AmendLane privacy policy
AmendLane processes only the Shopify data needed to authenticate a shopper, determine whether an order can be corrected safely, apply a confirmed correction, and release the order to the merchant's fulfillment workflow.
What the app reads
- Order, line item, fulfillment order, hold, product variant, location, and customer identifiers, plus order status and amounts, so an eligible correction can be offered and verified.
- The signed-in shopper's customer identifier, used only to confirm that the order being changed is their own.
What the app does not do
- It does not store card details and does not charge a stored payment method.
- It does not write a shipping address. Delivery-detail changes are passed to the merchant as a request.
- It does not log names, addresses, email addresses, phone numbers, tokens, payment links, or raw webhook payloads.
Retention and deletion
- Access logs and compatibility samples are retained for 90 days.
- Resolved correction, hold, exception, and per-order usage records are retained for 180 days.
- Unresolved operations remain until they are recovered or reviewed, so the app does not silently lose a hold or financial obligation.
- Shopify customer-redaction requests remove the customer reference and customer operations. Shop redaction removes all shop data.
Security and subprocessors
Data is encrypted in transit and stored in the merchant's isolated Cloudflare Durable Object. Cloudflare provides the application runtime and SQLite storage. Access is authenticated, logged, and restricted to the scopes required by the supported workflow.
Merchant terms
AmendLane's data processing termsapply when a merchant installs and uses the app.
Contact
Privacy questions, deletion requests, and security reports can be sent to privacy@keelcroft.com.