Privacy Policy
At Cazi Media, we are committed to protecting your privacy. This Privacy Policy explains how we handle your data when you visit our websites, use our software, or interact with our plugins and integrations.
1. Privacy-First Software Design
As a software development studio, Cazi Media builds applications and extensions designed to interact with your productivity platforms (like monday.com and Shopify). We strive to engineer solutions that minimize data processing and eliminate unnecessary data retention. Many of our applications process data entirely in transient memory (at the edge runtime) and do not persist your operational files or private content.
2. Information We Collect and Process
Depending on which Cazi Media applications or services you use, we may temporarily process or access the following data types:
- Usage and Interaction Data: Minimal telemetry or error reporting logs to ensure app stability.
- Authorization tokens: Apps verify platform session tokens to authenticate requests. Apps that need continuing platform access also store OAuth access and refresh tokens. Storage and deletion depend on the app, as described in its privacy details.
- App-Specific Media and Files: Transient media buffers necessary to complete user requests (like zipping documents or routing contracts). These are governed by specific, app-level privacy policies.
- AgentNative Entitlements: Opaque payment claim identifiers, hashed API tokens, Stripe customer and subscription identifiers, entitlement status, and minute-level rate-limit counters. We do not receive or store card numbers.
- CountSafe Inventory Counts: CountSafe stores shop and installation identifiers, encrypted Shopify access and refresh credentials, preview and plan-access state, locations, inventory identifiers, product and variant titles, SKUs, baseline quantities, entered counts, revisions and count status in Cloudflare Durable Objects. Count records are isolated by shop and installation. Saved counts remain available after plan cancellation. Uninstall cleanup removes the affected installation's records after its identity is verified; ambiguous events remain pending verification and can delay deletion. Webhook delivery records contain only event identifiers, topics, shop identity when included in the signed event, receipt times and processing status or retry timing, never raw payloads or credentials. Unfinished records remain until verified resolution; completed delivery and lifecycle records are retained for at most 31 days. CountSafe does not request customer or order data.
- Promoter Briefs: Wix site and event identifiers, event titles and times, ticket names and aggregate quantities, order digests, gross totals and currency, encrypted verified-recipient addresses, schedules, and delivery state. Buyer names, buyer email addresses, contact/member identifiers, payment methods, and free-form buyer details are discarded before processing. Site data is deleted when the app is removed or the owner requests deletion.
- LinkLifeboat Delivery Recovery: LinkLifeboat stores the shop domain, an expiring Shopify offline access token with its refresh token, the recovery files a merchant uploads (held in Cloudflare R2 with their SHA-256 checksums), the Shopify product and variant identifiers those files are attached to, and for each paid order a Shopify order identifier, an optional Shopify customer identifier, entitlement state, download count and timestamps. It does not store customer names, email addresses, phone numbers or postal addresses. A customer redaction request clears the stored customer identifier, uninstalling the app clears the access token, and a shop redaction request deletes that shop's files and records.
Fulfillment Lens privacy
Fulfillment Lens stores shop and installation identifiers, Shopify access and refresh credentials, order-linked fulfillment reports, item and location details, quantities and report history in Cloudflare D1. Optional delivery settings contain your HTTPS receiver and a signing secret. Reports sent there are subject to your receiver's retention. Shopify handles billing; Cloudflare Workers runs the app. Customer email and phone from privacy webhooks are not stored. Connection observation times and reconnection status are also stored.
Merchants can review Shopify privacy requests and download the matching stored reports and quantity changes without a paid plan. Confirming receipt records merchant receipt, not delivery to the customer. Customer erasure removes the specified orders from stored reports and history. Keyed order fingerprints prevent those records from being regenerated.
Reports, quantity history, audit records and webhook receipts have a configured 365-day retention. Privacy exports expire after 30 days. Requested order IDs are cleared after merchant acknowledgement or the next daily cleanup after expiry. Terminal request metadata expires 60 days after the request was received. Scheduled processing delays can delay cleanup. Verified installation removal deletes the affected installation's records and suppression fingerprints; unresolved installation identity is retried. For access or unresolved requests, contact [email protected] with your shop domain and request reference, without credentials.
Queued processing stores only necessary order and request IDs, a keyed digest and operational metadata. Payloads and digests are cleared when processing completes; completed job metadata expires after 7 days. Failed pending jobs retain the identifiers needed for retries. Unprocessed data-access jobs expire after 30 days, but erasure jobs continue retrying until resolved. Cleanup runs on a schedule and may be delayed. Installation lifecycle jobs also keep a keyed fingerprint of the credential pair. Raw credentials are not copied into queued jobs. Unresolved jobs retain this fingerprint until resolution, supersession or removal of the installation's data.
Location Guard privacy
Location Guard stores shop and authorized administrator identifiers, rotating Shopify offline access and refresh tokens, product and variant identifiers, inventory locations and quantities, guard and reservation records, keyed request fingerprints for duplicate prevention, synchronized draft summaries, and audit events. Optional customer email and note fields are used to create your requested draft. Privacy requests retain request references, matching fingerprints, review decisions and export delivery state.
This data lets the app check stock at your selected location, prevent conflicting reservations, create drafts you confirm, synchronize draft status, recover failed operations and handle customer privacy requests. Shopify processes subscription billing. Cloudflare Workers and D1 run the app and store its records; Cloudflare Pages hosts this website.
Optional email and note fields expire at the reservation's original 30-minute deadline and are removed when the workflow reaches a terminal state. Expired fields are scrubbed by scheduled cleanup, normally every 15 minutes, and during app activity. Guard history and synchronized draft records remain while the app is installed; audit events expire after 365 days. Export downloads expire after 30 days, or within 24 hours after retrieval. Cleanup may run later if processing is delayed.
Shopify customer data requests appear in the app's Privacy requests section, which remains available without a paid plan. Exact matches are included in a customer export. Records with uncertain associations require merchant review. Customer erasure removes matching app records and prevents their reimport, while retaining necessary suppression fingerprints. Installation removal is verified against current connection state and signed Shopify lifecycle evidence. Ambiguous requests affecting an active installation remain pending for review.
Queued events retain necessary draft identifiers, keyed matching fingerprints, delivery and retry metadata. Installation checks also retain connection observation times and a keyed fingerprint of the credential pair; raw credentials are not copied into queued jobs. Successful processing removes queued jobs. Failed or ambiguous jobs, privacy review records, suppression fingerprints and unresolved token-operation markers have no fixed expiry. Webhook delivery receipts expire after 7 days. Verified shop erasure removes the shop's app records.
Deletion from the active database does not immediately remove provider recovery copies. Cloudflare D1 recovery copies may retain deleted data for up to 30 days, and Workers Logs retain operational logs for up to 7 days. Draft orders already created in Shopify remain subject to Shopify's records and the merchant's own deletion controls.
For access, deletion or unresolved privacy requests, contact [email protected]. Include the shop domain and request reference, but do not send passwords or access tokens.
3. App-Specific Privacy Policies
Because different applications perform different actions, some Cazi Media tools maintain their own dedicated, app-specific privacy policies detailing exactly how they access and process metadata and content (e.g., our ZIP Exporter Privacy Policy). We recommend reviewing those individual policies when installing our tools.
4. Subprocessors and Third-Party Services
The services below support our websites and apps. Each app's privacy details identify the services it uses. Some website pages load fonts from Google Fonts; embedded Shopify apps load Shopify's App Bridge and interface components from Shopify's CDN.
- Cloudflare: Hosts websites and app services through Pages and Workers, with D1, Durable Objects or R2 storage where the app needs it. Operational logs and stored app records have different retention periods; see the app's privacy details.
- The platform you installed from (e.g. monday.com, Shopify): our apps call that platform's own API and file URLs, under your permissions, to read only the data you asked us to act on.
- Stripe: hosts AgentNative checkout and processes subscription payment details. We receive payment, customer, and subscription identifiers through signed webhooks to grant or revoke access.
- Microsoft: Microsoft Graph sends Promoter Briefs verification messages and scheduled reports from our Cazimedia mailbox. Microsoft processes the recipient address and message only to deliver and retain the sent message under our Microsoft 365 account.
5. Information Security
We implement strict administrative, technical, and physical safeguards to protect all data in transit. We enforce HTTPS encryption for all transactions and host our micro-SaaS backends on globally distributed edge networks to ensure enterprise-grade security.
6. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our tools or platform requirements. Any updates will be posted directly to this page with an updated modification date.
7. Contact Us
If you have any questions or security concerns regarding our data policies, please reach out to us at:
Email: [email protected]