Privacy policy
This describes what Kubal receives from a connected store, why it is needed, where it is held and for how long. Last updated 14 September 2026.
Who we are
Kubal provides software that receives changes from a merchant's store and delivers them to other software that merchant has chosen. Contact us at admin@kubal.online.
Where a merchant installs Kubal on their store, the merchant decides what data is collected and who receives it. We process that data on their instructions.
What we receive
| Store information | Your store address and when the app was installed or removed. |
|---|---|
| Change notifications | The full detail Shopify sends when something changes: orders, products, variants, stock levels, fulfilments and refunds. |
| Customer details inside orders | An order from Shopify contains the customer's name, email address, phone number and addresses. We receive this because it is part of the order, not because we sought it separately. |
| Account information | For the optional Kubal account used to manage several stores: an email address, handled by our authentication provider. |
| Operational records | What we attempted to deliver, when, to which destination, and whether it succeeded. |
We do not collect payment card numbers. Subscription charges are handled by Shopify and we never see card details.
Why we hold it
- To deliver each change to the destinations a merchant has connected.
- To retry a delivery that failed, and to let a merchant resend a period after an outage.
- To show a merchant what was sent, what arrived and what did not.
- To apply the rules and checks a merchant has configured.
- To count usage so storage and retention limits can be applied.
We do not sell data, and we do not use it to train machine learning models.
Who else sees it
Destinations receive only what the merchant has granted them. A destination granted access to orders but not to customer details never receives names, email addresses, phone numbers, shipping addresses or checkout links; those fields are removed before the data leaves us, both when it is delivered and when it is read back through our API.
Our service providers:
| Cloudflare | Runs the service and stores the content of each change. |
|---|---|
| Supabase | Stores records of stores, destinations, deliveries and accounts. |
| Shopify | Source of the data, and handles subscription billing. |
| Resend | Sends alert emails, where a merchant has chosen email alerts. |
We disclose data to law enforcement or a regulator only where we are legally required to, and we will tell the affected merchant unless prohibited from doing so.
How long we keep it
| Content of changes | 7 days on the free plan, 30 days on the paid plan, then deleted automatically. |
|---|---|
| Delivery records | Kept while the store remains connected, so history stays readable after the content has gone. |
| Store and destination settings | Kept while installed, and removed on request after uninstall. |
When Shopify asks us to erase a store's data, we delete the stored content of every change for that store. When Shopify sends us a customer erasure or access request, we record it and respond within the 30 days Shopify requires.
Where it is held
The service runs on Cloudflare's global network, and stored content may be held in more than one region. Records are held in the Supabase region chosen when the service was set up. Where data is transferred across borders, we rely on our providers' standard contractual protections.
Security
- Access credentials for a store are encrypted before being stored, and are never written to logs.
- Every delivery is signed so a receiving system can confirm it came from us.
- Each destination can read only the store that granted it access, and only the categories granted.
- Access keys are stored as one-way hashes and shown once. Removing a destination revokes its access immediately.
- Records are separated by store at the database level, not only in application code.
No system is beyond failure. If a breach affects a merchant's data, we will tell them and the relevant authority within the time the law requires, and explain what happened.
Your rights
Depending on where you live, you may have the right to ask what we hold about you, to correct it, to have it deleted, to receive a copy, or to object to how it is used.
If you are a shopper who bought from a store using Kubal, your relationship is with that merchant. Ask them, and they can instruct us. If you write to us directly we will pass the request to the merchant and help them answer it.
Merchants can exercise these rights by writing to admin@kubal.online. We respond within 30 days.
Children
Kubal is for businesses. It is not directed at children, and we do not knowingly collect data about them.
Changes
If we change this policy in a way that materially affects merchants, we will tell connected merchants by email before it takes effect. The date at the top shows the last revision.
Contact
Questions, requests and complaints: admin@kubal.online. If you are in India, you may also raise a grievance with us at that address, and we will respond within the period required under the Digital Personal Data Protection Act.