Cados Publish Matrix
Privacy Policy
Last updated: August 1, 2026
This policy explains the information Cados Publish Matrix processes when a merchant installs and uses the app. The app is built to preview, apply, and verify native product-variant publication changes for one supported sales-channel publication at a time.
Information we process
- Shop identifiers, the shop domain, Shopify AppInstallation ID, a random local installation-generation marker, installation state, granted scopes, and Shopify online or offline session records required for authentication. When Shopify supplies them, session records can include the staff user ID, name, email, locale, and account or collaborator flags.
- Limited acting-user references needed to associate a merchant-requested operation with its session.
- Product, variant, and publication identifiers; display snapshots; parent publication context; before, requested, and observed publication values; and relevant Shopify timestamps.
- Change jobs, change rows, mutation-attempt state, short-lived operation leases, bounded error codes, verification results, and timestamps.
- Webhook receipt identifiers, normalized topics, processing state, Shopify's trigger timestamp when required for lifecycle fencing, a local installation-generation marker, and a hashed shop link while processing is active. A completed uninstall or shop-redact receipt clears the generation marker and replaces the shop link with a shop-unlinked delivery tombstone. Raw webhook payloads are not retained in business tables.
We do not use or store Shopify customer records, orders, payment details, checkout data, shipping details, or customer personal information. The app does not need those data types for its publication workflow.
How information is used
We use the information above to authenticate the current merchant, display publication state, produce a zero-write preview, carry out explicitly confirmed changes, verify observed results, show history, and evaluate an eligible Boolean undo. Online sessions authorize merchant-triggered work. Offline sessions may be stored for installation and authenticated webhook mechanics; they are not used to bypass the acting user for publication changes.
Hosting and service providers
The application runs on Vercel in Singapore. Operational data is stored in a Neon-hosted PostgreSQL database in AWS US East (N. Virginia), so operational data can be transferred between Singapore and the United States. Shopify provides authentication, webhook delivery, and the Admin GraphQL API through which publication state is read and changed. These providers and their disclosed subprocessors process data in the locations where they operate only as needed to supply their respective services.
The current Vercel Pro runtime-log window is one day and this project has no external log drain. Neon Free provides point-in-time restore for up to six hours or 1 GB of data changes, whichever comes first. We have not configured a separate application-managed database backup export. Neon separately states that it performs daily encrypted backups across multiple availability zones and retains backup data for 30 days.
Retention and deletion
Change-job and row history has a nominal 30-day expiry. An explicit foreground apply, undo, recovery, or reconciliation operation can be claimed only before that deadline. If fewer than five minutes remain, only that job's expiry moves to five minutes after the claim, never beyond preview time plus 30 days and five minutes. A request at or after the nominal deadline cannot claim the job, and no later claim can renew the grace. After expiry the job is removed during an authenticated foreground maintenance pass; the app does not use a recurring background cleanup job. Authentication and shop records are kept while needed to operate an installed app.
Shopify-authenticated installation authority is the only path that creates or rotates an installed-shop generation. OAuth normally binds it in afterAuth; an exact stored session whose refreshed token was deliberately left unbound may retry the same confirmation. Token changes atomically clear the old local generation before that confirmation. When Shopify's current AppInstallation ID changes, data and sessions from the retired local generation are removed before the new generation is used. An authenticated app-uninstalled delivery must include a valid Shopify trigger timestamp and can delete only the immutable generation bound to that receipt. A ten-minute clock margin keeps near-simultaneous uninstall and reinstall evidence pending rather than deleting or acknowledging it. Shopify documents shop-redact as occurring 48 hours after uninstall. The app combines that causal schedule with the immutable local generation and first receipt time; a valid trigger header can only make the deletion test more conservative. A live, positively confirmed current AppInstallation and a clearly later install are preserved. A same-generation missed uninstall is deleted when it is strictly older than the causal margin and the first receipt has remained unsettled for ten minutes. The clock-skew band remains retryable for one hour; after that it is deleted unless Shopify positively confirms the exact current installation. A confirmed or clearly later installation is preserved and its pending uninstall receipt is completed and unlinked. Missing sessions and 401 responses do not independently authorize immediate deletion. An installed app that cannot be confirmed within the one-hour boundary can lose its app-held history and settings, and must be reopened or reauthorized to establish a fresh local generation. Publication values already stored by Shopify are not reversed. Unresolved uninstall and shop-redact receipt evidence is excluded from generic expiry pruning so the pending decision cannot silently disappear. A completed lifecycle receipt clears its generation link and becomes a shop-unlinked tombstone with an expiry marker seven days after completion. Authenticated customer data request or customer redact webhooks are acknowledged without returning or deleting customer records because the app does not store them.
Changes stored by Shopify
Removing the app deletes app-held data, but it does not reverse publication changes already applied inside Shopify. A merchant should review or reverse those publication values in Shopify, or use an eligible in-app undo before uninstalling. The app does not restore original publication timestamps.
Data minimization and security
Access tokens remain in Shopify session storage and are not copied into the app's business records. Raw GraphQL responses, raw webhook payloads, and customer data are not stored in those records. Log messages emitted by the application use allowlisted operational fields and exclude access tokens, raw payloads, shop domains, product titles, and raw error messages. The hosting provider can separately retain request and function metadata within the runtime-log window described above.
Contact
Privacy questions or deletion concerns can be sent to cadosy@gmail.com.