Order Triggers Privacy Policy

Operated by Sognora · Effective September 10, 2026

What Order Triggers reads

When one of your orders is fulfilled, gains a tracking number or is canceled, the app is notified and reads that one order back from your store's order service using the permission you granted at install. It reads the order number, the fulfillment status, the line item names and quantities, the order total, the shipment's tracking number, carrier and tracking link, the times involved, and the identifier of the contact the order belongs to.

What Order Triggers passes on

Those values are placed in the event it reports so that the automation you built can use them — for example, so your email can say the tracking number. The contact identifier is included so the platform's own email action knows who to send to; the app never sees which message you send or what it says.

What Order Triggers stores

Four things. Your app installation record (installation identifier, site identifier, plan state, an authentication token, and whether you have been asked for a review and your answer). Which of the four triggers you have switched off. One row per event it decided about, holding the trigger, the order identifier, the order number, the shipment identifier, the tracking number, the times, the outcome and the reason. And a count of reported events per month, which is what the free plan's limit is measured against.A record of each installation, uninstallation and plan change (installation identifier, site identifier, event kind, plan and time) is also kept as our billing and support record, and is kept after the rest has been deleted. It names no person.

What Order Triggers deliberately does not store

Buyer names, email addresses, phone numbers, shipping and billing addresses, payment details and the contact identifier are never written to our database. The order is read for one event, the values are handed to the platform, and they are dropped. A retry re-reads the order rather than replaying anything stored, which is also why a tracking number you corrected in the meantime goes out corrected.

How the data is used and shared

Order data is used only to decide which of your triggers to report and to fill in that event. It is not sold, not used for advertising and not used to build buyer profiles. The app sends nothing to any third-party service beyond your store's own API: there is no carrier account, no external automation service and no analytics vendor in this app.The service is hosted on Fly.io and its database is provided through Supabase. Those vendors process data only to host and operate the app.

Retention and deletion

Event rows are deleted 90 days after they are written. Settings and the monthly count exist while the app is installed. When the app-removal event is delivered, the app immediately deletes your settings, your entire activity log and your monthly counts, and clears its authentication token. A minimal removal record remains so the installation cannot be treated as live again. To request access, correction or deletion at any other time, email shin@sognoragroup.com. We verify that the requester is authorised for the site before acting.

Security and international processing

Every inbound request from the platform is verified cryptographically: dashboard sessions with an HMAC-SHA256 signature, webhooks with an RS256 signature. Data is encrypted in transit and isolated to this app's own database schema, which no other app on the same server can read. Sognora operates from South Korea; the hosting infrastructure may process data in other countries, including the United States.

Changes and contact

Material changes appear on this page with a new effective date. Privacy, security and deletion questions go to shin@sognoragroup.com.
·Privacy