VERITAS / PRIVACY

Privacy, in plain words.

How Veritas handles information in the Shopify app, review widgets, review-request emails, and this website.

Effective September 8, 2026

Complete before publishing. Add the legal operating entity and business mailing address below, and confirm that reviews@useveritas.app is monitored.

Publisher and contact

Veritas is operated by:

[Insert the legal name of the operating entity]
[Insert the business mailing address]
Privacy contact: reviews@useveritas.app

Roles and scope

Veritas provides tools to Shopify merchants. For information a merchant asks us to process for its store—such as reviews, questions, order details, and email addresses—the merchant generally decides why the information is used and is responsible for its own customer-facing privacy notice and lawful instructions. Veritas processes it to provide the service, keep it secure, and follow the merchant’s settings. Veritas also handles limited information to operate the app, prevent abuse, provide support, and meet legal obligations. Shopify operates its platform under its own terms and privacy policy.

Information we handle

Merchant, store, and staff information

  • Shopify shop domain and identifiers, shop name, URL, logo, contact email, business address, country, locales, themes, and language settings.
  • Product catalog details such as product IDs, titles, handles, images, status, vendor, product type, tags, SKUs, and gift-card status.
  • App settings, widget and email-template settings, review-request schedules and limits, moderation choices, coupon settings, notification preferences, and social-post templates.
  • Shopify staff identifiers available through the merchant session, such as Shopify user ID, name, initials, and email address, when used for staff activity.
  • Shopify session information and access tokens needed to call the Shopify APIs, with access controls and use limited to the connected shop.
  • If connected, Facebook, Instagram, or X account identifiers, handles, scopes, expiry information, connection status, and encrypted OAuth tokens.

Reviewer and shopper information

  • Name, email address, rating, review title and text, product, country, language, usage duration, custom answers, and optional photos or videos.
  • Shopify customer ID, order ID, product or line-item identifiers, and purchase-verification evidence used to associate a review with a purchase or review request.
  • Merchant replies, internal notes, tags, moderation status, reports, helpful or unhelpful votes, edit history, translations, and related review activity.
  • Questions and answers, including the supplied name and email address, text, and helpful or unhelpful votes.
  • Review-request records, one-time invite tokens, request status, expiry and completion times, reminder status, and coupon or discount details.
  • Email suppression or unsubscribe status for the store.

The merchant decides whether content is approved and shown on its storefront. Published review text, ratings, display names, media, questions, answers, and merchant replies may be visible to other shoppers. Veritas does not intentionally display a shopper’s email address, access token, invite token, or Shopify customer ID in a storefront widget.

Shopify data used for store features

With the merchant’s permissions, Veritas can receive order and fulfillment events, customer identifiers and contact details, order IDs, line items, product IDs, titles, variants, and prices. We use this to schedule review requests, verify purchases, send configured follow-ups, and keep the catalog current. Veritas does not ask shoppers to provide payment-card numbers to Veritas; Shopify handles Shopify checkout and payment processing.

Technical and operational information

We store review and email-request event history, request metadata such as user-agent and referrer when an email is opened or clicked, import-job status, audit and edit history, moderation reports, staff activity, derived search indexes, and error or security logs. These records can contain shop, order, customer, review, or request identifiers.

Review-request emails can include a one-pixel open signal and redirect links. When requested, Veritas records the related request ID and may record user-agent and referrer. This supports delivery and engagement reporting and is not used for advertising.

The current Veritas marketing website has no advertising trackers, third-party analytics scripts, forms, or non-essential cookies. Its hosting provider may process ordinary technical request logs needed to serve the site.

How we use information

  1. Install, authenticate, configure, and operate Veritas for a Shopify shop.
  2. Collect, import, moderate, translate, index, search, publish, edit, and display reviews, media, questions, answers, and merchant replies.
  3. Match review requests with products, orders, and purchase signals and mark reviews as verified where the merchant’s rules allow.
  4. Send configured review-request, reminder, thank-you, reply-notification, question or answer notification, and reward emails.
  5. Honor unsubscribe choices, prevent abuse and spam, investigate reports, and protect the app, merchants, shoppers, and the public.
  6. Generate optional translations, “customers say” summaries, and merchant reply drafts. The relevant content is sent to the configured AI provider for that operation.
  7. Publish review content to a connected Facebook Page, Instagram account, or X account when the merchant asks Veritas to post.
  8. Run imports, background jobs, synchronizations, search indexing, backups, support, debugging, and service improvements.
  9. Comply with law, valid requests, Shopify requirements, and the exercise or defense of legal claims.

When we share information

We share information only as needed to provide the service, follow the merchant’s instructions, or meet legal obligations. Current providers and integrations include:

  • Shopify, for app installation, API access, store data, orders, products, themes, customers, discounts, and storefront delivery.
  • PostgreSQL and Google Cloud hosting, for the app database, sessions, runtime, and backups.
  • Resend, for transactional email delivery.
  • Cloudinary, for uploaded review photos and videos and their delivery or transformation.
  • Elasticsearch, for derived search indexes of reviews, questions, products, and related content.
  • Inngest, for background jobs such as order handling, imports, translations, synchronization, and email workflows.
  • OpenAI or xAI, only when an AI translation, summary, or reply-generation feature is used or enabled.
  • Meta and X, only when a merchant connects those services and asks Veritas to publish.
  • Vercel, for the public Veritas marketing website.

We may also disclose information to advisers, purchasers or successors in a business transfer, authorities, or other parties when reasonably necessary for security, fraud prevention, legal compliance, or protection of rights. The current implementation does not sell personal information or use customer information for cross-context behavioral advertising.

International processing

Veritas and its providers may process information in countries other than the country where a merchant or shopper lives. Where required, we use appropriate contractual or other legal safeguards for international transfers. Provider-specific transfers are also governed by each provider’s terms and privacy notice.

Retention and deletion

We retain information for as long as it is needed to provide the app, keep a merchant’s review history and settings available, honor suppression choices, resolve disputes, maintain security, meet legal obligations, and maintain reliable backups and derived indexes. Review-request tokens and similar links have expiry values; event and audit records can remain after a link expires so the merchant can understand what happened.

There is not currently a single fixed retention period for every data type. We delete or anonymize information when the merchant directs us to do so, when a valid data-rights request requires it, or when it is no longer needed, subject to legal, security, dispute, backup, and technical constraints. Derived indexes, logs, and backups may persist temporarily while they are rotated or rebuilt.

When Shopify sends a required customer-data, customer-redaction, or shop-redaction request, Veritas authenticates and processes it and applies the deletion or anonymization steps supported by the current data records. A merchant can also remove the app and contact us about additional deletion needs.

Choices and rights

  • Review-request, reminder, thank-you, reply-notification, and reward emails include an unsubscribe path where applicable. It adds the address to that store’s suppression list; it does not remove a review already published by the store.
  • A shopper can ask the merchant that collected the information to access, correct, publish, unpublish, or delete a review, question, answer, photo, or video.
  • Depending on location, a shopper may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent where processing relies on consent. Contact the merchant first for store-specific requests, or contact Veritas.
  • To help us find records, include the store domain, email address used, relevant product or order, and the request. We may verify identity before completing it.

We do not use an unsubscribe request to prevent a shopper from submitting a review through an order confirmation or by contacting the store directly.

Security

We use safeguards appropriate to the information we handle, including HTTPS, authenticated Shopify webhooks, scoped Shopify access, access controls, encrypted social OAuth credentials, tokenized links, and monitoring of errors and abuse. No service or transmission is completely secure, so we cannot promise absolute security.

Children

Veritas is intended for merchants and their shoppers and is not directed to children. We do not knowingly request personal information from children. If you believe a child provided information to Veritas, contact us so we can review and remove it where appropriate.

Changes and contact

We may update this policy as the app, providers, or legal requirements change. We will update the effective date and publish the revised policy at this URL. Questions or privacy requests can be sent to reviews@useveritas.app. Include the Shopify store domain and enough context for us to identify the relevant records.