This policy explains the information Obsidian Guard handles, why it is used, when providers receive it, and the choices available during the private beta. It should be read with the Terms of Service.
1. Who we are
Obsidian Guard, LLC operates Obsidian Guard, a private-beta protected-action service for supported commerce and business operations.
Privacy questions and requests can be sent to [email protected].
2. Information we collect
Depending on your use, we may collect:
- Account and organization details, including names, email addresses, roles, invitations, and authentication records.
- Shopify store identity, installation, permissions, order, refund, fulfillment, customer/order metadata, and webhook/event evidence needed for enabled controls.
- Workflow configuration, reviewer assignments, protected requests, decisions, comments, execution outcomes, detected events, exceptions, and activity history.
- Notification preferences, email addresses, phone numbers, push subscriptions, Slack configuration, delivery attempts, and mobile-alert usage.
- Plan, entitlement, Stripe customer/subscription references, and billing status. Stripe processes payment-card details; we do not intend to store full card numbers.
- Support submissions, diagnostic context, timestamps, IP/network and browser/device information, and security/operational logs.
3. How we use information
- Provide authentication, organization access, Shopify connectivity, protected workflows, reviews, execution, activity history, notifications, and support.
- Enforce plans, usage limits, mobile-alert credits, API access, and security controls.
- Diagnose failures, prevent abuse, investigate security events, and improve reliability.
- Communicate about private-beta access, service changes, support, privacy, and security.
- Comply with law and protect the rights, safety, and integrity of customers and the service.
6. International processing
Service providers may process information in countries other than where you live. The applicable transfer mechanisms, provider locations, and contractual disclosures require legal confirmation before public launch.
7. Retention, uninstall, and deletion
Direct Shopify customer identifiers needed to review or execute a protected request are removed after successful execution and are otherwise removed within 30 days after the request reaches a final state. We retain non-identifying authorization evidence, security records, and records required for legal, fraud-prevention, accounting, or dispute purposes for their applicable operational period.
Shopify privacy requests are recorded when received and must be completed within 30 days. Uninstall handling revokes the Shopify access token; Shopify's later shop-redaction request starts the reviewed deletion of remaining Shopify-derived records without automatically deleting unrelated workspace data.
You may request account or personal-data access, correction, export, or deletion by contacting us. A legal obligation may require limited information to be retained despite a deletion request; if so, we restrict it to that purpose.
8. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal a request decision. We may need to verify identity and organizational authority before acting.
Notification destinations and preferences can be changed in the product where available. Browser push permission can also be revoked in browser/device settings.
9. Security
We use technical and organizational measures designed to protect information, including production HTTPS, server-side authorization, organization scoping, database policies, one-way API-key hashes, and application encryption for supported stored integration secrets. No security measure eliminates all risk. See Security or report concerns to [email protected].
10. Children
The service is intended for organizations and adults authorized to act for them, not children. We do not knowingly offer accounts to children under 13.
11. Policy changes
We may update this policy as the private beta, providers, law, and product behavior change. Material updates will be communicated through an appropriate account, email, or product notice, and the last-updated date will change.
12. Contact
Contact [email protected] for privacy questions or requests. For legal notices, use [email protected].
