Privacy policy
Last updated
Cogsy is a Shopify app operated by Blackout Media, a company established in Brazil. It keeps a record of what a store's products cost. This page says what the app and this website collect, why, for how long, and where it is processed.
Cogsy does not read or store anything about a store's customers or orders. It has no permission to: the app asks Shopify only for access to products and to inventory.
What the app reads from a store
When a store installs Cogsy, the app reads from Shopify and keeps a copy of:
- The store's myshopify.com address and its currency.
- Each product variant: its Shopify id, the product's id, title and status, the variant's title, SKU and price, and the address of the product's image.
- The cost per item Shopify holds for each variant.
- For a Shopify bundle, which variants it is made of and how many of each.
The app also stores the access token Shopify issues for the store, which is what lets it read the catalog and write a cost back.
What a merchant enters
- Costs: the amount or percentage, the date it applies from, where the figure came from (a supplier's name, for example) and any note.
- The kinds of cost the store tracks, such as packaging or fulfilment, and the store's settings in the app.
- The rows of each CSV file imported, with the file's name.
- API keys, when a merchant makes one in Settings: the name given to the key, its first characters, when it was made and last used, and a one-way hash of the key. The key itself is shown once and not stored.
The app also keeps a record of each catalog sync it runs for a store: when it ran, how many variants it read and changed, and the error message if it failed.
The app does not store the names, email addresses or passwords of the people who use it. Signing in is handled by Shopify.
How it is used
To show what each variant costs and what margin it leaves, to keep the history of those costs, and, when the merchant asks, to write a cost per item to Shopify. Nothing is sold, shared for advertising or used to train models.
A merchant who makes an API key can read and change their own store's costs with it from their own tools. The key reaches that store's data only.
Where it is processed
- Cloudflare runs the app and serves this website, from its network worldwide. Its logs record requests to the app, including the store's address, for a short time.
- Neon hosts the database, on Amazon Web Services in the United States (Ohio).
- Shopify, whose admin the app runs inside.
How long it is kept
For as long as the app is installed. When a store uninstalls Cogsy, its access token is deleted at once. Shopify then asks the app to erase the store's data 48 hours after the uninstall, and the app deletes everything it holds for that store: the catalog copy, the costs and their history, the cost kinds, the bundles, the imports, the sync records and the API keys. A store that reinstalls within those 48 hours finds its costs as it left them.
This website
This website sets no cookies and runs no analytics or advertising scripts. Its fonts are loaded from Google Fonts, so a visitor's browser sends its IP address to Google when a page loads. Cloudflare, which serves the site, processes the IP address of each request.
When you write to us, we keep your message and your address so that we can answer. Ask us to delete them and we will.
Requests and questions
To see, correct or delete what Cogsy holds for your store, or to ask anything about this policy, write to support@cogsy.app from an address that belongs to the store. A buyer who wants their data from a store should ask the store: Cogsy holds none of it.
When this policy changes, the date at the top changes with it.