Privacy

Privacy policy

Effective May 3, 2026

Landed Cost Radar (“the App”) is operated by TradeHawk HQ LLC (“we”, “us”). The App is a Shopify embedded application that helps merchants compute and monitor product margin after supplier cost, freight, duties, and other fees. This policy explains what we collect, why we collect it, how we store it, and the choices you have.

1. Data we read from Shopify

When a merchant installs the App, we request the minimum scopes necessary to do the math:

  • read_products — product titles, handles, status, and product/variant identifiers
  • read_inventory — inventory quantity per variant and the unit cost field on inventory items, when set

We do not request, collect, or read order data, customer data, customer contact information, draft orders, fulfillment data, payment methods, billing addresses, or any storefront analytics. The App has no read_customers or read_orders scope and no customer account or storefront extensions.

2. Cost data you enter

The App stores cost assumptions you provide: per-variant supplier cost, freight per unit, duty rate, country of origin, other fees per unit, target margin, and any imported CSVs. It also stores shop-level defaults (default freight, default duty rates per country, default margin alert threshold) and the email address you designate to receive the weekly digest.

This data is used solely to compute landed cost and gross margin for your own products and to email you the weekly digest. We do not share it with Shopify, your customers, or any third party for advertising, profiling, or resale purposes.

3. What we never do

  • We do not write your cost assumptions back to Shopify’s product or inventory records.
  • We do not modify product titles, prices, descriptions, or images.
  • We do not create, edit, cancel, or refund any order.
  • We do not contact your customers.
  • We do not provide customs, tax, or legal advice. The App is a calculator, not a filing tool.

4. Where data lives

Data is stored in a managed PostgreSQL database (Neon) hosted in the United States. Application servers are hosted on Vercel. Email delivery for the weekly digest is sent via Resend. Each of these subprocessors is named in section 7. All connections are TLS-encrypted in transit. At rest, data is encrypted by the respective provider using AES-256.

5. Retention and deletion

When you uninstall the App, we receive a webhook from Shopify and within 48 hours your access tokens and session records are deleted. Cost data and Shop records are retained in a soft-deleted state for 30 days in case you reinstall, then permanently purged. You may request immediate hard-deletion at any time by emailing support@tradehawkhq.com.

We comply with Shopify’s mandatory privacy webhooks: customers/data_request, customers/redact, and shop/redact. The first two will produce empty responses because the App does not collect customer data; the third hard-deletes all shop records.

6. Your rights

You have the right to access, correct, export, or delete the data the App holds about your shop. Most of this is directly visible and editable in the App itself. For requests we cannot fulfill in-product (such as full export or hard-delete on demand), email support@tradehawkhq.com and we will respond within 14 days.

If you are an EU/UK resident, you have additional rights under the GDPR/UK-GDPR (right to object, right to data portability, right to lodge a complaint with a supervisory authority). If you are a California resident, you have rights under the CCPA. The contact above applies for all such requests.

7. Subprocessors

  • Vercel (USA) — application hosting and serverless function execution
  • Neon (USA) — managed PostgreSQL database
  • Resend (USA) — transactional email delivery for the weekly digest
  • Shopify (Canada/USA) — the platform whose API we read from

We will update this list before adding new subprocessors that materially process merchant or cost data.

8. Cookies and tracking

The embedded App sets two short-lived HTTP-only cookies for OAuth state and dashboard session integrity. These are functional cookies, not analytics or advertising cookies. The App does not embed third-party tracking scripts and does not use Google Analytics, Meta Pixel, or similar tools inside the merchant-facing surfaces.

9. Changes to this policy

We will note the effective date at the top of this page when we materially change this policy. If a change affects how we process merchant data, we will email the digest recipient on file at least 14 days before the change takes effect.

10. Contact

Email support@tradehawkhq.com for questions, deletion requests, or anything privacy-related.