Otheriver Audit Logs Privacy Policy

Effective date: 18 August 2026

This Privacy Policy describes how Otheriver Audit Logs (“the App”) handles information when a Shopify merchant installs or uses the App.

1. Who we are

The App is provided by Alex Marcone, trading as Otheriver / Otheriver Apps, VAT number IT 02172620672, Via Primo Riccitelli 3, Teramo, Italy (“Otheriver”, “we”, “us”). Privacy enquiries and data-rights requests can be sent to apps@otheriver.com.

For merchant account, support and billing-administration data, Otheriver generally acts as an independent controller. For store and customer data processed to provide the App to a merchant, Otheriver generally acts as a processor or service provider on the merchant’s instructions. The merchant remains responsible for its own privacy notices and lawful use of the App.

2. Information the App processes

Depending on the merchant’s store and enabled Shopify permissions, the App may process:

  • shop domain, installation state, Shopify access scopes and authentication/session data;
  • merchant or staff account details supplied by Shopify for authenticated sessions, such as name, email, locale and user identifier;
  • Shopify activity returned by the Admin Events API, including timestamps, resource identifiers, action, message and available actor/app attribution;
  • operational webhooks for products, collections, orders, fulfillments, customers and inventory;
  • current product-variant and SKU details used to enrich an export;
  • technical request metadata for API calls made by this App, including operation, status, duration and aggregate row/error counts;
  • identifiers included in Shopify privacy-law data-access and erasure requests;
  • information a person chooses to send in a support request.

The App does not intentionally store payment-card details. Billing is handled by Shopify.

3. Data minimisation

Personal webhook fields such as names, email addresses, phone numbers, postal addresses, IP/browser details and order notes are replaced with a redaction marker before webhook payloads are stored. Shopify Admin Events are queried when a merchant requests them and are not copied into the App database as a persistent event archive. Technical API-call logs store operational summaries, not complete Shopify API responses.

Resource identifiers and other operational fields can remain where needed to find, filter, export, match or erase audit records.

4. Why information is processed

We process information to:

  • install, authenticate, secure and operate the App;
  • display, filter and export audit activity requested by the merchant;
  • capture the merchant’s selected operational webhook history after installation;
  • diagnose performance and API errors generated by this App;
  • provide support and communicate about service or security matters;
  • administer subscriptions through Shopify;
  • respond to privacy-law requests and meet legal obligations;
  • prevent abuse and protect the App, merchants and Otheriver.

Depending on the context, the legal basis can be performance of a contract, legitimate interests in operating and securing the service, compliance with a legal obligation, or consent where applicable.

5. Retention

  • Sanitised webhook audit records: rolling 90 days.
  • Technical API-call records: rolling 30 days.
  • Shopify sessions: for the installation period; active sessions are removed on uninstall.
  • Remaining shop data: deleted when Shopify sends the mandatory shop-redaction request and in any event within 30 days after a valid deletion request, unless retention is legally required.
  • Infrastructure backups: a rolling point-in-time recovery window of approximately four weeks and never more than 30 days, after which deletion propagates through the backup cycle.
  • Support communications: up to 24 months after the last interaction, unless needed for an unresolved dispute or legal obligation.
  • Billing, accounting and tax records: for the period required by applicable Italian law.

Retention cleanup runs automatically. Shopify controls the timing of some platform events, including the shop-redaction webhook sent after uninstall.

6. Service providers and international transfers

The App relies on Shopify for installation, APIs, authentication and billing, and on Railway for application and database hosting. These providers may process data in countries outside the merchant’s country. Where required, transfers are protected through the provider’s applicable contractual and legal safeguards. Provider terms and locations can change; current details are available from their public privacy and security documentation.

We do not sell personal information and do not use App data for third-party behavioural advertising.

7. Security

We use access controls, separate production credentials, HTTPS, Shopify HMAC verification, shop-scoped database queries, data minimisation, retention controls and dependency/availability monitoring. No system is completely secure, and merchants should export only the records they are authorised to access.

8. Privacy rights and Shopify requests

Depending on applicable law, individuals may have rights to access, correct, delete, restrict or object to processing, receive portable information, or lodge a complaint with a supervisory authority. A Shopify customer should normally contact the merchant that controls the store. Shopify can send the App mandatory customers/data_request, customers/redact and shop/redact webhooks. A merchant can download the sanitised records matched to a customer data request from the authenticated Privacy & retention screen. Requests can also be sent to apps@otheriver.com.

9. Changes

We may update this Policy when the App, providers or legal requirements change. We will publish the updated effective date and provide additional notice where required.