Privacy Policy

Notesly Instructions Hub processes the minimum protected customer and order note data required to provide merchant note workflows. We do not claim that the app processes no customer data; order and customer notes may contain personal data if merchants or customers put personal data inside notes.

Data processed

Data not requested by default

The app does not request customer email, phone, first name, last name, billing address, or shipping address by default. Enhanced customer identity display is not part of the MVP.

Storage and search

Note content is stored encrypted. Search indexes use protected tokenization and HMAC token hashes where implemented. Owner/admin panels are designed to show operational metadata, not merchant note content.

Deletion and privacy webhooks

The app supports Shopify privacy webhooks for customer data request, customer redact, and shop redact events. Merchants can request deletion through support.