Daybook

Privacy policy

Daybook turns purchase orders your buyers email you into Shopify draft orders. Those emails contain other people's business details, so this page states exactly what we touch and — more importantly — what we deliberately do not keep.

What we read from your store

After you install the app we hold access tokens for your shop, encrypted at rest with AES-GCM. We use them to:

We never complete an order, charge a card, or change inventory. The app has no code path that does any of those things.

What happens to an order email

Mail sent to your intake address at cardiworkshop.com is read once, in memory, and then discarded. We do not store the original email or its attachments. What we keep is the order table we extracted from it:

Anything else in the document — addresses, contact names, contract terms, logos, other sheets — is never written to storage.

What we store about you

When a purchase order arrives we also keep a short-lived fingerprint of it — a hash of the sender, subject, file name and order lines, plus the id of the earlier document — so we can tell you when the same order appears twice. It holds no readable content, it is deleted with the rest of your data when you uninstall or when a buyer asks us to erase theirs, and it expires on its own after 5 days.

Who else sees it

We do not sell, rent or share your data with anyone else, we do not use it for advertising, and we do not use it to train models.

Retention and deletion

Extracted documents are deleted automatically 90 days after they arrive — measured from when the message arrived, not from when you last edited it. Your inbox holds the 200 most recent, and up to 100 more can sit in the held-back list described below; anything pushed out of either list moves to a third list the app shows you, and is deleted within 7 days of landing there. When you uninstall, Shopify sends an app/uninstalled webhook and we delete your tokens, settings and every stored document. You can also request deletion at any time at cardi.workshop@gmail.com.

One thing we keep, and we would rather say it plainly than let you find out at the checkout screen: a record that this shop has used part of its free trial. It holds your .myshopify.com domain, a number of days, a date, and the ids of the subscriptions already counted — no order data, no addresses, nothing about your buyers. It survives uninstall on purpose, because otherwise uninstalling and reinstalling would hand out a fresh free trial every time, and it deletes itself 180 days after the trial that created it. If you want it removed sooner, write to cardi.workshop@gmail.com and we will delete it.

If one of your buyers exercises their rights

The personal data we hold about a buyer is the email address they sent the order from, together with the order table extracted from that email. We implement Shopify's mandatory compliance webhooks and act on them:

A second limitation, in the same spirit: if we held nothing for that buyer when the access request arrived, the record of that request names no documents, so an erasure request has nothing to match it against and it stays until it expires. It says only that a request was made and when — nothing about who made it — but Shopify can still tie the request id back to them.

One honest limitation: we identify a buyer by the address their email came from, while Shopify's request identifies them by the email on their customer record. If those differ, or if the person never became a customer in your shop, the request will not reach us. Tell us at cardi.workshop@gmail.com and we will erase by the sending address directly.

Contact

Questions about this policy, or about data we hold: cardi.workshop@gmail.com.

Last updated 2026-08-21 · Home · Support · Privacy · Terms