ReportNest ("the App", "we", "our", "us"), published by AppNest Studio, is a Shopify app that builds sales, product, tax, discount and refund reports in Shopify Finance terms and delivers them on a schedule by email and Slack. This policy explains what data the App accesses, why, how long we keep it, and who it is shared with.
1. Who is who
The merchant who installs ReportNest is the data controller for their store's data. AppNest Studio is a data processor acting on that merchant's instructions. Buyers with questions about their personal data should contact the merchant; we assist the merchant in answering them.
2. Shopify scopes we request
| Scope | Why |
|---|---|
read_orders |
Read orders and refunds, the facts every report is built from. |
read_all_orders |
Shopify grants apps only the last 60 days by default. Reports that compare this month with last year, and the tie-out against past periods, need more. |
ReportNest requests no write scopes and no customers scope. It never modifies store data.
3. What we store
ReportNest keeps a local mirror of your order history so reports run quickly and can be reconciled against Shopify. This is Protected Customer Data (Level 1).
| Data | Stored? | Detail |
|---|---|---|
| Order facts | Yes | Order id and name, dates, financial and fulfillment status, currency, payment gateway, sales channel, tags, discount codes, and amounts (gross, discounts, shipping, taxes, total, refunded). |
| Shipping country code | Yes | ISO-2 only (e.g. DE), for sales-by-country and tax-by-country reports. |
| Customer id | Yes | The Shopify numeric id only, used solely to tell a first-time buyer from a repeat buyer. It is not resolved to a person and is erased on redaction. |
| Customer name, email, phone, address lines | No | The normaliser never reads these fields. This is asserted by an automated test. |
| Line item facts | Yes | Product, variant, SKU, vendor, product type, quantity and amounts. |
| Refund facts | Yes | Refund date and the returned, shipping and tax amounts. |
| Card / payment details | No | Only the gateway name is stored. We never see or store payment credentials. |
| Shopify access token | Yes | Encrypted at rest (AES-256-GCM, rotation-ready key ring). |
| Store email, timezone, currency | Yes | To address alerts and to compute day boundaries and money in your own terms. |
| Report definitions, schedules, delivery receipts, incidents | Yes | Configuration you create, plus the proof of what was delivered and when. |
**
4. What we do with it
Exactly one thing: build the reports you ask for and deliver them where you tell us to. Your data is never sold, never shared with other merchants, and never used to profile buyers or to train models. Exports go only to the recipients you configure.
5. Retention and deletion
| Data | Kept for |
|---|---|
| Order, line and refund facts | As long as the App is installed, this is your financial history. |
| Generated report files (CSV/XLSX) | 7 days, then deleted from object storage. |
| Delivery receipts | 1 year. |
| Webhook de-duplication records | 7 days. |
Uninstalling the App deletes everything we hold for your store: facts, reports, schedules, receipts, incidents, stored files and the session token. The same purge runs on Shopify's shop/redact request.
6. GDPR / CCPA webhooks
customers/data_request: we hold no personal data about buyers (no name, email, phone or address), so there is nothing personal to return. The request is acknowledged.customers/redact. We erase the customer id from that customer's orders, so the orders can no longer be linked to the person. The monetary totals remain, because they are the merchant's financial records.shop/redact, every row and file we hold for the shop is deleted.
7. Sub-processors
| Provider | Purpose | What it receives |
|---|---|---|
| Railway | Application hosting, PostgreSQL, Redis | All stored data described in §3 |
| Cloudflare R2 | Report file storage | Generated CSV/XLSX files (deleted after 7 days) |
| Resend | Sending report and alert emails | Recipient addresses, the report summary and the attached file |
| Slack | Slack delivery, only if you configure a webhook | The report summary you chose to send |
| Sentry | Error monitoring | Error traces, with email addresses and query arguments scrubbed before sending |
We use no analytics or advertising trackers inside the embedded app.
8. International transfers
AppNest Studio operates from India, and the providers listed above may process data in regions outside your own. Where a transfer leaves the UK or the European Economic Area, we rely on the Standard Contractual Clauses incorporated into those providers' data-processing terms. Write to support@appnest.studio if you need detail on a specific provider.
9. Security
HTTPS/TLS everywhere, including all webhook and OAuth callbacks. Shopify access tokens are encrypted at rest with AES-256-GCM. The database and object storage are encrypted at rest by the providers above. Every webhook is verified by HMAC signature and rejected if it does not match. Access to production is limited to the developer, for support.
10. Your rights
Merchants can delete all of their data at any time by uninstalling the App, or by writing to the address below. Buyers should direct GDPR/CCPA requests to the merchant who operates the store; we support the merchant in fulfilling them.
11. Changes
We will update this policy as the App evolves and revise the "Last updated" date above.
ReportNest by AppNest Studio · support@appnest.studio