Privacy Policy

Opsflow – ClickUp Tasks · Last updated 19 July 2026

Opsflow – ClickUp Tasks (the “App”) is a Shopify app that turns store events — new orders, refunds, low stock, and abandoned checkouts — into tasks in the merchant’s own ClickUp workspace. This policy explains what data the App processes, why, and how it is protected.

1. Our role

The App is installed by a Shopify merchant and acts as a data processor on that merchant’s behalf. The merchant is the data controller for their store’s and customers’ data and decides what tasks are created and where they are sent. Shoppers should direct data requests to the merchant they purchased from; we assist merchants in fulfilling them.

2. Information we process

CategoryExamplesSource
Store & account data Shop domain, installation status, plan, automation settings, and an encrypted ClickUp access token Shopify install; the merchant’s configuration and ClickUp authorization
Customer personal data Customer name, email address, shipping address, and order details (line items, amounts) Shopify order / refund / checkout webhooks, and the Shopify Admin API
Operational logs Records of each task created or failed (activity log). Payloads for failed syncs may briefly include the customer data above so the merchant can retry. Generated by the App

We do not collect payment card numbers, passwords, or government IDs, and we do not use any of this data for advertising or profiling.

3. How we use it

Data flow is one-way (Shopify → ClickUp). We never sell personal data.

4. Sharing & subprocessors

We share data only with the service providers needed to run the App:

ProviderPurposeData involved
ClickUpThe destination for tasks — the merchant’s own workspace The order/customer details the merchant chose to include in tasks
Heroku (Salesforce)Application hosting & database (United States) All stored data
SentryError tracking & diagnostics Technical error details and shop identifiers; we do not send customer personal data to Sentry
ShopifyThe platform the App runs on and receives events from As governed by Shopify’s own privacy terms

We may also disclose data if required by law.

5. Security

6. Error tracking

We use Sentry to capture unexpected errors so we can keep the service reliable. Error reports contain technical context (stack traces, the shop domain, event type) and are not used to send customer personal data.

7. Data retention & deletion

8. Your rights

Depending on your location (e.g. under GDPR or CCPA), you may have rights to access, correct, or delete your personal data, or to object to or restrict its processing. Because we process shopper data on a merchant’s behalf, shoppers should contact the merchant they purchased from; Shopify’s data-request and redaction webhooks route those requests to us and we act on them. Merchants and shoppers can also contact us directly at the address below.

9. International transfers

The App is hosted in the United States. If you access the service from outside the US, your data may be processed there.

10. Children

The App is a business tool and is not directed to children. We do not knowingly process the personal data of children.

11. Changes to this policy

We may update this policy as the App evolves. Material changes will be reflected here with a new “Last updated” date.


12. Contact

Questions or privacy requests: melbsdev@gmail.com.