Privacy Policy
This policy covers www.pippen.com, the Pippen web application, and the Pippen Shopify app. It is written to be read, not to be survived.
The short version
Pippen connects to systems you already use and reads them so it can answer questions about your operation. It starts with read-only access, and writes to a system only when you grant that access and a person approves. It does not sell your data, does not use it to advertise to you or anyone else, and does not use your commerce data to train models for other customers. When you disconnect a system or uninstall the app, we stop reading it; what we hold is deleted as described under how long we keep it.
Who we are
Pippen is operated by Pipe17, Inc.. In this policy, “Pippen”, “we” and “us” mean that company. It provides a commerce-operations agent for brands and commerce providers. For questions about this policy, or to make a request about your data, write to support@pippen.com. We answer data requests from a person, not a queue.
Account data we collect
To run an account, we collect and store:
- Your name and email address, from Shopify at install or from you at signup.
- Your workspace name, and which other people you have invited into it.
- Authentication records — a session identifier, and an identity-provider user id if you sign in with Google, Microsoft, or a password.
- Billing records: plan, subscription status, credit balance and usage. Card details are held by our payment processor or by Shopify, never by us.
- Ordinary service logs: request timestamps, IP address, browser and error traces, kept for security and debugging.
Shopify data we access
When you install the Shopify app or connect a store, Pippen is granted read-only scopes and reads the following from your store, on an ongoing basis, so answers reflect the current state of the business:
- Orders and line items, including historical orders beyond the default 60-day window.
- Products, variants, prices and publication status.
- Inventory levels, per variant and per location.
- Locations and their fulfillment roles.
- Fulfillments and tracking events.
- Returns and their reasons.
- Customer records attached to orders — name, email, and the order history that joins to them.
- Shipping methods and rates.
The Shopify app holds no write scopes. It cannot change a product, an order, an inventory level, a price, or a customer record, and it cannot message your customers. Where you connect other systems — Pipe17, an ERP, an accounting tool, a help desk, a warehouse or a documentation site — credentials are stored encrypted and used only inside your workspace; any change Pippen prepares for one of them is applied only after a person in your workspace approves it.
How we use it
We use the data described above only to:
- Run the initial census and keep your workspace's picture of the operation current.
- Answer the questions you and your team ask, and show the records behind each answer.
- Watch for changes you asked to be told about, and run the weekly review.
- Remember facts and decisions your team tells the agent, scoped to your workspace.
- Operate, secure, support and bill the service.
Answering a question involves sending the relevant records to an AI model provider acting on our behalf under contract. Your commerce data is not used to train general models, and it is never used to answer another customer's question.
How long we keep it
Commerce data is kept while your workspace is active, because the product's value is continuity — a review is only useful next to last quarter's. If you disconnect a system, we stop syncing it and delete the data derived from it within 30 days.
If you uninstall the Shopify app, access ends immediately: the store connection is disconnected and syncing stops. Your history is kept, so a reinstall picks up where you left off. Shopify then sends a mandatory shop/redact request, and on receiving it we delete that shop's commerce data and stored credentials. A customers/redact request deletes the records for the named customer. A customers/data_request is answered with what we hold for that customer. Backups age out on their own schedule, within 90 days.
Your rights
Depending on where you live, you may have the right to access, correct, export or delete personal data we hold about you, and to object to or restrict some processing. Write to support@pippen.com and we will act on it. Where we process store data on a merchant's behalf, we act on the merchant's instructions and will refer an end-customer request to them.
Security
Credentials are encrypted at rest and are never shown back to you or to us in plain text. Data is isolated per workspace at the database level, so one workspace's query cannot read another's rows. Access to production is limited and logged. No system is perfect; if we ever have a breach affecting your data, we will tell you promptly and plainly.
Children
Pippen is a business tool and is not directed to anyone under 16. We do not knowingly collect personal information from children.
Changes to this policy
If this policy changes materially, we will update the date at the top and notify workspace owners by email before the change takes effect. Continuing to use Pippen after that means the new version applies.