Effective 2026-08-12 (previously 2026-07-30; section 10 now describes the self-serve export in the app)
Kept is a Shopify app that shows a store what it actually kept: contribution margin, the costs behind it, and how this period compares with the last one. Kept is built and operated by The Prompted ("we", "us", "our").
This policy covers the Kept app inside your Shopify admin, the Kept API, and the pages on kept.theprompted.co. It does not cover Shopify itself, or any advertising platform or fulfilment provider you connect to Kept. Each of those has its own policy and its own relationship with you.
Two commitments up front, because they are the whole shape of this document. We use your store's data only to produce your own numbers, for you. And we delete it when you leave.
Every permission Kept asks for is read-only. Kept never writes to your store. It does not create, edit or cancel orders, does not touch products or inventory, and does not contact your customers.
Required, because the product cannot work without them:
read_orders). Line items and quantities, prices, discounts, refunds, taxes, shipping charged, and payment transactions. Purpose: net sales, contribution margin, per product margin, and every daily figure the dashboard draws.read_all_orders). Shopify limits apps to the most recent 60 days of orders unless it grants this permission separately. Purpose: comparing this period with the last one, and with the same period last year. Without it, Kept can still run, but only on a two month window, and it will tell you so.read_products). Product and variant titles, SKUs and prices. Purpose: attaching a cost to the thing that actually sold.read_inventory). The unit cost you already keep in Shopify. Purpose: seeding your cost of goods so the app is useful on the first day instead of after an afternoon of data entry.Optional. Kept works without each of these, and says in the app which number got less precise as a result:
read_customers). Used for one thing: matching an order that was cancelled and recreated by an edit to its replacement, so the pair can be shown as one economic event instead of two. We use the customer identifier attached to an order. We do not use, and do not store, customer names, email addresses, phone numbers or physical addresses. See section 13.read_shopify_payments_accounts and read_shopify_payments_payouts, which Kept asks for together because neither reads a fee without the other). Purpose: your exact processing fee per transaction as it settled in your payouts, instead of an estimate from a percentage rule. Decline it and Kept falls back to the fee reported on the order's own transaction, and past that to a rule you can see and edit, flagged as an estimate.read_returns). Purpose: handling returned items as returned items rather than as an undifferentiated credit, which keeps refunds and margin honest.Kept requests Level 1 protected customer data from Shopify. It does not request Level 2.
If you connect Meta, Google Ads or TikTok, we read spend, read-only, at account and campaign level, day by day, along with the account name, account id and currency. Purpose: putting ad spend into the margin calculation, and computing marketing efficiency ratio and cost per acquisition.
We do not read creatives, audiences, customer lists or conversion level data. We never create, edit, pause, or spend against a campaign. You can disconnect a platform at any time in Settings, which stops the sync and deletes the stored credential. You can also skip the connection entirely and type a spend total in by hand.
If you connect a print on demand or fulfilment provider, for example Printful or Printify, we read the charges on your own orders in your own account there. Purpose: a real supplier cost per order instead of an estimated one. Read-only, like everything else.
Cost tables and their size and colour tiers, per SKU cost overrides, product mappings, bundle components, shipping and fee rules, assumption defaults, your settings, and any discount code you apply to your subscription.
This is your work, and it is the one thing in the account that exists nowhere else in the world. We hold it in a separate system of record from your order data, so that a failure on our side means a re-sync from Shopify rather than asking you to type it all again.
Your Shopify access token and any ad platform or provider credentials are encrypted before they are written to storage, using AES-GCM with keys held outside the database. They are used only to sync your own data on your behalf. Shopify tokens are short-lived and refreshed automatically.
If you give an AI assistant access to your numbers, the access token you create (or approve through the assistant's own secure connection) is read-only, scoped to your store alone, stored only as a hash, and revocable in Settings at any time. Kept keeps a 30 day log of what your assistant asked, visible to you in Settings, and deletes it on the same schedule as everything else. An assistant's connection record holds no store data.
shop/redact we erase everything we hold for the store, including subscription and trial records. On customers/redact we erase what we hold relating to that shopper. Either way, erasure is complete well inside the 30 day window above.Do it yourself, in the app. Open Kept, go to Settings, and press Prepare an export under Your data. Kept builds a machine-readable file holding everything we hold for that store, your orders and refunds as we stored them, the costs you set and the costs we read from Shopify, and every figure we worked out from those. It takes a few seconds, and the download appears when the file is ready. The file is a portable SQLite database, readable by any tool that speaks SQLite. There is no charge and no limit on how often you ask.
The file is a snapshot taken at the moment you press the button, not a live feed, and preparing a new one replaces the previous one, so an old copy of your figures is never left sitting on our storage.
If you would rather not do it yourself, or you want the same data as CSV and JSON, email support@theprompted.co from an address associated with the store and we will send it. Within 30 days, usually within one business day, and at no charge. Either way this applies whether or not you are still a subscriber, up to the deletion window in section 9.
Advertising platforms and fulfilment providers are not our subprocessors. They are sources you connect, under your own agreement with them, and we read from them on your instruction.
We will keep this list current in this document. If we add a subprocessor that handles store data, it will appear here before it handles anything.
If we become aware of a breach affecting your data, we will tell you without undue delay, tell you plainly what we know and what we are doing about it, and notify Shopify within 24 hours of becoming aware where Shopify data is involved. We would rather send you an early notice that turns out to be minor than a complete one that arrives late.
Roles. For your store's data, including any personal data of your customers, you are the controller (the "business" under California law) and we are the processor (the "service provider"). We process it only on your instruction and only for the purposes described above. This policy, together with our terms of service, sets out those processing terms.
For our own records, such as the email address that contacts us, your subscription state and our support correspondence with you, we are the controller.
Shopper requests. If one of your customers asks to access or delete their data, that request belongs to you, not to us. Send it on and we will help you answer it within 30 days. Shopify's own customers/data_request signal reaches us the same way and we answer it to you.
Your rights. You can export the data we hold at any time from Settings inside the app, as section 10 describes, and you can ask us for access to, correction of or deletion of it using the contact address below. If you are in the UK, EU or EEA you may also complain to your supervisory authority. If you are in California you have the right to know, delete, and correct, and we do not sell or share personal information as those terms are defined there.
Data minimisation. We ask for the narrowest permission that answers the question. That is why the customer permission is optional, why we take no shopper contact details, and why we do not request Level 2 protected customer data.
Inside Shopify admin, Kept uses only what is required to hold your session. The pages on kept.theprompted.co set no advertising or cross-site tracking cookies.
Where anything in this policy would be less protective of you than Shopify's API License and Terms of Use, its Protected Customer Data requirements, or its Data Processing Addendum, those terms apply instead of this one.
This policy is dated at the top. If we change anything material, we will say so in the app before the change takes effect, and update the date here.
Questions, export requests, deletion requests, and anything about this policy:
The Prompted, Toronto, Ontario, Canada
We answer within one business day.