This policy covers the Provenance app for Shopify and this website. Provenance is made by Monochrome, a software studio in Lebanon. We are the people you reach at hello@monochrome.digital, and there is no larger organisation behind us.
It is written in two halves because they are two unrelated things, and reading them as one produces nonsense. If you are a merchant deciding whether to install the app, the first half is yours. If you are somebody who scanned a card or is reading this page, the second half is.
The short version
The app holds records about objects, not about people. It asks Shopify for no permission touching customers, and it writes nothing identifying a person into your register. What we hold about you as a merchant is your store's address, your staff account details from Shopify, and the records you create about the items you make.
This website sets no cookies and runs no analytics. That will change only if the section on analytics below changes with it, and the build refuses to publish a tracking tag while this document says there is none.
1. Which half applies to you
| You are | Read | Who is responsible for your data |
|---|---|---|
| A merchant who installed the app | Sections 2 to 7 | You are the controller. We are your processor. |
| Somebody who scanned a card | Section 8 | The merchant whose store you scanned into is the controller. |
| A visitor to this website | Sections 9 to 11 | We are the controller. |
2. What the app collects from your store
When you install Provenance, Shopify gives us the information the app was granted permission for. That is:
- Your shop record. Your
.myshopify.comdomain, your primary storefront domain, your shop name, your plan, your country and your locale. - Your staff account. The name, email address and user ID of whoever is signed in to the app, so an action in the event log can say who performed it.
- Product and variant data, read to resolve an identifier back to the thing it names: titles, options, images, product and variant IDs.
- Order access, granted but not yet used. The app has permission to read orders, for a feature that does not exist yet: marking an item sold when its order is fulfilled. Until that is built, the app reads no orders at all. When it is, it will read the fact of a fulfilment and nothing else — never customer names, addresses or payment details, and it will not store order line contents.
The app requests no permission touching customers. Shopify's protected customer data approval is not something we have applied for, because we do not need it and asking for it would drag the whole app into a review it does not require.
3. What the app creates
The records you make, which are the point of the product:
- Items. An identifier, the product and variant it names, the date it was made, its edition number and size, its status, and timestamps.
- Runs. Which items were minted together, when, and by whom.
- Events. Every change to an item, with a timestamp and an actor. The actor is a member of your staff or a system source such as a Shopify webhook. It is never a customer.
- Settings. Your storefront address, your identifier prefix, your certificate design, and the page your cards resolve on.
None of this describes a person. An identifier is generated randomly and carries no structure: not the model, not a sequence, not a date. That is a deliberate choice rather than a side effect, and it is what stops two cards together telling anybody your production volumes.
4. Where it is held
Our database is hosted in the European Union, in Frankfurt, with encryption in transit and at rest. The app itself runs on infrastructure that may serve a request from a location closer to whoever made it, but the records are stored in the EU.
A second copy of each item record sits in your own Shopify admin, as a metaobject in your store. That copy is yours. It is subject to Shopify's own terms and privacy commitments rather than ours, and it stays in your store after you uninstall this app.
Every third party that may handle data on our behalf is listed, with its location and its role, in the Sub-processors document. We give 30 days' notice before adding one.
5. Who can read what
The metaobject definition the app creates in your store is publicly readable. That is what makes a scan work at all: anybody holding an identifier can read every field on that item's entry, without an account and without your permission.
So the rule the app enforces, and the one you should enforce in anything you build on top of it: nothing identifying a person goes into the register. No owner names, no email addresses, no order numbers, no prices paid. The app does not write those and does not offer a field for them.
6. How long we keep it
While the app is installed, we keep your records for as long as you have them. That is the service.
When you uninstall, Shopify tells us, and what we hold about your store is deleted 48 hours later. Export anything you want to keep before you go: the app has an export, and your register in Shopify is yours regardless.
We keep two things beyond that, and only these: entries in the operational logs of our hosting providers, and any invoice or billing record we are required by law to retain.
We do not run a log store of our own, and we do not copy, export or archive those logs anywhere else. They expire on the schedule the providers named in Sub-processors apply, which is a short period measured in days rather than months. We would rather describe that accurately than name a number we are not the ones enforcing.
Deleting our copy does not delete your register in your own Shopify admin. That is deliberate, and it is the promise this whole arrangement is built around: the records describe physical objects that are in other people's hands, and those objects do not stop existing because you stopped paying us.
7. Your rights as a merchant
You are the controller of the data in your store. We act on your instructions.
- Access, correction and export. Available in the app at any time. If something is not exportable that should be, tell us and we will get it to you.
- Deletion. Uninstall, and our copy goes 48 hours later. If you want it gone sooner, or want us to delete something specific while staying installed, write to hello@monochrome.digital.
- A data processing agreement. You already have one. The Data Processing Addendum, including the Standard Contractual Clauses, forms part of your agreement with us from the moment you accept the terms. There is nothing separate to sign.
- Shopify's mandatory requests. The app implements Shopify's three compliance webhooks. A customer data request or a redaction request routed through Shopify is answered, and the honest answer in almost every case is that we hold nothing about that customer, because the app does not collect customer data.
We answer any request within 30 days.
8. If you scanned a card
You are reading this because a card, a tag or a label sent you to a page, and that page mentioned this app.
What happened when you scanned. Your phone opened a page on the merchant's own storefront. The identifier from the card travelled in the part of the web address after the #, which browsers never send to a server. The page then asked our service what that identifier names, and showed you the answer.
What we learn about you. The request reaches us through Shopify's app proxy from the merchant's storefront. We receive the identifier being looked up, and the technical details every web request carries: an IP address, the time, and what kind of browser made it. These sit in our hosting providers' operational logs, which expire on their schedule within days, and they are used to keep the service working and to spot abuse. We keep no copy of our own. We do not build a profile, we do not set a cookie on that page, and we do not know who you are.
What we do not have. We hold no record of who owns any item. Not your name, not your email address, not what you paid, not who you bought it from. If you scan the same card a hundred times, we have not learned anything about you.
Who is responsible. The merchant whose store you scanned into is the controller of the record you were shown. If a record about an item is wrong, or you want an item's status corrected, that is theirs to fix. Their privacy policy covers what they do with the information. We are glad to point you at them if you write to hello@monochrome.digital.
9. This website
Separate from the app, and much simpler.
We set no cookies on this site. There is no analytics, no advertising and no third-party script of any kind. Nothing here is measured, so no consent banner is shown, because there is nothing to consent to.
Should that change, it will change here first. The build that publishes this site refuses to publish a tracking tag while this document says there is none: the check is in the code, not in somebody's memory.
10. The contact form
If you write to us through the form on this site, we get your name, your email address, whatever you put in the message, and the store address if you gave one. Cloudflare also tells us which country the request came from, which we use to spot a flood from one source.
That reaches us as an email, through Resend, and we use it to answer you. It is not added to a mailing list, because we do not have one. We keep the correspondence for as long as it is useful and delete it when it is not.
11. Hosting this site
This site is served by Cloudflare, in whichever of its locations is nearest to you. Cloudflare processes the technical details of the request in order to deliver the page and to protect the site from abuse.
12. Changes to this policy
We date this document at the top and we do not change it quietly. Anything that materially changes what we collect or who we share it with is announced to installed merchants by email before it takes effect, and shown on the changelog.
13. Complaints
Write to us first: hello@monochrome.digital. We answer within 30 days.
If you are in the European Union or the United Kingdom and you are not satisfied with our answer, you have the right to complain to your local data protection authority. That right exists whether or not you have written to us, and using it does not require our agreement.