KittenCuddlesSilly Name, Serious Security

KittenCuddles

Privacy policy

This policy explains how Ophanim Ltd handles information when a merchant installs or uses KittenCuddles.

Last updated: 23 August 2026

Effective date: 23 August 2026

Who we are

KittenCuddles is operated by Ophanim Ltd in New Zealand. Privacy questions and requests can be sent to privacy@kittencuddles.app.

Information we process

  • Store and installation details supplied by Shopify, including the permanent store domain, store name, timezone, plan capability, app subscription status, and authorization sessions.
  • Security observations derived from supported product, variant, inventory, discount, and theme activity.
  • Published-theme file metadata, checksums, filenames, and minimized indicators of scripts, forms, remote resources, or suspicious code. Theme file contents are inspected for detection and are not retained as a general copy of the theme.
  • On eligible Shopify Plus stores that enable the feature, minimized Admin API audit signals such as actor identifiers, operation classes, and keyed fingerprints of network addresses and user agents. Audit query text, variables, raw network addresses, and complete user-agent strings are not retained.
  • Incident records, alert-delivery status, support correspondence, and an alert email address chosen by the merchant.

KittenCuddles does not request Shopify customer or order scopes and is not designed to collect customer payment information.

Why we use information

We use this information to authenticate the store, operate the service, learn normal store activity, detect security-relevant deviations, deliver alerts, administer subscriptions, provide support, prevent abuse, and meet legal obligations. We process it to perform our contract with the merchant and for our legitimate interests in operating and securing the service.

Service providers and transfers

Shopify provides the commerce platform, installation, and billing. Cloudflare provides application hosting, database, queue, logging, and transactional email infrastructure. Support correspondence is stored in a private Cloudflare-hosted inbox and may be processed by Cloudflare Workers AI to prepare draft replies for human review. Drafts are not sent automatically. Google Cloud Pub/Sub transports the optional Shopify Plus audit feed. These providers may process data in multiple countries under their own security and data-protection terms. We do not sell personal information or use app data for advertising.

Retention and deletion

Operational data is retained while the app is installed and as needed to provide the service. Uninstalling immediately removes active Shopify sessions and disables billing in KittenCuddles. When Shopify sends its mandatory shop-redaction webhook, the store record and associated observations, findings, incidents, alert settings, baselines, and audit profiles are deleted. A minimized receipt may remain to demonstrate that a privacy request was completed, and limited records may be kept where legally required. Support correspondence and attachments are retained only as long as reasonably needed to answer the request, maintain a support history, resolve disputes, or meet legal obligations. You may ask us to delete support correspondence, subject to those obligations.

Security

We use read-only Shopify permissions, encrypted transport, tenant-bound records, authenticated webhook and Pub/Sub delivery, minimized payloads, and restricted production credentials. No online service can guarantee absolute security. Report a suspected issue to security@kittencuddles.app.

Your choices and rights

Merchants can disable optional alerts, decline the optional Plus audit permission, cancel their subscription, or uninstall the app. Depending on applicable law, individuals may request access, correction, deletion, restriction, or a copy of personal information. Contact us using the privacy address above. You may also complain to your local privacy regulator; in New Zealand this is the Office of the Privacy Commissioner.

Changes to this policy

We may update this policy when the service or legal requirements change. The current version and effective date will remain available on this page. Material changes will be communicated where appropriate.