Privacy and data use
Clearpick is operated by Fritz Döbel and prepares pick lists for Shopify merchants. This page describes the app’s data processing. Last updated: 3 October 2026.
Information used to prepare a list
When a merchant opens or refreshes a list, Clearpick reads order identifiers and references, product and variant information, SKUs, fulfillment locations, remaining quantities and Shopify-recorded bundle relationships. This information is used only to display and export the merchant’s pick list.
The app does not request customer names, email addresses, phone numbers, shipping addresses or billing addresses. Order references can still relate to a customer in the merchant’s Shopify account.
Storage and retention
Order contents and generated pick lists are processed for the current request and are not stored in the application database. A downloaded CSV or printed list stays under the merchant’s control. Clearpick cannot delete those copies.
Authentication sessions are retained while the app is installed. They include the shop domain, granted permissions, access and refresh tokens, expiry times and, where supplied by Shopify, staff account identity and session metadata. Shopify subscription status is used to verify the selected plan and its order allowance. Uninstall and shop-redaction webhooks remove stored sessions for the shop.
Service providers and security
Shopify supplies the API, authentication, embedded app components and subscription processing. Cloudflare provides Workers hosting and a private SQLite-backed Durable Object dedicated to Clearpick, restricted to the European Union for storage and object execution. The front Worker, delivery network and provider metadata can process elsewhere. The previous Netlify hosting and PostgreSQL store in Ohio may be retained temporarily for migration verification and recovery. Hosting infrastructure processes requests and operational metadata. Access and refresh tokens are encrypted in private storage, and connections to Shopify use HTTPS. Application logs omit request URLs, order contents and tokens.
Cloudflare SQLite point-in-time recovery can retain earlier database states for up to 30 days. Automatic Worker invocation logs are disabled. Netlify stores and backups have separate residual retention while rollback verification finishes. Deleted shop records must be removed before restoring service. Backups are for recovery, not routine access.
Optional review invitations
When a live, non-empty pick list is successfully loaded, Clearpick records the shop domain, a count of distinct days of use, the first and most recent use dates, and whether the merchant dismissed review invitations. These records contain no order contents. They allow an optional, neutral invitation after repeated use. Choosing “Don’t ask again” permanently suppresses the invitation for this installation. Uninstall and shop redaction remove these records; provider backups follow the retention limits above.
Choices and requests
Clearpick does not sell customer data, use it for advertising, or make automated decisions about individuals. Merchants can uninstall the app to revoke its access and can send data access or deletion requests through Shopify. Mandatory Shopify privacy webhooks are authenticated and processed even after uninstall.
If you are a customer of a store, contact that store about its order records. Clearpick does not keep a separate customer database. Support messages are handled by the support email provider and should contain no customer data or credentials.
Merchant agreement
Before live order data is loaded, an authorized store representative accepts the merchant terms and data processing agreement. Clearpick stores the shop domain, accepted version and acceptance time while installed. These records are removed with the shop’s sessions on uninstall or shop redaction. Provider backups follow the retention limits above.
Contact
For app support or privacy requests, email fritzdoebel@gmail.com.
The operator’s postal address is in the legal notice.