Sitelet https://github.com/fullbleed-engine/docs/pull/34/files
Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
30 changes: 30 additions & 0 deletions docs/commerce/privacy.md
Original file line number Diff line number Diff line change
Expand Up @@ -58,13 +58,40 @@ including previews, automation, and downloads. Failed work does not count.

## Retention and deletion

### Access history in the next preview update

The next preview deployment adds **Access history**, available to authenticated
store staff even without a paid plan. It records requests for order lists,
document previews and PDFs, automation activity, privacy exports and access
history itself. It also records Flow document preparation and private-link
downloads. This update has passed local synthetic-store checks; it is not yet
running on the hosted preview.

Each entry contains the store, action, time, outcome and relevant order, job or
privacy-request reference. Staff requests include the staff ID from the verified
Shopify session. Automated requests use a Flow run or document job identifier;
a private link does not identify the person holding it. The history excludes
customer names, addresses, document contents, full download links, tokens and
IP addresses. A collection read records the action without listing every
customer or order returned.

Entries expire after 30 days. Customer erasure removes matching order and
associated privacy-export references sooner; marking a privacy request handled
removes references to that export. Uninstall and shop erasure remove all of the
store's access history. Generic collection-read entries contain no customer
reference and follow the 30-day policy. Encrypted recovery copies follow the
restoration and deletion process below.

### Application records

| Information | Retention in the live application database |
| --- | --- |
| Authorization, branding, and saved templates | Until replaced or deleted where the app offers that action, or until an authenticated uninstall or shop-erasure notification is processed. |
| Automation job history | 30 days. Customer erasure revokes affected links and clears order references and verification hashes. Empty action-run records can remain for up to 30 days to prevent delayed retries from recreating a document. |
| Plan usage | The billing period plus 30 days. Customer erasure removes affected order references while retaining the period's aggregate count. Uninstall and shop erasure remove all of the store's usage records. |
| Outstanding customer-data exports | Until the merchant marks the request handled or Shopify requests erasure. Overdue requests remain visible and require action. |
| Completed or erased privacy-request receipts | 30 days after completion or erasure, without the live export, customer identity hashes, or order references. |
| Access history (next preview update) | 30 days, with earlier deletion of the corresponding order, privacy-export or store references as described above. |

Cleanup runs at startup and hourly while the app is running. An outage or a
paused preview can delay removal. Authenticated uninstall and shop-erasure
Expand All @@ -79,6 +106,9 @@ export of retained automation and order-usage metadata, including the customer
ID or email supplied to identify the request. Requested order references and
keyed identity hashes support subsequent deletion.

The next preview update also includes retained access to the requested orders
in this export, without staff identifiers or unrelated-store records.

Authorized store staff can download the export from **Privacy requests**
without a paid plan, then respond through the store's privacy process.
Fullbleed does not email these exports. The app displays the 30-day response
Expand Down
Loading