This page describes how Kuwalyst processes data from third-party services connected to your workspace. It supplements our main Privacy policy, which covers Kuwalyst's general data handling.
Last updated: 7 May 2026
This section describes how Kuwalyst processes data from Shopify stores connected to your Kuwalyst workspace.
When a merchant connects their Shopify store to Kuwalyst, we read the following via Shopify's Admin GraphQL API:
Kuwalyst requests read-only scopes and cannot modify any merchant or customer data.
Synced data is stored in per-merchant DuckDB files on EU infrastructure (Scaleway, Paris region). One DuckDB file per data source, isolated at the filesystem level. OAuth access tokens and other credentials are encrypted at rest using Fernet (AES-128-CBC + HMAC-SHA256) before being written to the application database.
Data is retained while the merchant has the Kuwalyst app installed. When the merchant uninstalls, Kuwalyst receives Shopify's app/uninstalled webhook and immediately revokes its copy of the access token. Approximately 48 hours later, Shopify sends the shop/redact webhook, at which point Kuwalyst deletes the entire DuckDB file and all associated metadata.
When Shopify sends a customers/redact webhook for a specific customer, Kuwalyst deletes that customer's rows from every relevant table — customers, orders, abandoned checkouts, order line items, customer journey — within minutes of receipt.
When Shopify sends a customers/data_request webhook, Kuwalyst forwards the request to support@kuwalyst.ai for manual processing. We respond to the merchant within 30 days with a data export covering everything we hold about the named customer.
Kuwalyst transmits Shopify-sourced data only to the LLM providers that power its analytics agents:
We do not share Shopify-sourced data with any other third party.
For privacy or data-handling questions about any connector, contact contact@kuwalyst.ai.