Privacy Policy
Opsflow – ClickUp Tasks · Last updated 19 July 2026
Opsflow – ClickUp Tasks (the “App”) is a Shopify app that turns store events — new orders, refunds, low stock, and abandoned checkouts — into tasks in the merchant’s own ClickUp workspace. This policy explains what data the App processes, why, and how it is protected.
1. Our role
The App is installed by a Shopify merchant and acts as a data processor on that merchant’s behalf. The merchant is the data controller for their store’s and customers’ data and decides what tasks are created and where they are sent. Shoppers should direct data requests to the merchant they purchased from; we assist merchants in fulfilling them.
2. Information we process
| Category | Examples | Source |
|---|---|---|
| Store & account data | Shop domain, installation status, plan, automation settings, and an encrypted ClickUp access token | Shopify install; the merchant’s configuration and ClickUp authorization |
| Customer personal data | Customer name, email address, shipping address, and order details (line items, amounts) | Shopify order / refund / checkout webhooks, and the Shopify Admin API |
| Operational logs | Records of each task created or failed (activity log). Payloads for failed syncs may briefly include the customer data above so the merchant can retry. | Generated by the App |
We do not collect payment card numbers, passwords, or government IDs, and we do not use any of this data for advertising or profiling.
3. How we use it
- To create and update tasks in the merchant’s connected ClickUp workspace from their chosen store events.
- To operate the service — apply the merchant’s filters and settings, prevent duplicate tasks, and show a recent-activity log so the merchant can see and retry failures.
- To secure and debug the service (see “Security” and “Error tracking” below).
Data flow is one-way (Shopify → ClickUp). We never sell personal data.
4. Sharing & subprocessors
We share data only with the service providers needed to run the App:
| Provider | Purpose | Data involved |
|---|---|---|
| ClickUp | The destination for tasks — the merchant’s own workspace | The order/customer details the merchant chose to include in tasks |
| Heroku (Salesforce) | Application hosting & database (United States) | All stored data |
| Sentry | Error tracking & diagnostics | Technical error details and shop identifiers; we do not send customer personal data to Sentry |
| Shopify | The platform the App runs on and receives events from | As governed by Shopify’s own privacy terms |
We may also disclose data if required by law.
5. Security
- ClickUp access tokens are encrypted at rest using AES-256-GCM; plaintext tokens are never stored.
- Stored data resides in a managed PostgreSQL database with encryption at rest.
- Incoming Shopify webhooks are verified by HMAC signature before processing.
- Access to production systems is restricted to the operator of the App.
6. Error tracking
We use Sentry to capture unexpected errors so we can keep the service reliable. Error reports contain technical context (stack traces, the shop domain, event type) and are not used to send customer personal data.
7. Data retention & deletion
- Activity logs are automatically pruned after 90 days; internal webhook de-duplication records after 7 days.
- On a Shopify
customers/redactrequest, we erase that shopper’s personal data from our records (buffered checkouts, compiled data-request records, and failed-sync payloads). - On app uninstall, Shopify sends a
shop/redactrequest (~48 hours later) and we delete all data for that store. Tasks already created in the merchant’s ClickUp workspace remain the merchant’s data and are outside our control.
8. Your rights
Depending on your location (e.g. under GDPR or CCPA), you may have rights to access, correct, or delete your personal data, or to object to or restrict its processing. Because we process shopper data on a merchant’s behalf, shoppers should contact the merchant they purchased from; Shopify’s data-request and redaction webhooks route those requests to us and we act on them. Merchants and shoppers can also contact us directly at the address below.
9. International transfers
The App is hosted in the United States. If you access the service from outside the US, your data may be processed there.
10. Children
The App is a business tool and is not directed to children. We do not knowingly process the personal data of children.
11. Changes to this policy
We may update this policy as the App evolves. Material changes will be reflected here with a new “Last updated” date.
12. Contact
Questions or privacy requests: melbsdev@gmail.com.