SafeOptions — Privacy Policy

Effective 4 August 2026

SafeOptions is a Shopify app operated by Sognora. It adds customer input fields (such as an engraving message) to your products, and checks every order to confirm those fields actually arrived on it. This policy describes what the app stores about your shop and about the orders it checks, and what it deliberately does not store.

For the shop data described below, Sognora acts as your service provider and processes it on your instructions to operate the app.

1. What the app stores

2. What the app deliberately does not store

3. Permissions the app requests

The app requests 3 access scopes and no others:

The product scopes are used to read your catalog, so you can choose which products and collections an option set applies to, and to publish your option-set definitions to an app-owned metafield that your theme reads in order to draw the fields. The app does not create, edit or delete your products; the only write it performs is to that one metafield on its own app installation. The order scope is used to receive the order-created webhook and to re-read recent orders when a webhook was missed, which is how every order gets checked.

4. Alert emails

When an order arrives without an option it should have carried, the app emails the address you configured, from shin@sognoragroup.com. Delivery is handled by Resend, acting as our email processor. The message contains the order name, the field keys that did not arrive, the time of the check and a link to the order in your Shopify admin — never a value a buyer typed, because the app does not hold one.

5. Retention and deletion

6. Sub-processors and disclosure

Shop data is not sold, is not used for advertising, and is not used to train machine-learning models. It may also be disclosed where the law requires it, or to protect the service and its users.

7. Security and location

Data is encrypted in transit over HTTPS. This app's data lives in its own PostgreSQL schema, reached by a database role that has no access to any neighbouring app's data. Credentials are held as deployment secrets and are kept out of application code. The application is operated from the United States, so data may be transferred there from your country.

8. Your choices and requests

You can switch alerts off or change the alert address on the Settings screen at any time, deactivate or delete an option set, or uninstall the app — which starts the deletion described in section 5. You may also ask us to access, correct or delete your data, or object to a particular use of it, and you may complain to the data protection authority in your country. We will confirm that a requester is authorised for the shop before acting.

9. Changes and contact

Material changes will be posted on this page with a new effective date. Privacy questions and requests go to shin@sognoragroup.com. Never include an API key, password or access token in a message to us.

Privacy · Terms · Support