Magnorus ("we", "us") provides profit and order analytics for merchants. This policy explains what data we process when you install or use the Magnorus app. It applies to https://magnorus.com and the Magnorus Shopify app.
Contact: [email protected]
Last updated: 11 September 2026
When you install Magnorus on a Shopify store, we request these Admin API scopes:
read_products — product titles, variants, prices, and inventory cost so we can calculate cost of goodsread_orders and read_all_orders — paid order totals, taxes, line items, and the customer name/email attached to an order so we can show revenue and customer mix, including orders older than 60 daysread_inventory — unit cost on inventory items used for margin calculationsWe do not request payment card data, and we do not send store data to third-party AI providers.
Order records from Shopify can include a customer name, email address, and Shopify customer ID. We use that information only to power in-app analytics for the merchant who installed the app (for example, revenue by customer). We do not sell customer data, use it for advertising, or contact customers.
If a merchant signs in on magnorus.com, we store name, email, and authentication details. Shopify installs can create an account from the shop's contact email so the app can open immediately after OAuth.
Shopify catalog and order payloads are fetched to generate reports. We may cache a report for a limited time and save reports or expenses the merchant chooses to keep. Access tokens are stored so the app can refresh analytics. We do not use customer data for our own marketing.
Magnorus implements Shopify's mandatory compliance webhooks:
customers/data_request — we log the request so we can provide stored personal data to the merchantcustomers/redact — we remove or mask that customer's personal data from saved reportsshop/redact and app/uninstalled — we delete the shop's access token and stored analytics for that storeWebhook deliveries are verified with Shopify HMAC signatures. Redaction is completed within 30 days.
We use a session cookie to keep merchants signed in. When the app is embedded in Shopify admin, we also verify Shopify session tokens issued by App Bridge.
We share data only with Shopify (to provide the app), hosting/email providers that process it on our instructions, or when required by law.
Shop credentials and analytics are kept while the app is installed. After uninstall, Shopify sends shop/redact and we delete that shop's stored data. Merchant account records on magnorus.com remain until the merchant deletes the account.
Merchants and their customers can request access or deletion through Shopify's customer privacy tools or by emailing [email protected].
We will post updates to this page and revise the date above.