Effective September 1, 2026

App privacy policy

This policy explains how Parallel Studio's Shopify apps process information, why they need it, and the choices available to merchants and other affected people.

Parallel Studio LLC (“Parallel Studio,” “we,” “us,” or “our”) builds software for Shopify merchants. This policy covers ChangeProof, Makewright, and Deltaproof. A product may provide an additional notice where its workflow requires more detail. This policy does not replace a merchant's own privacy policy for its storefront or customers.

Our privacy approach

We design each app to request the least access its shipped features require. In particular, ChangeProof deliberately does not request:

  • shipping access, because Shopify's current grant surface bundles buyer names, email addresses, phone numbers, addresses, device, location, and shipping information;
  • checkout topics, because they expose buyer checkout objects; or
  • ShopifyQL reporting access, because it requires Level 2 protected customer data.

ChangeProof also does not request order, fulfillment, customer, payment, analytics, or staff access. These are product boundaries, not missing setup.

We do not sell personal information, use it for behavioral advertising, or collect payment-card details.

Information each app processes

ChangeProof

ChangeProof is an evidence-based store change ledger. It processes:

  • Shopify store identity and configuration, including the myshopify.com domain, primary storefront host, store email, installed-app identity, granted scopes, installation status, and Shopify subscription status;
  • supported product and variant fields, discount state, market metadata, theme settings, navigation menu structure, and changes to ChangeProof's own scopes;
  • webhook and event identifiers, timestamps, payload hashes, before-and-after values, and explicit source-confidence labels;
  • digest and report recipient emails, change policies, alert records, organization names and memberships, report branding, and credential lifecycle metadata; and
  • encrypted Shopify offline access and refresh tokens. Plaintext tokens are not written to the database or logs.

Rollback receipt tokens, organization invite codes, ledger API keys, and unsubscribe tokens are displayed or issued once where applicable and stored only as cryptographic hashes.

ChangeProof does not process orders, fulfillments, buyer checkout objects, customer records, shipping profiles, payment data, or ShopifyQL sales or customer analytics.

Makewright

Makewright helps merchants sell configurable and made-to-order products. It processes:

  • Shopify store identity, merchant contact and notification email, installation and subscription state, and app settings;
  • product identifiers, configuration templates, option and pricing rules, theme diagnostics, and draft-order or order references; and
  • information a shopper submits for a quote, which may include name, email, phone, company, configuration choices, project notes, messages, and uploaded specification files.

The merchant determines why shopper information is collected and is generally the controller of it. Makewright processes that information for the merchant. Shoppers should usually contact the merchant first about a quote or privacy request.

Deltaproof

Deltaproof audits agent-facing and human-facing public storefront behavior. It processes public catalog and policy pages, public agent-discovery documents, anonymous cart responses, scan findings, scores, report history, merchant-requested monitoring settings, and report-delivery contact information.

Deltaproof does not proceed to checkout, submit payment, provide a buyer identity, or retain checkout and continue URLs. Evidence redaction removes tokens, query strings, email addresses, and other values that are not needed for the report.

How we use information

We use information only to provide and secure the requested product workflows. Depending on the app, this includes authenticating a Shopify store, recording change evidence, showing a byte-exact rollback preview, verifying an applied write, rendering a product configurator, routing a quote, generating an audit report, sending opted-in notifications, detecting abuse, troubleshooting failures, and satisfying Shopify platform or legal requirements.

Service providers

We use a limited set of service providers:

  • Shopify for app authentication, Admin API data, webhooks, billing, Sidekick, and merchant storefront services;
  • Cloudflare for ChangeProof and Deltaproof application hosting, databases, queues, and operational logs;
  • Railway for Makewright application hosting, its PostgreSQL database, and operational logs;
  • Supabase for Makewright's private file and encrypted backup storage; and
  • Resend for transactional, digest, alert, and report email.

These providers process information under their own security and privacy commitments. Information may be processed in the United States or other locations where they operate.

Retention and deletion

Retention depends on the product and the merchant's settings:

  • ChangeProof exposes a 30-day Free history window and a 365-day paid history window. These are query windows, not promises that underlying evidence is physically deleted on those dates. While installed, evidence remains available to support ledger integrity, plan changes, and verified receipts.
  • Makewright files attached to rejected or expired quotes are eligible for deletion after the configured retention period, currently 90 days. Its encrypted database backups are pruned after 35 days.
  • Deltaproof retains scan reports and score history needed to provide the report and any monitoring the merchant requested. A merchant can stop monitoring at any time.

Our Shopify apps process Shopify's mandatory customer data request, customer redaction, and shop redaction webhooks. On uninstall, access credentials are revoked or purged. When Shopify directs us to redact a shop, app data linked to that shop is deleted or depersonalized in dependency-safe order, subject to narrowly required security or legal records. Email recipients can unsubscribe. Agency client stores can leave an organization, and API keys can be revoked.

Security

We use encrypted connections, access controls, shop-scoped authorization, signed and HMAC-verified Shopify requests, encrypted credentials, hashed one-time secrets, and fail-closed validation for sensitive operations. ChangeProof does not write a rollback unless the merchant-approved preview hash still matches the exact operation and current values. No internet service can guarantee absolute security.

Your choices and rights

Merchants can uninstall an app through Shopify, revoke ChangeProof API keys, leave a ChangeProof organization, remove notification recipients, stop Deltaproof monitoring, and use Makewright's available export and deletion controls.

To request access, correction, deletion, or another privacy action, contact the relevant merchant or email us. We may need to verify the request and the Shopify store before acting. Rights vary by location and may include access, correction, deletion, restriction, objection, or portability.

Changes to this policy

We may update this policy as our products, providers, or legal obligations change. We will publish the revised policy with a new effective date and provide additional notice where required.

Contact

Parallel Studio LLC
4532 Washburn Ave S
Minneapolis, MN 55410
United States
ggray225@gmail.com