Kitwise

Privacy

Kitwise · last updated 6 September 2026

What Kitwise stores

Kitwise stores the offers you create — their type, products, quantity tiers, target prices and bilingual copy — along with your shop domain, plan, currency and the guardrail settings on the Settings page. It also stores the Shopify session token needed to call the Admin API on your behalf.

What Kitwise reads from your shop

The app requests these scopes and uses each one for a single purpose:

  • read_products and read_inventory — product titles, prices, unit costs, tags, collections and stock levels, used to validate offers and enforce your stock and margin floors.
  • read_orders — order totals, used to attribute extra revenue to the offers that produced it.
  • read_discounts and write_discounts — the single automatic discount that backs every published Kitwise offer.

Kitwise does not request write access to products, customers or orders, and does not read customer personal data.

Customer data

Discounts are calculated inside a Shopify Function that runs on Shopify's infrastructure during checkout. That Function cannot make network calls, so cart contents never leave Shopify and are never sent to Kitwise servers.

Data requests and deletion

Kitwise implements Shopify's mandatory compliance webhooks: customers/data_request, customers/redact and shop/redact. Because Kitwise holds no customer records, the first two are acknowledged with an empty result. On shop/redact, and on app uninstall, every offer, setting and session belonging to that shop is deleted.

Sub-processors

Shopify (platform and billing) and the application host (Render). When in-app support chat is enabled, Kitwise also uses Tawk.to (tawk.to ltd) as a third-party support messaging provider. Session context sent to Tawk.to is limited to non-PII shop metadata (shop domain, locale, plan, theme-block and offer-publish status) — never customer personal data from checkout. Kitwise does not sell data and does not share it with advertisers.

Contact

Questions or a deletion request outside the webhook flow: privacy@kitwise.app.