ChangeDesk — Privacy Policy
ChangeDesk ("the app") tells Shopify merchants when their store configuration changes and shows exactly what changed. This policy explains what data the app processes and why.
Data we process
ChangeDesk holds read-only permissions and can never write to a store. It reads the store's configuration objects so it can compare them over time: discounts (title, status, value, dates, usage limits, combination rules, discount codes and the most recent Shopify event for the discount), delivery profiles (profile names, shipping zones, the countries in each zone, and each rate's name, price and active state), markets (names and handles), locations (name, active state, online-order fulfilment and the business address of the location), sales channels (name and auto-publish setting), selling plan groups (group and plan names, merchant codes and options), themes (name and role only), the store's own settings (store name, the store's contact and customer-facing e-mail addresses, primary domain, currency, timezone, weight unit, tax settings and plan name) and the list of permissions granted to ChangeDesk itself.
For each of these it stores a snapshot of those fields, a computed before/after difference, and the merchant's own settings (which object types to watch, alert thresholds, and an optional alert webhook URL).
Data we do NOT collect
ChangeDesk stores no customer personal data: no names, e-mail addresses, shipping addresses, payment details, carts, checkouts or order records. It does not request read_orders, read_customers or any protected customer data scope. It does not read theme files, product content, variant data or inventory. No cookies, no tracking, no advertising identifiers.
Data retention and deletion
The raw payload Shopify sends with each change is kept for 30 days and then deleted automatically; the small computed differences and snapshots are kept so the merchant's history stays readable. Every delivery attempt for an alert is logged with its destination URL and outcome. Uninstalling the app stops all alerts immediately, and every record held for the shop is permanently deleted in response to Shopify's shop redaction webhook.
Third parties
If a merchant configures an incoming webhook URL (for example Slack or Microsoft Teams), ChangeDesk posts alert summaries — the change headline, its severity, the object type and the time — to that URL. Nothing else is sent anywhere, and no data is ever sold or shared.
Attribution
Shopify only exposes the author of a change for a small number of object types. Where an author is not available, ChangeDesk says so plainly rather than inferring one. It never collects staff identities beyond what Shopify itself returns on those objects.
Contact
Fleeta Limited — sales@fleeta.co.uk