Arcanum Hollow Labs · Shopify app
Margin Keep — Privacy & data processing
Last updated: August 2026
This page describes how Margin Keep (our Shopify embedded app) processes personal data on behalf of merchants. It supports our Shopify Partner protected customer data disclosures and gives merchants a clear record of what we collect, why, and how long we keep it.
Overview
Margin Keep is a contribution-margin and campaign-insurance app for Shopify merchants. We process shop identity, product cost profiles, promotion and sale-price audits, Safety Studio simulations, order-level margin evaluations (order identifiers, not customer profiles), Protect settings, and optional merchant alert connectors so merchants can spot unprofitable promotions and optionally Flag or Block risky checkouts when costs are trustworthy.
Arcanum Hollow Labs acts as a service provider to the merchant. The merchant remains responsible for their storefront, customer relationships, and compliance with applicable privacy laws.
Personal and store data we process
Shop identity: shop domain, timezone, and subscription plan tier.
Authorization: encrypted Shopify offline access tokens and session metadata required to call the Shopify Admin API on the merchant's behalf.
Cost and margin configuration: product/variant cost profiles (including sync and spreadsheet imports), margin floors, fee estimates, peak-sale settings, loss budgets, and Flag/Block checkout policy settings the merchant configures.
Promotion and sale-price analysis: discount and sale-price audit findings, Safety Studio simulation inputs/results, margin rules, findings, and Decision ledger evaluations keyed to Shopify order and line identifiers — not a customer profile or CRM store.
Merchant contact preferences: notification email addresses and weekly report settings the merchant configures in Settings.
Connector credentials: encrypted Resend API keys (email), Slack incoming webhook URLs, and Microsoft Teams incoming webhook URLs the merchant saves in Settings.
Checkout enforcement metadata: shop and variant metafields published so the Cart Validation Function can apply the merchant's Flag/Block policy on the live cart (unit costs and policy; no customer PII).
Billing: Shopify app subscription status via Shopify Billing API (no separate payment card storage in Margin Keep).
Purposes of processing
We use the data above solely to provide Margin Keep functionality: syncing and reviewing product costs, simulating promotions, auditing discounts and sale prices, recording Decision ledger evaluations, delivering merchant-configured alerts, publishing checkout policy when the merchant chooses Flag or Block, and managing app billing.
We do not use merchant or customer data for advertising, resale, or unrelated analytics.
Data minimization
We request Shopify Admin scopes needed for products, inventory, discounts, and orders, and process the minimum needed for cost coverage, audits, simulations, and Protect features.
Margin Keep does not require read_customers. We do not maintain a first-class customer ledger. Evaluations store order identifiers and margin math, not shopper names or emails. Merchants can uninstall the app to stop processing.
Merchant agreements and transparency
Merchants install Margin Keep under the Shopify Partner Program terms and this data processing description.
We tell merchants what we process through this page, in-app Settings and documentation, and Shopify App Store listing materials.
Use of Margin Keep is limited to the contribution-margin and campaign-insurance purposes described here.
Customer consent
Margin Keep does not collect consent directly from a merchant's customers. Processing runs on the merchant's Shopify store data according to the merchant's configuration.
Merchants are responsible for providing appropriate notices and obtaining any required consent from their customers under applicable law — including checkout messaging when Block mode is enabled.
No sale of personal data
We do not sell, rent, or trade merchant or customer personal data. We do not share data with third parties except subprocessors listed below, solely to operate the service.
Automated decision-making
Margin Keep applies merchant-defined margin floors and Flag/Block policy to carts and orders. In Flag mode, risky carts are recorded on the Decision ledger after the order. In Block mode, the Cart Validation Function may stop checkout when live margin is below the active floor and every line has high-confidence cost data.
Enforcement is fail-open: missing, estimated, or uncertain costs never stop checkout. These are merchant operations controls for promotions and checkout, not credit, employment, housing, or comparable eligibility decisions about consumers.
Retention
Shop credentials and connector secrets are retained while the app is installed on the merchant's store.
Cost profiles, simulations, audits, findings, evaluations, and Protect settings are retained to provide history and campaign tools. We apply reasonable retention limits and delete shop-associated Margin Keep data when the app is uninstalled or Shopify sends a shop/redact webhook, subject to short operational backup cycles.
Shopify customers/data_request and customers/redact webhooks are acknowledged. Because Margin Keep does not store first-class customer profile rows, there are typically no customer records to export or delete beyond shop-level operational data removed on uninstall or shop redaction.
Merchants may contact us to request export or deletion assistance as described below.
Security
Data in transit is protected with TLS (HTTPS) between Shopify, our application, and integrated services such as Slack and Microsoft Teams.
Sensitive values at rest (Shopify access tokens, Resend API keys, Slack webhook URLs, and Microsoft Teams webhook URLs) are encrypted using application-level encryption before storage in our database.
Access to production systems is limited to authorized Arcanum Hollow Labs personnel with a business need.
Subprocessors
Shopify — commerce platform, webhooks, Admin API, Shopify Functions (Cart Validation), and app billing.
Hosting and database providers — application hosting and PostgreSQL storage for shop configuration, cost profiles, audits, simulations, and Decision ledger records.
Resend (optional) — when the merchant connects email alerts, weekly summaries and test emails are sent through the merchant's Resend account to configured recipient inboxes.
Slack (optional) — when the merchant connects a Slack incoming webhook, alert text is delivered to the merchant's chosen Slack workspace.
Microsoft Teams (optional) — when the merchant connects a Teams incoming webhook, alert text is delivered to the merchant's chosen Teams channel.
Uninstall and deletion
When a merchant uninstalls Margin Keep, we receive Shopify's app/uninstalled webhook and remove shop credentials, connector configuration, cost profiles, rules, simulations, audits, findings, evaluations, and related Margin Keep datasets associated with that store.
Shopify shop/redact triggers the same shop-level purge. customers/data_request and customers/redact are acknowledged with no customer profile rows held.
Residual backups may persist for a limited period for disaster recovery, after which they are purged according to our retention practices.
Contact
Arcanum Hollow Labs
Privacy and data requests: privacy@arcanumhollow.com
For merchant support related to Margin Keep, use the contact options on arcanumhollow.com or your Arcanum engagement lead.