← Back to ORKA

Privacy Policy

This page is maintained by ORKA to answer common privacy questions about how the product handles merchant data.

What ORKA reads from your Shopify store

When you connect your store, ORKA requests read-only OAuth scopes only: read_orders, read_products, read_customers, and read_inventory. ORKA does not request any write_* scope — it cannot edit prices, change inventory, fulfill orders, issue refunds, or create discounts.

How your data is stored

  • Shopify access tokens are encrypted at rest with AES-256-GCM before being written to our database.
  • Encryption keys are server-side only and never exposed to the browser.
  • Every database table is protected by row-level security: a merchant can only ever query their own store's rows.

Who can see your data

Only you. ORKA does not sell, rent, share, or use your store data for any purpose other than generating the insights you see in your dashboard. We do not use your data to train AI models for other customers.

Subprocessors

ORKA relies on the following third parties to operate the service. Each processes your data strictly under contract to deliver ORKA's functionality:

  • Supabase — managed Postgres database (data at rest, authentication, row-level security).
  • Cloudflare — application hosting and edge runtime.
  • Stripe — subscription billing and payment processing (ORKA never sees your card details).
  • Lovable AI Gateway — the model gateway used to generate AI briefs. Your data is sent per request to produce your own brief and is not retained by the gateway for model training.

Data retention

ORKA retains your data only while your account is active. When you disconnect Shopify or delete your account, your store data is purged immediately — there is no additional retention window and no cold backup that survives deletion. Uninstalling the ORKA app from Shopify triggers the same purge automatically via the app/uninstalled webhook.

Webhooks

Shopify sends ORKA event notifications (orders, refunds, inventory, uninstall). Every webhook is verified with HMAC-SHA256 before processing. Duplicate webhooks are detected by their Shopify webhook ID and only processed once.

Your controls

  • Disconnect Shopify — revokes the access token and deletes all synced data from ORKA. Available in Settings.
  • Export my data — downloads a single JSON file containing your operational store data replicated in ORKA: orders, order_line_items, products, variants, customers, alerts, opportunities, ai_briefs, notification_settings, and sync_logs. The export does not include internal billing records or low-level sync bookkeeping (webhook receipts, sync cursors, billing events) — those are internal to ORKA's operation and are removed when you delete your account.
  • Delete my account — permanent deletion of your account, all connected stores, all replicated Shopify data, and all internal billing and sync records associated with your user.

Cookies

ORKA uses strictly necessary cookies for authentication and OAuth state. We do not use third-party advertising or tracking cookies.

Contact

Privacy questions: orkaanalisis@gmail.com.