TrackJoy is provided by Vuerio. Questions and privacy requests can be sent to hello@vuerio.com.
1. Scope and roles
This policy describes how TrackJoy processes information when a Shopify merchant installs or uses the TrackJoy application. The Shopify merchant controls its store and customer relationship. TrackJoy acts as a service provider or processor for merchant data where applicable. Shopify separately processes data under Shopify's own terms and privacy policy.
TrackJoy is an administrative tool for merchants. It does not operate a customer-facing storefront feature, place customer-facing tracking cookies, or collect information directly from a merchant's customers.
2. Information processed
TrackJoy processes only the information needed to provide serial-number tracking:
- Merchant and staff session information: Shopify shop domain, OAuth access token, granted scopes, session expiry, and Shopify-supplied staff identity fields such as name and email when present.
- Order and customer information: Order identifiers, order names and dates, line-item details, customer display name, and order email are requested from Shopify when a merchant loads the dashboard, searches for a serial, or prepares a CSV export.
- Serial records: Manufacturer serial numbers, IMEIs or other device identifiers, order and line-item identifiers, and recording timestamps are stored in app-owned Shopify order metafields.
- Derived lookup data: An app-owned Shopify metaobject contains a serial hash, Order GID, and versioned serial record so TrackJoy can perform exact lookup and export without scanning all orders.
- Usage data: The Free-plan quota is stored in a private Shopify AppInstallation metafield using hashed order-unit slot identities. It does not store serial values or customer identity/contact fields.
- Operational logs: The production service may create limited security and diagnostic logs. Logs must not contain access tokens, full webhook payloads, customer names or contact details, or clear-text serial numbers.
TrackJoy does not maintain an external database of customer profiles, serial records, order records, or CSV exports. Prisma is used only for Shopify OAuth sessions.
3. How information is used
Information is processed to:
- authenticate merchants and maintain the Shopify app installation;
- let merchants select products that require serial tracking;
- record and correct one manufacturer identifier per tracked order unit;
- find the authoritative order associated with a serial number;
- generate merchant-requested CSV exports;
- enforce the selected Shopify-hosted usage plan;
- prevent duplicate serials and diagnose service or security failures; and
- respond to Shopify privacy and lifecycle webhooks.
TrackJoy does not sell personal information, share it for cross-context behavioural advertising, use it for unrelated marketing, or make automated decisions with legal or similarly significant effects.
4. Storage and subprocessors
Serial, index, and quota data is stored in the merchant's Shopify store using app-owned Shopify data resources. OAuth sessions and limited operational logs are hosted on self-managed infrastructure in the United Kingdom. Cloudflare provides public network, TLS, and DNS services. Shopify and Cloudflare process data as infrastructure providers under their respective terms and privacy commitments.
5. Retention and deletion
- Expiring Shopify sessions are retained until expiry or earlier deletion.
- All local sessions for a shop are deleted when TrackJoy receives a valid
app/uninstalledorshop/redactwebhook. - Customer names and email addresses are read from Shopify on demand and are not copied into TrackJoy's external storage.
- Operational logs are retained for no longer than 30 days and may be deleted sooner through bounded platform rotation.
- Encrypted session-database backups are retained for 14 days.
- Shopify-hosted serial/order audit records are retained for the merchant's operational, return, warranty-enquiry, audit, and legal-retention needs. Shopify controls the lifecycle and customer redaction of the underlying order data.
When TrackJoy receives customers/redact, it retains serial/order audit records because they do not contain duplicated customer name, email, phone, or address fields. Shopify's redaction of the underlying customer information is reflected the next time TrackJoy reads the order.
6. Privacy requests
Customers should normally submit access, correction, or deletion requests through the Shopify merchant with whom they placed an order. Shopify sends mandatory privacy webhooks to TrackJoy where applicable.
TrackJoy acknowledges valid Shopify privacy webhooks and completes applicable actions within the required period. Because TrackJoy does not keep a separate customer identity/contact database, customers/data_request does not produce an additional local customer profile. Merchants or data subjects may contact hello@vuerio.com with questions.
7. Security
TrackJoy uses Shopify authentication, signed-webhook verification, access-controlled app-owned data, TLS in transit, data minimisation, encrypted backups, access review, an incident-response process, and secret-safe logging practices.
No internet service can guarantee absolute security. Merchants are responsible for protecting their Shopify accounts, staff permissions, scanner devices, and exported CSV files.
8. International transfers
TrackJoy's self-managed application and session database are hosted in the United Kingdom. Shopify and Cloudflare may process information in other countries under their published data-transfer safeguards. Merchants should review Shopify's and Cloudflare's privacy information for details relevant to their location.
9. Changes
This policy may be updated to reflect product, legal, or infrastructure changes. Material changes will be identified by an updated effective date and communicated as required.
10. Contact
Vuerio
hello@vuerio.com