Contact
Privacy requests
WeaveCycle uses taimoor@weavecycle.co for privacy, security, and data protection requests until a dedicated legal contact is published.
Email a privacy requestAnalytics choice
We use PostHog analytics to understand public site usage only if you accept. Essential auth cookies still work without analytics. Read the Privacy Policy.
Privacy Policy
This policy explains how WeaveCycle handles account, Shopify, return workflow, and analytics data. It is a transparent legal-review draft dated May 4, 2026.
Contact
WeaveCycle uses taimoor@weavecycle.co for privacy, security, and data protection requests until a dedicated legal contact is published.
Email a privacy requestController and processor roles
WeaveCycle acts as a controller for direct site, account, support, security, and product analytics data. For Shopify merchant data and customer-related return workflow data processed inside a merchant workspace, WeaveCycle generally acts as a processor on the merchant's instructions.
This notice is not a signed data processing agreement. Merchants that need a DPA, final subprocessor terms, or legal entity details should contact WeaveCycle before sending live production data.
Data we process
Work email, name, job title, organization name, workspace name, role, invitation status, notification preferences, and sign-in timestamps.
Store domain, Shopify scopes, product records, order records, return reasons, routing decisions, recovery values, and sync status. Protected customer data is limited to customer name and email (used to verify shoppers in the returns portal and identify the order owner). We do not collect customer phone, street address, or payment data.
Audit log actions, product events, sync runs, import summaries, webhook events, routing overrides, export records, and support context.
Public pageviews only after consent, signed-in product events, browser metadata, timestamps, referrer, and high-level usage properties.
Purposes and lawful bases
Contract or pre-contractual steps with the merchant, and legitimate interests in operating the service.
Processor activity performed on merchant instructions, plus contract performance for the workspace.
Legitimate interests and legal obligations where applicable.
Consent. Public PostHog analytics is not initialized until analytics consent is accepted.
Legitimate interests in running and improving the B2B service, with disclosures and privacy request channels available.
Supabase and WeaveCycle use essential auth cookies for sign-in and session continuity. Public PostHog analytics uses local storage and cookies only after consent. The default analytics host is the EU PostHog endpoint.
Workspace data is retained while the workspace is active and for a reasonable period needed for audit, security, legal, and backup purposes. Protected Shopify customer data (name and email) is erased on request: we honor Shopify's customer redaction and shop redaction webhooks programmatically, and respond to customer data requests within 30 days. Pilot merchants can also request deletion or export review by email.
WeaveCycle routing, forecasting, and listing tools are workflow aids. The current product does not make solely automated legal or similarly significant decisions about individuals.
Your GDPR rights
The response period may depend on identity verification, merchant instructions, and lawful exceptions.
WeaveCycle uses infrastructure, auth, analytics, and commerce services to run the product. See the subprocessor page for the current list.
The target posture is EU-first: Render Frankfurt, EU Supabase, EU PostHog, and Vercel route execution preferred in Frankfurt where applicable. Some providers, support, CDN delivery, or account administration may involve processing outside the EEA, supported by provider DPAs and Standard Contractual Clauses where needed.