Public Shopify installation is not available yet. Check availability. Gmail is optional and requires a connected store.
Privacy
How CaseKit processes Shopify support data, account information and conversations when you use the optional Gmail extension.
Last updated: 10 September 2026
What the extension reads
CaseKit runs in Gmail and reads only the conversation currently displayed. It does this from the page itself, using a content script.
- CaseKit does not use the Gmail API and never requests Gmail account scopes. It does not automatically search your mailbox or open other conversations.
- It reads the sender and participant addresses on the open thread, any order number in the subject or message, and the text of the most recent message.
- Signing in uses Google identity only:
openid,emailandprofile. Nothing more.
Using CaseKit in Shopify Admin
The Shopify app works without Gmail, a Google account or the Chrome extension. When you ask for a reply, the app sends the order reference or customer email and the message you provide to api.casekit.app over HTTPS. Shopify session tokens authenticate access to your connected store.
Using the optional Gmail extension
The extension sends candidate customer email addresses, order references, a customer-message snippet capped at 800 characters, and a conversation identifier to our backend. The identifier supports duplicate-use detection; it is not a guarantee of anonymity. The extension does not upload attachments or entire mailbox contents. Google sign-in identifies the extension user; the extension stores its CaseKit session and account state locally in Chrome.
Shopify permissions and order data
CaseKit uses read_orders and read_customers to find the relevant order and customer and prepare support replies. Access normally covers the last 60 days of orders. It cannot edit, refund, cancel or fulfil an order.
Depending on the fields Shopify makes available, processing includes order references, customer name and email, dates, items, totals and currency, payment and fulfilment status, carrier and tracking information, refunds and returns, discounts, shipping method, order notes and tags, and the customer's order count.
Normalized order results are cached in Cloudflare KV for up to 90 seconds to avoid repeat Shopify requests. We do not maintain a permanent copy of Shopify order history in D1. The cache can contain the customer and order fields listed above. Results shown in an open browser remain there until the page or extension clears them.
Shopify credentials are encrypted with AES-GCM on our backend and are never returned to the extension. When CaseKit processes Shopify's uninstall notification, it disables the connection and deletes the stored credentials.
Account, workspace and operational storage
Cloudflare D1 stores account email and identity, workspace and membership, store domain, encrypted credentials, subscription state, monthly usage, reply language, tone and policy settings, feedback identifiers and operational audit events. Do not put unnecessary customer information or sensitive personal details in tone or policy settings.
Website assistant abuse controls store daily salted hashes of IP addresses and request counters in Cloudflare KV for up to 48 hours. Cloudflare KV also stores temporary authentication state, connection claims, invitation and subscription-cache records, usage-deduplication identifiers and rate-limit records. If you join the availability list, we store your email and any store domain you provide until you connect or request removal. Signing into the extension before connecting a store also enrolls that account in the availability list.
Operational logs support troubleshooting and can contain request paths, store identifiers and upstream error diagnostics. CaseKit does not intentionally log message bodies or access tokens. Infrastructure providers also process technical request information, such as IP addresses, to operate and protect the service.
AI processing
Pro reply generation and AI rewrites use OpenAI. For the five supported reply languages, order facts and policy sentences remain in reviewed templates; AI selects an acknowledgment. Other AI rewrite features may rephrase draft text and require merchant review. Requests may include the draft, customer-message snippet, language, store tone and policy, case/status information, order age, order count, item names, tags and order notes. Names, order references and tracking details can also appear in the draft. Avoid including sensitive information that is not needed to answer the customer.
Free-plan support replies use server-side templates. This is separate from the website assistant: questions that its local knowledge does not answer may be sent, with recent conversation messages, to OpenAI through our website assistant service. Do not submit customer records, credentials or payment details to the website assistant. Provider processing and retention are governed by their applicable service terms; the 90-second order-cache period does not describe OpenAI's retention. OpenAI requests disable response storage; this does not mean that all provider security or abuse-monitoring retention is disabled.
Service providers and purpose
- Cloudflare: website and API hosting, database, caches and service security.
- Shopify: store authorization, order/customer information and app billing.
- Google: identity for the optional extension; Gmail hosts the conversation the extension reads.
- OpenAI: Pro reply processing, AI rewrites and website assistant responses when used.
We use this data to provide the requested features, manage access and billing, respond to support and privacy requests, and protect the service. Providers may process data outside your country. We do not sell personal data or use Gmail or Shopify customer content for advertising.
CaseKit's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through the Chrome extension is used only for its disclosed support functionality and complies with the Chrome Web Store Limited Use policy.
Billing
CaseKit Shopify app subscriptions are handled through Shopify. We store subscription state, not card details. Legacy direct purchases made before CaseKit 2.0 used PayPal; questions about those purchases should be sent to support.
Retention and privacy requests
Order-cache entries expire within 90 seconds. Account and workspace records are retained while needed to provide the service. Following uninstall, Shopify normally sends a shop-erasure request after 48 hours; CaseKit then removes the uninstalled store and its workspace data, retaining accounts that still belong to another workspace. A reinstalled active store is not erased by a stale uninstall request.
We verify Shopify's mandatory customer data-request, customer-erasure and shop-erasure webhooks. CaseKit does not keep a durable shopper profile or order-history database; transient order caches expire within 90 seconds. Merchants can contact us for help with access, correction or deletion requests, including customer information they may have entered into settings or support messages.
Email support@casekit.app to request access, correction, deletion or availability-list removal. We verify the requester's authority before disclosing or deleting data and respond within 30 days, subject to applicable legal requirements. Billing or support records may be retained where needed to meet legal obligations or resolve a dispute.
Website
We do not run advertising trackers on casekit.app. The site uses service infrastructure and browser storage where needed for its features. Demo videos are hosted by YouTube; loading a video involves Google's services. The website assistant has the separate processing described above.
Changes
Material changes to this policy will be announced on the changelog before they take effect.
Contact
Privacy questions: support@casekit.app
Infra Cloud Services S.A.R.L AU, Morocco