Settled
Features How it works Pricing FAQ
Install on Shopify

Privacy Policy

Last updated: October 1, 2026

Settled is a read-only Shopify app that explains your Shopify Payments payouts visually and exports accounting-ready summaries. This policy explains what data Settled accesses, what it stores, and the choices you have.

The short version: from Shopify, Settled stores order numbers only — never your customers' names, emails, phone numbers or addresses. It never sells or shares your data for marketing, and it never moves money or changes your store. This marketing website itself collects nothing — no analytics, no cookies, no forms; it just serves static pages.

1. Who this policy is for

This policy applies to Shopify merchants who install the Settled app on their store, and to visitors of this website. "Settled", "we" and "our" refer to the makers of the Settled app.

2. This website vs. the app

This site (settled marketing pages) is a static set of HTML/CSS pages with no analytics, no tracking cookies, and no forms — it does not collect anything about you. The rest of this policy describes the Settled app, which you install separately from your Shopify admin and which does access Shopify data as described below.

3. What data Settled accesses

With your permission (granted when you install the app), Settled reads the following from Shopify through its official APIs. Access is read-only — Settled requests no write permissions.

  • Order data (via the read_orders scope) — used to match each payout line back to the order it came from.
  • Shopify Payments data (via the read_shopify_payments_accounts scope) — your payouts, balance transactions and disputes.
  • Shop information — your store domain, name, timezone and currency, so figures are shown correctly for your store.

Separately, you may choose to upload CSV exports from PayPal or Stripe so Settled can reconcile them against your Shopify payouts. Settled never connects to PayPal, Stripe or your bank directly — those files come only from you, uploaded by hand.

4. What Settled stores

Settled is designed to hold as little of your data as possible. From your Shopify orders, it stores the order number only.

  • We never store customer names, email addresses, phone numbers or shipping/billing addresses from Shopify.
  • We store payout and fee totals, dispute status, your app settings, and an encrypted access token used to talk to Shopify on your behalf.
  • From an uploaded PayPal or Stripe CSV, the raw transaction rows are kept for up to 90 days so you can review matches; those raw rows can include the payer's email address as it appears in the file. The buyer's name is discarded during import and is never stored.

This keeps Settled within Shopify's Protected Customer Data — Level 1, the lowest data-handling tier, because no customer personal information from Shopify is retained.

5. How Settled uses your data

Your data is used for one purpose: to run the app for you. Specifically, to

  • show your payouts, fees, refunds, reserves and disputes visually;
  • reconcile your Shopify payouts against the CSV files you upload; and
  • generate the accounting exports you request.

Settled does not:

  • sell, rent or share your data with third parties for their own use;
  • use your data for advertising or marketing; or
  • perform profiling or any automated decision-making that produces legal or similarly significant effects.

6. Optional AI features (your own key)

Settled offers optional AI-assisted explanations that run on your own API key from a provider you choose (Anthropic, OpenAI, Google Gemini or OpenRouter). If you never add a key, these features stay off and no data leaves Settled for any AI provider.

If you do add a key and use an AI feature, the payout figures needed for that answer are sent to your chosen provider, under your own agreement with them. The app names the provider before the first call, AI suggestions always wait for your approval, and your key is stored encrypted (AES-256-GCM) — Settled never uses its own keys on your data.

7. Notifications you opt into

  • Email digests and alerts are sent through Resend to the address you configure.
  • Discord alerts are sent only if you paste your own Discord channel webhook into Settings. The webhook URL is a secret, so it is stored encrypted (AES-256-GCM) and used only to post your alerts.

Separately, the app's own operational error logs (PII-scrubbed, no merchant or customer data) may be mirrored to the operator's private Discord channel so failures get fixed quickly.

8. Retention & deletion

  • Raw rows from uploaded CSV files are purged automatically after 90 days.
  • Application logs are kept for 30 days, then deleted.
  • Everything else is kept only while you use the app, and is deleted when you uninstall or when we receive a Shopify GDPR webhook — customers/redact (redact customer references) or shop/redact (delete all shop data, sent about 48 hours after uninstall).

You can also export everything Settled stores, or request deletion at any time, from the app's Settings → Data & privacy screen.

9. How your data is protected

  • All traffic is encrypted in transit over HTTPS / TLS.
  • Your Shopify access token, AI keys and webhook URLs are encrypted at rest (AES-256-GCM); they are never stored in plain text.
  • The app and its PostgreSQL database run on a dedicated Hetzner VPS (EU). The database accepts connections from the app server only — it is not reachable from the public internet.
  • Secrets and API keys live only in server environment variables — never in our source code or this website.

10. Sub-processors

Settled relies on a small set of trusted service providers to operate. Each processes data only to provide its service.

Provider What it does
Shopify The platform Settled runs on, and the source of your payout & order data.
Hetzner Hosts the Settled app and its PostgreSQL database on a dedicated VPS (EU).
Resend Sends transactional email you opt into, such as digest and hold-alert emails.
Inngest Runs the background jobs that fetch your latest payouts from Shopify.
Your AI provider (Anthropic, OpenAI, Google Gemini or OpenRouter) Receives the payout figures behind an AI answer — only if you add your own API key and use the AI features.
Discord Delivers your alerts to your own channel — only if you paste your own webhook URL. Also receives the operator's PII-scrubbed error mirror.

11. Your rights

Depending on where you live, you may have rights under the GDPR (EU/UK) or CCPA/CPRA (California) and similar laws, including the right to:

  • access the data we hold about your store;
  • correct or delete that data;
  • export it in a portable format; and
  • object to or restrict certain processing.

Because Settled stores order numbers only and no customer personal information from Shopify, most requests can be satisfied instantly by uninstalling or using the in-app delete tool. For anything else, contact us using the details below.

12. Children

Settled is a business tool for Shopify merchants and is not directed to children. We do not knowingly collect data from anyone under 16.

13. Changes to this policy

We may update this policy as the app evolves. Material changes will be reflected here with a new "Last updated" date.

14. Contact

Questions about this policy or your data? Email us at brandonta1035@gmail.com.

Settled is a data formatting & visualization tool — not tax or financial advice. The figures it shows and exports are for your reference; you are responsible for the numbers you report and should verify them against your Shopify and bank records before filing.
Settled

Payout dates, hold explanations, and reconciliation for Shopify Payments merchants.

Product

  • Features
  • Pricing
  • Sample payout
  • FAQ

Resources

  • Payout timing guide
  • Reserve & hold glossary
  • Reconciliation checklist
  • Help center

Company

  • About
  • Contact
  • Privacy
  • Terms
© 2026 Settled. All rights reserved. Built for Shopify merchants · Not affiliated with Shopify Inc.