SpecFinch
Privacy policy
Last updated: August 25, 2026
Who operates SpecFinch
SpecFinch is operated by Chris Online. Privacy questions can be sent to info@chrisonline.nl.
Data processed
SpecFinch is a read-only Shopify catalog-monitoring app. It processes the store domain and installation metadata; an encrypted offline access token; merchant-configured contracts, rules, timezone, and optional digest address; and product, variant, collection-membership, and selected metafield data read from Shopify under the read_products scope while scans run.
SpecFinch stores normalized observations such as whether a field is present or empty, its length and type, salted fingerprints, compact issue context, scan metadata, issue status, digest status, and limited security and operational logs. It does not request Shopify orders, customer records, payment details, theme files, or protected customer data. Access tokens, complete product descriptions, complete metafield values, and full webhook or API payloads are not written to application logs.
Purposes
Data is used to authenticate the installed store, evaluate merchant-configured catalog rules, maintain a baseline, identify changed findings, provide CSV exports and Shopify Admin links, send enabled operational digests, secure the service, and diagnose failures.
Storage and service providers
SpecFinch uses Shopify for commerce-platform access and authentication, Render for application hosting and PostgreSQL storage, Resend for enabled operational email delivery, and Better Stack for uptime and heartbeat monitoring. Data is shared only with providers needed to operate SpecFinch, with Shopify as directed by the merchant, or where legally required.
Retention and deletion
Issue observations are designed for 90-day retention and scan metadata for 180-day retention. Provider logs follow the configured provider retention. Uninstalling deactivates the store and stops scheduled work. A valid Shopify shop/redact request removes the shop's stored tenant data, including sessions and catalog-monitoring records.
Merchant choices
Merchants can disable operational digests, uninstall the app, and contact info@chrisonline.nlabout applicable data requests. SpecFinch supports Shopify's mandatory privacy webhooks.
Security
SpecFinch uses HTTPS, encrypted session-token storage, tenant-scoped database access, signed webhook checks, bounded retries, and secret storage in the hosting platform. No system can guarantee absolute security. Suspected incidents should be reported to info@chrisonline.nl.
Changes
Material changes will be reflected by an updated date and, where required, an in-app or direct notice.