Third-party connectors

This page describes how Kuwalyst processes data from third-party services connected to your workspace. It supplements our main Privacy policy, which covers Kuwalyst's general data handling.

Shopify

Last updated: 7 May 2026

This section describes how Kuwalyst processes data from Shopify stores connected to your Kuwalyst workspace.

What we ingest

When a merchant connects their Shopify store to Kuwalyst, we read the following via Shopify's Admin GraphQL API:

  • Orders — line items, totals, fulfilment status
  • Products and variants — SKU, title, pricing, inventory
  • Customers — id, email, country, lifetime spend, order count. Kuwalyst uses this only for aggregate cohort and segmentation analysis. Individual customer-level data is not displayed in the product UI.
  • Discounts and discount codes
  • Abandoned checkouts
  • Customer-journey UTMs and referrer data attached to each order

Kuwalyst requests read-only scopes and cannot modify any merchant or customer data.

Storage and location

Synced data is stored in per-merchant DuckDB files on EU infrastructure (Scaleway, Paris region). One DuckDB file per data source, isolated at the filesystem level. OAuth access tokens and other credentials are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256) before being written to the application database.

Retention

Data is retained while the merchant has the Kuwalyst app installed. When the merchant uninstalls, Kuwalyst receives Shopify's app/uninstalled webhook and immediately revokes its copy of the access token. Approximately 48 hours later, Shopify sends the shop/redact webhook, at which point Kuwalyst deletes the entire DuckDB file and all associated metadata.

Customer redaction (GDPR / CCPA "right to be forgotten")

When Shopify sends a customers/redact webhook for a specific customer, Kuwalyst deletes that customer's rows from every relevant table — customers, orders, abandoned checkouts, order line items, customer journey — within minutes of receipt.

Customer data requests

When Shopify sends a customers/data_request webhook, Kuwalyst forwards the request to support@kuwalyst.ai for manual processing. We respond to the merchant within 30 days with a data export covering everything we hold about the named customer.

Sub-processors

Kuwalyst transmits Shopify-sourced data only to the LLM providers that power its analytics agents:

  • Scaleway Generative APIs (EU, France) — primary LLM provider

We do not share Shopify-sourced data with any other third party.

Contact

For privacy or data-handling questions about any connector, contact contact@kuwalyst.ai.