Privacy Policy

Draft for legal review. This page describes what the platform stores today, written from the code that runs it. It has not been reviewed by a lawyer and is not yet the published policy: contact details, retention periods and the governing law will be added before it is. Questions about an order should go to the store you bought from.

Sable runs a checkout for Shopify stores that takes card payments through the store owner's own Whop account. This policy explains what is stored, why, who it is shared with and how it is protected.

1. Who this covers

Two groups of people meet Sable. Merchants run a Shopify store and use the Sable dashboard. Shoppers buy from those stores on a checkout Sable serves. Sable is operated on behalf of the stores that use it; for a shopper, the store they bought from remains the seller of record and the first place to take any question about an order.

This policy covers the marketing site, the dashboard, the theme snippet installed on a merchant's storefront, and the checkout and receipt pages Sable serves for a store, whether on the platform address or on the store's own checkout domain.

2. Merchants: what we store

  • Store details. Store name, the myshopify.com domain, storefront origins, checkout domain, currency and timezone.
  • Connected accounts. The Shopify custom app's client id and client secret, the Admin and Storefront API tokens minted from it, the Whop company id, API key and webhook signing secret, and, when enabled, a Klaviyo private API key. Every secret is encrypted at rest with a key only the platform holds; the dashboard shows whether a secret is saved, never the secret itself.
  • Tracking settings. Google Ads customer id, conversion action id, tag id and conversion label, and the ids of any ad pixels configured for the storefront pixel.
  • Sign-in. The dashboard is protected by a password. Signing in sets a wc_session cookie (HTTP-only, valid for 7 days) that carries a signed token and nothing else.
  • Operational records. Webhook deliveries from Whop and Shopify, the jobs run for a store (Google Ads uploads, Klaviyo events, Shopify order sync) and their outcomes, kept so problems can be traced and retried.

3. Shoppers: what we store on an order

  • Contact and delivery. Email address, phone number, the marketing opt-in choice, shipping address and, when different, billing address.
  • The cart. The items, variants, quantities and prices as Shopify quoted them, the shipping method chosen, taxes, duties, discounts and totals.
  • The payment. The Whop payment id and what Whop reports about it, including the last four digits of the card. Card details are entered in Whop's embedded payment form and go to Whop directly: the full card number never reaches Sable.
  • The Shopify order. The id and order number of the order written back to Shopify, its status, and any refunds or disputes recorded against it.
  • Attribution. The advertising click ids (gclid, gbraid, wbraid, fbclid, ttclid, msclkid), UTM parameters, landing page and referrer that the theme snippet captured on the storefront, plus the browser's user agent, attached to the hand-off and the order.

Abandoned checkouts keep whatever was entered before the shopper left, so a checkout can be resumed from the link an email tool sends.

4. Cookies

  • _wc_attr on the storefront. Set by the theme snippet on the store's root domain for 90 days, mirrored in localStorage. It holds only the advertising parameters listed above; it does not identify the shopper.
  • wc_session on the dashboard. The merchant sign-in cookie described above. Nothing is set for visitors of the marketing pages.
  • Whop's embedded checkout. The payment form is served by Whop inside the checkout page and is covered by Whop's own privacy policy.

5. Where information goes

Sable moves data between the systems a merchant has connected, and nowhere else:

  • Shopify. The cart is priced by the store's Storefront API, and each paid order is written into the store as a Shopify order with its contact, address, lines, tax and shipping. Refunds and cancellations flow in both directions.
  • Whop. Takes the card payment, holds the payment record, and receives refund requests that started in Shopify.
  • Google Ads (only when the merchant switches it on). One conversion event per paid order: the click id, the order id, the value and currency, the time of payment, and the shopper's email and phone hashed with SHA-256 after normalisation. The plain values are never sent.
  • Klaviyo (only when the merchant switches it on). A Started Checkout event with the shopper's email, the cart and a link that resumes the checkout.
  • Meta, TikTok and GA4 (only when the merchant configures the storefront pixel). Storefront and checkout events for the pixel ids the merchant entered.
  • Hosting. The platform runs on Vercel, which also serves each store's checkout domain and issues its certificate, and stores its data in a managed Postgres database.

Sable does not sell data, does not build profiles across stores, and does not use a shopper's details for anything other than completing and supporting their order with the store they bought from.

6. Security

  • Every credential is encrypted at rest; Admin tokens minted from a Shopify client secret expire after 24 hours.
  • Every webhook delivery is verified before it is read: Whop deliveries against the webhook's signing secret, Shopify deliveries against the custom app's client secret.
  • The dashboard, webhooks and jobs are served only on the platform host; a store's checkout domain answers 404 for all of them.
  • All hosts are served over TLS. Checkout clicks are accepted only from the storefront origins a merchant listed.

7. How long we keep information

Orders, their webhook deliveries and jobs are kept for as long as the store is active on the platform, so refunds, disputes and reconciliation can refer back to them. A fixed retention period for closed orders and a deletion route for merchants who leave are to be set during legal review and will be stated here.

8. Your choices and rights

Shoppers should contact the store they bought from: the store holds the same order in Shopify and can ask Sable to correct or delete what it holds about it. Merchants can edit or remove their credentials and tracking settings in the dashboard at any time, and can pause a store, which stops new checkouts immediately.

Depending on where you live you may have rights to access, correct, delete or export personal information, or to object to certain processing. The route for exercising them will be listed under Contact once the operator's details are published.

9. Changes to this policy

This page is versioned with the platform. The date at the top changes whenever the policy does, and material changes will be announced to merchants in the dashboard.

10. Contact

The operator's contact details for privacy questions will be published here before this policy leaves draft.