Arcanum Hollow Labs · Shopify app
Hollow Sentinel — Privacy & data processing
Last updated: July 2026
This page describes how Hollow Sentinel (our Shopify embedded app) processes personal data on behalf of merchants. It supports our Shopify Partner protected customer data disclosures and gives merchants a clear record of what we collect, why, and how long we keep it.
Overview
Hollow Sentinel is an operational intelligence app for Shopify merchants. We process shop metrics, inventory and order aggregates, briefing preferences, and connector settings so merchants can monitor store health, anomalies, and revenue-at-risk signals.
Arcanum Hollow Labs acts as a service provider to the merchant. The merchant remains responsible for their storefront, customer relationships, and compliance with applicable privacy laws.
Personal and store data we process
Shop identity: shop domain, timezone, and subscription plan tier.
Authorization: encrypted Shopify offline access tokens and session metadata required to call the Shopify Admin API on the merchant's behalf.
Operational intelligence: business events, metric observations, store baselines, insights, briefings, and related health or snapshot data derived from Admin API reads (orders, products, inventory, themes) — typically as aggregates and operational records, not as a customer profile database.
Merchant contact preferences: alert recipient email addresses and briefing channel settings the merchant configures in Settings.
Connector credentials: encrypted Resend API keys, Slack incoming webhook URLs, and Klaviyo private API keys the merchant saves in Settings.
Optional Public API: hashed API keys when the merchant generates a Public API key on an entitled plan.
Billing: Shopify app subscription status via Shopify Billing API (no separate payment card storage in Hollow Sentinel).
Purposes of processing
We use the data above solely to provide Hollow Sentinel functionality: syncing store metrics, generating briefings and insights, delivering merchant-configured alerts, displaying health and timeline views, and managing app billing.
When AI narrative features are enabled on an entitled plan and an OpenAI API key is configured in our environment, we may send non-customer aggregate insight context to OpenAI to generate explanatory text for merchants.
We do not use merchant or customer data for advertising, resale, or unrelated analytics.
Data minimization
We request Shopify Admin scopes needed for operational monitoring (orders, products, inventory, themes) and process the minimum needed to power briefings, health scores, and insights.
Hollow Sentinel does not require read_customers. We do not maintain a first-class customer ledger in Sentinel. Merchants can uninstall the app to stop processing.
Merchant agreements and transparency
Merchants install Hollow Sentinel under the Shopify Partner Program terms and this data processing description.
We tell merchants what we process through this page, in-app Settings and documentation, and Shopify App Store listing materials.
Use of Hollow Sentinel is limited to the operational intelligence purposes described here.
Customer consent
Hollow Sentinel does not collect consent directly from a merchant's customers. Processing runs on the merchant's Shopify store data according to the merchant's configuration.
Merchants are responsible for providing appropriate notices and obtaining any required consent from their customers under applicable law.
No sale of personal data
We do not sell, rent, or trade merchant or customer personal data. We do not share data with third parties except subprocessors listed below, solely to operate the service.
Automated decision-making
Sentinel applies rules and models to store metrics to surface insights, health scores, and revenue-at-risk estimates for merchant operators. These are operational signals for the merchant team, not decisions with legal or similarly significant effects on consumers.
Hollow Sentinel does not make credit, employment, housing, or comparable eligibility decisions about customers.
Retention
Shop credentials and connector secrets are retained while the app is installed on the merchant's store.
Insights, briefings, business events, metrics, and baselines are retained to provide store memory and history. We apply reasonable retention limits and delete shop-associated Sentinel data when the app is uninstalled (including via Shopify shop redaction webhooks), subject to short operational backup cycles.
Merchants may contact us to request export or deletion assistance as described below.
Security
Data in transit is protected with TLS (HTTPS) between Shopify, our application, and integrated services such as Slack.
Sensitive values at rest (Shopify access tokens, Resend API keys, Slack webhook URLs, and Klaviyo API keys) are encrypted using application-level encryption before storage in our database.
Access to production systems is limited to authorized Arcanum Hollow Labs personnel with a business need.
Subprocessors
Shopify — commerce platform, webhooks, Admin API, and app billing.
Hosting and database providers — application hosting and PostgreSQL storage for shop configuration and operational intelligence records.
Resend (optional) — when the merchant connects email alerts, team alert emails are sent through the merchant's Resend account to configured recipient inboxes.
Slack (optional) — when the merchant connects a Slack incoming webhook, alert text is delivered to the merchant's chosen Slack workspace.
Klaviyo (optional) — when the merchant connects a Klaviyo private API key, Sentinel may use it for monitoring and merchant-configured Klaviyo-related signals.
OpenAI (optional) — when AI narrative features are enabled in our environment on an entitled plan, aggregate insight context may be sent to OpenAI to generate merchant-facing explanatory text.
Uninstall and deletion
When a merchant uninstalls Hollow Sentinel, we receive Shopify's app/uninstalled webhook and remove shop credentials, connector configuration, and Sentinel operational datasets associated with that store.
Shopify customers/data_request and customers/redact webhooks are acknowledged. Because Sentinel does not store first-class customer profile rows, there are typically no customer records to export or delete beyond shop-level operational data removed on uninstall or shop redaction.
Residual backups may persist for a limited period for disaster recovery, after which they are purged according to our retention practices.
Contact
Arcanum Hollow Labs
Privacy and data requests: privacy@arcanumhollow.com
For merchant support related to Hollow Sentinel, use the contact options on arcanumhollow.com or your Arcanum engagement lead.