Kenney Labs CourseKeep / Privacy Back to product ↗

App data / Merchant and customer disclosure

CourseKeep privacy notice

This notice explains how CourseKeep processes information when a Shopify merchant installs the app and uses it to deliver courses, memberships, credits, or digital files.

Effective and last updated August 5, 2026

RolesData processedPurposesProvidersRetentionChoices

01 / Roles

The merchant controls its customer relationship.

The Shopify merchant determines which products, courses, files, memberships, and policies it offers. For customer data processed to provide those offerings, Kenney Labs generally acts as the merchant's service provider or processor. Kenney Labs is the controller of account, security, support, and business records it uses for its own legitimate operations.

02 / Data processed

Bounded records needed to decide and deliver access.

  • Merchant shop domain, installation state, approved Shopify scopes, encrypted offline access credential, configuration, and app activity.
  • A Shopify customer account identifier and a pseudonymous analytics reference. CourseKeep does not require a stored customer name, postal address, phone number, or email to enforce access.
  • Shopify product, order, refund, subscription-contract, and billing-attempt identifiers and statuses needed to grant, maintain, or review entitlements. Raw webhook bodies are reduced to bounded identifiers before asynchronous processing.
  • Course progress, membership state, credit issuance and redemption records, file-download counters, timestamps, and immutable entitlement evidence.
  • Merchant-uploaded course and digital-file content, filenames, types, sizes, checksums, object versions, and publication history.
  • Security, reliability, queue, storage, delivery, and aggregate product-usage telemetry. Tenant analytics use pseudonymous references rather than shop domains.

Shopify or the merchant's payment provider handles checkout and payment credentials. CourseKeep does not store card or bank-account details.

03 / Purposes

Operate the app, protect content, and honor lifecycle events.

CourseKeep uses these records to authenticate merchants and customers; manage content; verify purchases, memberships, grace periods, and credits; deliver courses and signed downloads; enforce merchant-configured limits; process uninstall and privacy requests; prevent abuse; diagnose failures; and produce aggregate operational and product analytics.

CourseKeep does not sell personal information or use customer activity for cross-context behavioral advertising.

04 / Service providers

Infrastructure with separated responsibilities.

Shopify

Provides app installation, merchant and customer authentication, products, checkout, orders, subscriptions, webhooks, and customer-account surfaces.

Laravel Forge and the hosting provider

Administer the Laravel application, PostgreSQL database, Redis/Horizon queues, scheduler, encrypted environment configuration, backups, and application logs.

Amazon Web Services

Provides private object storage, protected CloudFront delivery, media processing, event queues, logs, alarms, and cost monitoring for uploaded content.

Kenney Labs MainSite

Receives signed, bounded operational rollups using pseudonymous tenant references; it does not receive customer names, emails, order bodies, file contents, or download URLs.

05 / Retention and deletion

Retain what the service and audit trail require.

  • Installation credentials are removed when the app is uninstalled. A lifecycle barrier prevents older queued events from restoring access.
  • Customer and shop redaction requests remove the related tenant records according to Shopify's privacy lifecycle requirements, subject to narrowly applicable legal obligations.
  • Expired upload intents, signed-download events, transient queue payloads, and operational logs are pruned on documented schedules. Download links themselves are short-lived and are not reusable account credentials.
  • Published content revisions, entitlement evidence, credit ledger entries, and commerce mappings remain while the merchant uses CourseKeep and as reasonably needed to deliver access, resolve disputes, prevent fraud, and meet legal obligations.
  • Deleted files move through a quarantine and deletion workflow; backup copies age out on the configured backup-retention schedule.

06 / Choices and contact

Requests begin with the merchant or Kenney Labs.

Customers should normally contact the Shopify merchant from whom they purchased content because that merchant controls the offering and can identify the relevant account. Merchants can uninstall CourseKeep and can request export, correction, or deletion assistance.

For a privacy question, email hello@kenneylabs.com. Include the merchant's .myshopify.com domain, but do not send passwords, payment details, or private download links.

Kenney Labs
PrivacyTerms
Back to top ↑