Skip to main content

Privacy Policy — Entrupy Authentication for Shopify

Last updated: July 31, 2026

Entrupy Inc. ("Entrupy," "we," "our," or "us") provides Entrupy Authentication for Shopify, which connects your Shopify store to Entrupy's authentication service. This Privacy Policy applies only to the Entrupy Authentication Shopify app. Your use of Entrupy's other products and services is governed by Entrupy's general Privacy Policy and, where applicable, Entrupy's Terms of Service.

Who this is for

This Privacy Policy applies to merchants who install and use Entrupy Authentication for Shopify. The app is a business-to-business integration that connects a merchant's Shopify store with their Entrupy account and does not collect or store the personal data of the merchant's end customers (shoppers).

Data the app stores

The app stores only the information necessary to connect your Shopify store with your Entrupy account and operate the app. This information does not include a merchant's end-customer personal data.

The app stores:

  • your Shopify store domain;
  • a Shopify access token;
  • your Entrupy API key;
  • feature settings and configuration;
  • an Entrupy webhook identifier.

The app writes product authentication results (authentication status and certificate link) as metafields on the merchant's own Shopify store. The app requests only the minimum Shopify permissions required to operate (read/write products and write files) and does not request access to orders or customers.

Data the app does not store

The app does not collect or store merchants' end-customer personal information, including customer names, email addresses, mailing addresses, payment information, order data, checkout information, or other protected customer data. Because the app does not request access to Shopify customer or order data, our responses to Shopify's required customer data request and customer redaction webhooks confirm that no such information is maintained.

How data is used

We use the information maintained by the app solely to:

  • authenticate the app with Shopify;
  • connect your Shopify store to your Entrupy account;
  • synchronize authentication results to your Shopify products;
  • operate, maintain, and secure the app; and
  • support the functionality selected by the merchant.

We do not sell personal information or use information collected through the app for advertising purposes.

Data sharing

We share information only as necessary to operate the app, including with:

  • Shopify, to read and update authorized store information;
  • Entrupy's authentication services, to retrieve authentication results associated with the merchant's Entrupy account; and
  • service providers that help us host, operate, and secure the app (such as cloud infrastructure providers).

We may also disclose information where required by law or to protect our legal rights.

Retention and deletion

Data is kept while the app is installed. On uninstall, the app deactivates the Entrupy webhook and soft-deletes stored credentials. Following Shopify's required shop/redact webhook after uninstall, the store record is permanently deleted, typically within 48 hours of uninstall. Product metafields remain under the merchant's control; the storefront badge is removed automatically on uninstall.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information maintained by the app, including encrypted communications (HTTPS) and access controls designed to limit access to stored credentials.

Data location

Information maintained by the app is stored and processed using Amazon Web Services (AWS) infrastructure operated by Entrupy in the United States. If you install and use the app from outside the United States, you acknowledge that information maintained by the app will be transferred to and processed in the United States.

Contact

If you have questions about this Privacy Policy or our privacy practices, please contact us at privacy@entrupy.com.

Changes

Material changes are reflected by the "Last updated" date and communicated to installed merchants where appropriate.