain a secure app session;
- identify the merchant's store for app operation;
- save and retrieve the merchant's CopyHush configuration settings; and
- provide support, investigate security issues, and meet legal obligations.
Data storage and security
Session information is stored in a PostgreSQL database. App configuration settings are stored in a Shopify app-data metafield on the app installation. We use reasonable administrative, technical, and organizational safeguards designed to protect this information. No method of storage or transmission is completely secure.
Third-party service providers
We use service providers to operate CopyHush, including Railway for application hosting and PostgreSQL database hosting. Shopify provides merchant authentication, app installation services, and storage for app configuration settings. These providers process information only as needed to provide their services to us.
Data retention and deletion
We retain session information only while it is needed to operate the app. When a merchant uninstalls CopyHush, the app deletes the associated stored session records. Configuration settings remain limited to the Shopify app installation and are no longer used after uninstall. A merchant may also request deletion of information that CopyHush holds by contacting us.
Merchant rights
Merchants may request access to, correction of, or deletion of their information held by CopyHush, subject to applicable law. Merchants can also update their app configuration settings at any time from within the app, or uninstall the app to end its access to the store.
Changes to this privacy policy
We may update this policy as CopyHush changes or as legal requirements evolve. We will post the updated policy on this page and revise the effective date above.
Contact information
For privacy questions or requests, contact the CopyHush team through the support contact shown in the Shopify app listing or in your Shopify admin app installation.