Kenney Labs Seen In Use / Privacy Back to product ↗

Merchant disclosure / App data

Seen In Use privacy notice

This notice explains how Seen In Use processes connected social-feed data and the optional paid-order attribution data that a Shopify merchant authorizes when approving read_orders access.

Effective and last updated August 1, 2026

Purpose Consent Social feeds Data processed Retention & deletion Service providers Merchant choices

01 / Purpose

Association, not proof of causation.

Seen In Use helps a merchant understand whether a paid order was associated with a recent shopper interaction with an inspiration attached to a product. The app applies deterministic last-touch attribution: at most one inspiration receives credit, and only when its product is present in the paid order.

The report is an analytics indicator. It does not claim that the inspiration caused the purchase, calculate conversion lift, or adjust the paid total for later refunds.

02 / Customer Privacy consent

Collection is consent-qualified.

Before recording storefront analytics or writing an attribution token to the cart, Seen In Use checks Shopify's Customer Privacy API. Processing proceeds only when Shopify reports that both analytics processing and marketing/attribution processing are allowed for the visitor under the merchant's settings, the visitor's region, and the visitor's consent choices.

If the Customer Privacy API is unavailable, still loading, or either permission is false, Seen In Use sends no analytics event and writes no attribution token.

03 / Connected social feeds

Bounded provider data, served first-party.

When a merchant connects Instagram, Facebook, or TikTok, Seen In Use receives the account or Page identity, the permissions the merchant grants, encrypted access or refresh credentials, and a bounded list of recent public posts. For those posts, Seen In Use stores provider post identifiers, public links, captions, publication dates, media types, synchronization health, and sanitized first-party preview images. Credentials and temporary provider media URLs are never sent to the merchant's storefront.

Seen In Use uses this data only to synchronize and display the merchant-selected feed, maintain security and service health, and provide aggregate feed engagement analytics where Shopify's customer-privacy controls permit analytics processing. Provider credentials are encrypted at rest. A disconnect, app uninstall, or privacy erasure removes credentials, synchronized posts, previews, and publication objects. If Pro ends, connected credentials are retained for up to 30 days solely to permit restoration after an upgrade; the feeds are hidden during that period and the connection is then revoked and erased.

The social provider remains responsible for its platform and official embed. A shopper contacts a provider only after deliberately opening a post or following the original-post link. First-party preview and manifest delivery is served through Seen In Use's storage and CDN providers.

04 / Paid-order data processed

Only the fields needed for the report.

Hashed order identifier

Shopify's order identifier is transformed with SHA-256 before durable storage. The raw order identifier is not retained.

Paid time

The time Shopify reports the order as paid is retained to place the association in the merchant's reporting range.

Total and currency

The current total and ISO currency from Shopify shop_money are retained for shop-currency reporting.

Transient product identifiers

A bounded list of Shopify product identifiers is used only to confirm that the touched product is in the paid order. The list is discarded immediately after webhook processing.

Hashed attribution data

A random attribution token and session identifier are SHA-256 hashed. They connect a consent-qualified inspiration open to a qualifying paid order.

Data not retained

Seen In Use does not retain the customer name, email, phone number, shipping or billing address, IP address, user agent, or raw paid-order webhook body for attribution.

05 / Retention and deletion

A 366-day maximum for assisted orders.

  • An attribution touch can match for no more than 30 minutes and never past midnight UTC. Expired touches not associated with a paid order are deleted by the daily retention task.
  • An assisted-order record and its linked hashed touch are deleted 366 days after the recorded paid time.
  • Product identifiers and other projected paid-webhook facts are discarded immediately after the delivery is processed.
  • App uninstall and Shopify shop-redaction workflows purge the merchant's attribution data sooner. Those lifecycle deletion rules remain in addition to the age-based retention rule.

06 / Service providers

Processors supporting Seen In Use.

The current production architecture uses the following providers. Not every provider receives every category of data.

Shopify

Provides Customer Privacy decisions, the private cart attribute, merchant authorization, and the paid-order webhook.

DigitalOcean and Laravel Forge

Provide and administer the application, database, queue, and backup infrastructure that processes the bounded record.

Amazon Web Services

Provides app media delivery and bounded operational monitoring infrastructure. Raw paid-order webhook bodies are not stored in app media systems.

Paid-order attribution data is not sent to Instagram, Facebook, TikTok, YouTube, or other social-media providers by this reporting feature.

07 / Merchant choices and contact

The feature is optional.

A merchant can decline the optional read_orders request and continue using Seen In Use without assisted-order reporting. Removing access prevents new paid-order attribution. Uninstalling the app initiates the existing tenant deletion workflow.

To ask a privacy question or request earlier deletion of Seen In Use data, email hello@kenneylabs.com. The data deletion instructions explain the available request paths.

Kenney Labs
Privacy Terms Data deletion
Back to top ↑