Kept by The Prompted

Privacy Policy

Effective 2026-07-30

1. What this covers

Kept is a Shopify app that shows a store what it actually kept: contribution margin, the costs behind it, and how this period compares with the last one. Kept is built and operated by The Prompted ("we", "us", "our").

This policy covers the Kept app inside your Shopify admin, the Kept API, and the pages on kept.theprompted.co. It does not cover Shopify itself, or any advertising platform or fulfilment provider you connect to Kept. Each of those has its own policy and its own relationship with you.

Two commitments up front, because they are the whole shape of this document. We use your store's data only to produce your own numbers, for you. And we delete it when you leave.

2. What we read from your Shopify store

Every permission Kept asks for is read-only. Kept never writes to your store. It does not create, edit or cancel orders, does not touch products or inventory, and does not contact your customers.

Required, because the product cannot work without them:

Optional. Kept works without each of these, and says in the app which number got less precise as a result:

Kept requests Level 1 protected customer data from Shopify. It does not request Level 2.

3. What we receive from ad accounts you connect

If you connect Meta, Google Ads or TikTok, we read spend, read-only, at account and campaign level, day by day, along with the account name, account id and currency. Purpose: putting ad spend into the margin calculation, and computing marketing efficiency ratio and cost per acquisition.

We do not read creatives, audiences, customer lists or conversion level data. We never create, edit, pause, or spend against a campaign. You can disconnect a platform at any time in Settings, which stops the sync and deletes the stored credential. You can also skip the connection entirely and type a spend total in by hand.

4. What we receive from fulfilment providers you connect

If you connect a print on demand or fulfilment provider, for example Printful or Printify, we read the charges on your own orders in your own account there. Purpose: a real supplier cost per order instead of an estimated one. Read-only, like everything else.

5. What you enter yourself

Cost tables and their size and colour tiers, per SKU cost overrides, product mappings, bundle components, shipping and fee rules, assumption defaults, your settings, and any discount code you apply to your subscription.

This is your work, and it is the one thing in the account that exists nowhere else in the world. We hold it in a separate system of record from your order data, so that a failure on our side means a re-sync from Shopify rather than asking you to type it all again.

6. Access tokens and credentials

Your Shopify access token and any ad platform or provider credentials are encrypted before they are written to storage, using AES-GCM with keys held outside the database. They are used only to sync your own data on your behalf. Shopify tokens are short-lived and refreshed automatically.

7. What we never do

8. Where your data lives and how it is protected

9. How long we keep it

10. Getting your data out

Email support@theprompted.co from an address associated with the store and we will send you a machine-readable export of everything we hold for that store, as a portable database file or as CSV and JSON, whichever you prefer. Within 30 days, usually within one business day, and at no charge. This applies whether or not you are still a subscriber, up to the deletion window in section 9.

11. Subprocessors

Advertising platforms and fulfilment providers are not our subprocessors. They are sources you connect, under your own agreement with them, and we read from them on your instruction.

We will keep this list current in this document. If we add a subprocessor that handles store data, it will appear here before it handles anything.

12. Security incidents

If we become aware of a breach affecting your data, we will tell you without undue delay, tell you plainly what we know and what we are doing about it, and notify Shopify within 24 hours of becoming aware where Shopify data is involved. We would rather send you an early notice that turns out to be minor than a complete one that arrives late.

13. Roles, and your rights

Roles. For your store's data, including any personal data of your customers, you are the controller (the "business" under California law) and we are the processor (the "service provider"). We process it only on your instruction and only for the purposes described above. This policy, together with our terms of service, sets out those processing terms.

For our own records, such as the email address that contacts us, your subscription state and our support correspondence with you, we are the controller.

Shopper requests. If one of your customers asks to access or delete their data, that request belongs to you, not to us. Send it on and we will help you answer it within 30 days. Shopify's own customers/data_request signal reaches us the same way and we answer it to you.

Your rights. You can ask us for access to, correction of, export of, or deletion of the data we hold, using the contact address below. If you are in the UK, EU or EEA you may also complain to your supervisory authority. If you are in California you have the right to know, delete, and correct, and we do not sell or share personal information as those terms are defined there.

Data minimisation. We ask for the narrowest permission that answers the question. That is why the customer permission is optional, why we take no shopper contact details, and why we do not request Level 2 protected customer data.

14. Cookies

Inside Shopify admin, Kept uses only what is required to hold your session. The pages on kept.theprompted.co set no advertising or cross-site tracking cookies.

15. Shopify's terms take precedence

Where anything in this policy would be less protective of you than Shopify's API License and Terms of Use, its Protected Customer Data requirements, or its Data Processing Addendum, those terms apply instead of this one.

16. Changes

This policy is dated at the top. If we change anything material, we will say so in the app before the change takes effect, and update the date here.

17. Contact

Questions, export requests, deletion requests, and anything about this policy:

support@theprompted.co

The Prompted, Toronto, Ontario, Canada

We answer within one business day.