Privacy Policy
Effective date: July 15, 2026
1. Introduction
TicketLens ("we," "us") is a Shopify embedded app that helps merchants analyze product support issues by connecting Shopify order, line item, and SKU data with Gorgias support ticket data. TicketLens produces aggregate SKU-level Product Issue Reports, repeat-contact risk, issue trends, estimated support cost, and product issue alerts.
This policy describes what we collect, why we collect it, how long we keep it, and how it is deleted.
We do not sell customer data. We do not use customer data for advertising.
2. Data we collect from Shopify
With merchant authorization, TicketLens accesses:
- Shop domain and app session data for authentication
- Orders, including order ID, order number, dates, totals, and status
- Order line items, including SKU, product title, variant, quantity, and price
- Customer email and phone on orders, used only to match tickets to orders
- Billing and subscription status for app billing
TicketLens uses the Shopify read_orders scope. We do not request write access to Shopify data, and we do not request a standalone customers scope.
We do not collect customer names, shipping or billing addresses, payment methods, or Shopify customer IDs as standalone customer records.
3. Data we collect from Gorgias
When a merchant connects their Gorgias helpdesk, TicketLens may access:
- Helpdesk subdomain for API access
- Tickets, including ticket ID, subject, status, and created date
- Ticket message text, used to extract order numbers for linkage
- Customer email and phone on tickets, used only to match tickets to orders
- Account name for connection verification
Gorgias credentials or OAuth tokens are stored encrypted at rest. TicketLens does not display ticket bodies or customer contact details in the merchant dashboard.
4. Why we collect this data
We process this data only to:
- Match support tickets to Shopify orders
- Attribute support issues to products and SKUs
- Compute aggregate analytics such as ticket rates, issue trends, repeat-contact risk, and estimated support cost
- Show merchants SKU-level Product Issue Reports and alerts
Customer email and phone are used solely as match keys when an order number is missing from ticket content. They are not used for outreach, profiling, marketing, or advertising.
5. What merchants see
Merchants see aggregate SKU-level metrics only — for example SKU and product names, ticket counts and rates, trends, estimated support cost, and product issue alerts.
Individual customer email, phone, names, and ticket message bodies are not shown in the TicketLens dashboard.
6. Data retention
TicketLens retains synced orders, tickets, and related linkage data for a rolling 60-day window. Older records are purged automatically. Aggregate SKU metrics are recomputed from retained data.
7. Data deletion and uninstall
- App uninstall: All shop data is deleted from TicketLens systems.
- Shop redact webhook: Remaining shop data is deleted after Shopify's uninstall grace period.
- Customer redact webhook: Matching tickets are deleted, and customer email/phone are removed from matching orders.
- Merchant request: Contact support@ticket-lens.com.
8. Shopify GDPR and privacy webhooks
TicketLens implements Shopify's mandatory privacy webhooks:
customers/data_request— acknowledges requests. TicketLens does not maintain standalone customer profiles; stored fields are limited to order and ticket matching data.customers/redact— deletes or redacts customer-linked records.shop/redact— deletes all shop data after uninstall.
9. Subprocessors
TicketLens uses the following subprocessors to operate the service:
- Shopify — app platform, authentication, billing, and webhooks
- Gorgias — support ticket source (merchant-connected)
- Supabase — database hosting
- Railway — application hosting
These subprocessors process data only as needed to run TicketLens. We do not authorize them to use merchant or customer data for their own marketing.
10. Security measures
- Gorgias credentials are encrypted at rest
- Shopify API access is limited to
read_orders - Application logs are sanitized to avoid API keys, tokens, email, phone, and raw ticket bodies
- All traffic uses HTTPS
- Access to operational systems is limited to what is needed to run the service
11. Merchant responsibilities
Merchants are responsible for having a lawful basis to connect Shopify and Gorgias data, and for configuring permissions in those accounts.
12. Changes
We may update this policy from time to time. Material changes will be posted on this page with an updated effective date.
13. Contact
Questions about this privacy policy or TicketLens data practices: