Privacy Policy
Last updated August 24, 2026
GlassPalace is operated by Alessandro Gerelli in Italy. This policy describes how GlassPalace processes account, workspace, integration, and usage data.
Current Shopify data boundary
The Shopify app requires read_products and read_inventory. A workspace owner or admin can separately enable optional read_orders access for sales and profitability reporting. That optional sync processes order identifiers, timestamps, statuses, financial totals, line-item quantities, and current inventory unit costs. It deliberately excludes customer names, emails, phones, billing and shipping addresses, payment-card data, and every Shopify write permission. GlassPalace does not request read_customers or read_reports.
Shopify treats order data as protected customer data even when direct customer identifiers are excluded. GlassPalace therefore applies its Level 1 protected-data controls to the optional financials sync: field allowlisting, encrypted credentials, tenant isolation, role checks, human-access logging, scope-revocation purge, and uninstall/privacy-webhook handling. Order records are not exposed to the persistent workspace Agent; financial summaries use a minimized central projection.
Shopify requires the app to receive mandatory privacy webhooks. To authenticate, queue, and complete those requests, GlassPalace stores a minimized privacy inbox and receipt containing delivery metadata and the request identifiers Shopify supplies. Depending on the request, those identifiers can include a customer ID, a one-way customer email hash, order IDs, and a data-request ID. They are used only for the privacy workflow: they are not imported or synchronized as customer or order business records and do not appear in business views or Agent context.
Data we process
We process identity and contact details, workspace membership, connected-account metadata, OpenAgent conversations and workspace memory, audit events, device sessions, and model usage. Legacy approval records may remain during a compatibility and retention window, but no approval interface or execution worker is active. For integrations other than the submitted Shopify app, we process provider data only according to the permissions granted directly for that provider. Provider credentials are encrypted at the application layer and are not written into the OpenAgent filesystem.
Why we process it
We process data to authenticate users, operate isolated workspaces, synchronize connected services, show authorized business views, execute authorized actions, prevent abuse, provide support, respond to verified privacy requests, and measure model usage. We do not sell personal data or use connected business data to train public models.
Providers and international transfers
The Shopify app exchanges shop, catalog, and inventory data within its two required read-only permissions and, only after separate merchant consent, minimized order financials within read_orders. When you separately connect Google, Postiz, Pipeboard, Meta, or another provider, data is exchanged according to that provider’s own permissions and terms. Model prompts are sent only to the model provider selected for the workspace; the persistent workspace Agent does not receive Shopify order records. See our Subprocessors page for service providers.
Retention and deletion
The Shopify app retains shop metadata and synchronized catalog, inventory, and any separately authorized minimized order financial records while the connection is active. Revoking read_orders purges its order resources, cursors, derived financial facts, and protected operational traces. Disconnecting or uninstalling stops further synchronization and revokes credential use. Minimized Shopify privacy request identifiers and receipts are retained only as needed to process and demonstrate completion of the privacy workflow. Other provider data is retained according to its separate connection and grants. Workspace deletion immediately revokes access and begins a seven-day primary-volume retention period before purge.
Security and access-log records are retained with the workspace until its definitive purge unless a privacy redaction must sanitize them sooner. The service has no application-managed backup or disaster-recovery guarantee; loss of the hosting disk can permanently remove agent history and memory. Any encryption or backup claim for the managed PostgreSQL service depends on verified infrastructure-provider configuration and is not inferred from application TLS alone.
Your rights
You may request access, correction, export, restriction, or deletion by contacting geroale2000@gmail.com. We verify the requesting identity before acting.
Legal operator and contact
Alessandro Gerelli, Via San Procolo 10, 25010 San Felice del Benaco (BS), Italy. Privacy questions can be sent to geroale2000@gmail.com.