TheSocialForks

Privacy Policy

Last updated 13 September 2026

This policy explains what personal data TheSocialForks ("we") processes through TheSocialForks, an app for Shopify merchants, why, and what control merchants and their customers have over it. For personal data about a merchant's customers, the merchant is the controller and we process it on the merchant's behalf.

What we collect

When a merchant installs TheSocialForks, the app receives read-only access to parts of their Shopify store. It never changes anything in the store.

  • Store details: the store's domain, name, timezone, currency and plan.
  • Orders: order number, dates, payment and fulfillment status, totals, shipping cost, the destination country and region (never a street address), and line items (product and variant identifiers, SKU, quantity and price).
  • Shipments: carrier, tracking number, delivery status and tracking events.
  • Refunds: amounts, dates and the items refunded.
  • The store's published shipping and returns policies.
  • A customer's email address, used only to create a one-way code (a keyed hash) so the app can recognise repeat problems for the same customer and act on deletion requests. The email address itself is never stored. We do not request customers' names, phone numbers or street addresses.
  • Customer questions: when a signed-in customer asks about their order on its status page, the question, the answer and the order they relate to are kept, with a one-way code for the customer. We never ask customers for personal details, but they may choose to type some into a question.
  • Merchant staff activity in the app, such as acknowledging a problem or approving a message, with the staff member's Shopify user ID, so the store has an audit trail.
  • Settings a merchant chooses to add: a Slack channel connection (stored encrypted), email addresses for digests, and names for API keys (the keys themselves are stored only as one-way hashes).

How we use it

We use this data only to provide the app to the merchant who installed it:

  • to detect order and delivery problems and show the evidence behind them;
  • to send the alerts and digests the merchant asks for;
  • to answer a customer's questions about their own order, when the merchant turns this on;
  • to answer questions in Shopify Sidekick and trigger Shopify Flow, when the merchant uses them;
  • to apply the merchant's plan, which Shopify bills;
  • to keep the service secure, fix errors and provide support.

What we don't do

We do not sell personal data, share it for advertising, or use merchant or customer data to train AI models. We do not set advertising or tracking cookies.

Automated answers

If a merchant turns on customer answers, replies are written with the help of an AI model and checked against that order's facts before a customer sees them. They cannot offer refunds, promise delivery dates the carrier hasn't given, or discuss any other order; anything the app can't answer is passed to the merchant. No automated decision the app makes has legal or similarly significant effects on a customer, and the merchant can turn the feature off at any time.

Who we share it with

We use the following service providers, only for the purposes above:

  • Shopify, which hosts the store and bills for the app.
  • Anthropic, PBC, which provides the AI model. It receives the computed figures for a digest summary and, for a customer's question, that order's facts and the question — never a customer's email address, name, street address or identity. Only used when the merchant has these features on.
  • Slack Technologies, when a merchant connects Slack, to deliver alerts and digests to the merchant's own workspace.
  • Resend, when a merchant adds email addresses, to deliver alerts and digests to those addresses.
  • Our hosting and database providers, which store the data.
  • The merchant's own systems, when the merchant creates a read-only API key and uses it.

International transfers

Our service providers may process data outside the merchant's or customer's country, including in the United States. Where the law requires it, we rely on safeguards such as the standard contractual clauses our providers offer.

How long we keep it

  • Raw notifications received from Shopify are deleted after 90 days.
  • Customer questions and answers are deleted after the retention period the merchant chooses, and never kept longer than 365 days.
  • Resolved order problems are kept for the period the merchant chooses in Settings.
  • When a merchant uninstalls the app, Shopify sends a request to erase the store's data 48 hours later, and we delete all of it.
  • When a customer asks a merchant to erase their data, Shopify passes the request on: we delete the orders Shopify lists and everything attached to them, delete every question that customer asked, and remove the link between the customer and any other order.

Your choices and rights

Customers: because the merchant decides how your data is used, please contact the store you bought from. Requests to access or erase your data reach us through Shopify, and we act on them automatically.

Merchants: you can export everything the app holds for your store from Settings at any time, erase it by uninstalling, and contact us at support@thesocialforks.com with any question or request.

Security

Data is encrypted in transit. Store access tokens and Slack connections are encrypted with AES-256-GCM, customer email addresses are replaced with a one-way code before they are stored, and API keys and store-linking codes are kept only as one-way hashes. Access is limited to the people who need it to run the service, and actions in the app are recorded in an audit log. If a security incident affects a merchant's data, we will tell that merchant without undue delay.

Children

TheSocialForks is a business tool and is not directed at children.

Changes to this policy

We will update this page when our practices change, and tell merchants about material changes in the app or by email before they take effect.

Contact

TheSocialForks — support@thesocialforks.com, or by post to F-17, 408, Centurion Park O2 Valley, Greater Noida West, Uttar Pradesh 201306, India.

Privacy · Terms · support@thesocialforks.com