Privacy Policy
Notesly Instructions Hub processes the minimum protected customer and order note data required to provide merchant note workflows. We do not claim that the app processes no customer data; order and customer notes may contain personal data if merchants or customers put personal data inside notes.
Data processed
- Store domain and app session data.
- Product identifiers, titles, SKUs, vendor and status where needed.
- Order identifiers, order names, order note fields, order custom attributes, and line item instruction attributes.
- Customer identifiers and customer note fields.
- App-owned internal notes, tags, priority, status, due date, and assignee.
- Billing status, settings, sync job status, and operational logs.
Data not requested by default
The app does not request customer email, phone, first name, last name, billing address, or shipping address by default. Enhanced customer identity display is not part of the MVP.
Storage and search
Note content is stored encrypted. Search indexes use protected tokenization and HMAC token hashes where implemented. Owner/admin panels are designed to show operational metadata, not merchant note content.
Deletion and privacy webhooks
The app supports Shopify privacy webhooks for customer data request, customer redact, and shop redact events. Merchants can request deletion through support.