Last updated October 7, 2026 · Pre-launch policy
Privacy Policy
MaterialClear provides production readiness tools for Shopify merchants. This policy describes the current service and its handling of merchant operational data. Merchants remain responsible for the personal information they choose to provide and for responding to their customers.
What we process
We process merchant identifiers and shop domains; restricted Shopify session credentials; order, line item, product and variant references; order numbers; display titles and SKUs; templates; production jobs; requirements; receipts; inspections; approvals; corrections; readiness snapshots; audit and delivery records. Receiving location records may include a merchant’s workshop address.
We do not persist structured Shopify Customer Name, Email, Phone or Address fields in the current application. Notes and uploaded photos can nevertheless contain personal information. Do not upload customer identities, addresses or other unnecessary personal information.
Supplier handoffs include shipment details, quantities and notes. Supplier and receiving access use opaque identifiers. Supplier bearer secrets are stored as hashes. Evidence includes private image files, file metadata, hashes and object versions.
Why and where
We use these records to calculate readiness, coordinate receiving and inspection, preserve operational history, authenticate authorized users, prevent duplicates, and operate and secure the service. Shopify supplies commerce and authentication data. Cloudflare processes runtime, D1 database, private R2 evidence and operational logging data. Access is limited by merchant scope and staff authentication or revocable scoped supplier access. Evidence is not a public file library.
Retention and deletion
| Record | Current lifecycle |
|---|---|
| Operational history and evidence | Retained while installed, until a verified deletion request or uninstall retention deadline. Uninstall revokes credentials and mutations immediately; recovery retention is up to 30 days. |
| Verified deletion / Shopify shop redaction | Blocks new operations and queues evidence removal and database deletion, with a completion deadline within 30 days. A documented, bounded legal hold may retain a specifically identified subset. |
| Deletion completion records | Minimized anonymous completion records retained for 90 days. |
| Replay protection | Hashed order replay tombstones retained for 30 days. |
| Managed export artifacts | Encrypted temporary artifacts have a maximum 24-hour lifetime and require operator cleanup. Separately downloaded copies require separate access and deletion controls. |
| Orphan cleanup records | Opaque object-key reconciliation records persist until cleanup is reconciled; they do not retain merchant or order references. |
Limited operational logs support reliability and security. Application logging excludes raw webhook payloads, authorization values and notes; URL query values are redacted. Cloudflare Workers Logs currently retain logs for up to 7 days on the Paid plan; any separately retained operator evidence follows its own controlled retention. Provider-managed recovery history, including D1 Time Travel (up to 30 days on the current Paid plan), may remain after live-record deletion. We cannot promise immediate, merchant-specific physical erasure from provider recovery systems or separately downloaded copies.
Shopify privacy requests
The service handles customers/data_request, customers/redact and shop/redact webhooks. Customer requests enter a verified review process, including possible personal information in notes or photos. An absence of structured customer columns does not replace this review. Authorized operators fulfill applicable requests and scoped deletion within the request deadline.
Export, access and contact
Verified merchant requests can be handled through the internal export and deletion process. Exports omit authentication credentials, raw supplier secrets and raw webhook bodies; image files are handled separately. Contact support through our Support page. We may update this policy as the service changes; the date above identifies the current version.