Privacy Policy

Last updated: August 14, 2026

CostLedger ("the App") is operated by lcCode ("we", "us", or "our"). This policy explains how we collect, use, retain, disclose, and protect information when you install and use the App.

What data we collect

CostLedger accesses your Shopify store through the Shopify Admin API using the read_products, read_inventory, and read_orders scopes. We process:

CostLedger does not request or store customer names, customer email addresses, postal addresses, phone numbers, payment-card information, or other buyer-identifying fields.

How we use your data

Data storage and security

Your data is stored in a secured PostgreSQL database hosted on Railway's US-based infrastructure. We use encrypted HTTPS/TLS connections, secure credential storage, and HMAC verification for Shopify communications.

For an approved Shopify PO import, CostLedger stores the receipt metadata needed for duplicate prevention and audit. This may include the original filename, SHA-256 file hash, preview fingerprint, purchase-order number, supplier, reference, currency, receipt date, line counts, totals, result status, linked ledger entries, and any reversal record. CostLedger does not retain the raw PDF file.

Data retention

Raw Shopify order and line-item data is deleted on a daily schedule once it is more than 90 days old. Non-customer margin snapshots are retained for 25 months to support historical comparisons. Your cost ledger, Shopify PO receipt and reversal history, and any RestockRadar pending or recorded handoff receipts are retained while the App is installed because they form your accounting and audit record. Pending handoff rows are not auto-expired.

When you uninstall the App, all associated data — including your cost ledger, PO receipt history, snapshots, and synced store data — is automatically and permanently deleted from our systems. Export your ledger before uninstalling if you want to keep a copy.

Shopify commerce data remains unchanged

CostLedger does not change purchase orders, products, inventory, product costs, orders, checkout, or storefront data in Shopify. Manual, CSV, Shopify PO, and RestockRadar handoff imports record entries only in CostLedger. A Shopify restock or return does not reverse CostLedger cost of goods.

Data sharing

We do not sell your data. We disclose information only to service providers that help us operate CostLedger, or when required by law:

These providers receive only the information needed to deliver their services. We may also disclose information when legally required or to protect the security and rights of merchants, CostLedger, or others.

Your rights

Depending on your location, applicable privacy laws may give you rights to access, correct, delete, or obtain a portable copy of your data. You may also revoke CostLedger's access by uninstalling the App. Contact us for a copy of your store data or for immediate manual deletion.

We handle Shopify's mandatory customer-data request, customer-data erasure, and shop-data erasure webhooks. Because CostLedger stores no customer PII, customer-data requests return no customer-identifying records.

International data transfers

Your data is stored on servers in the United States. If you are located outside the United States, your data is transferred to and processed in the US.

Cookies and tracking

The App uses a temporary authorization cookie to prevent cross-site request forgery during Shopify installation. It is deleted after authorization completes. We do not use cookies for advertising or third-party analytics.

Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify merchants through the App or by email and update the date above.

Privacy contact
Email [email protected]. We respond to privacy requests within 30 days.