Privacy

LaneReady Privacy Policy

Last updated: October 3, 2026

LaneReady is a Shopify admin app that helps merchants review cross-border readiness signals before making their own operational decisions.

Shopify data access

LaneReady requires Shopify read access for products and orders. LaneReady also declares optional inventory-write access for one narrow v1 capability: an exact Shopify inventory-item weight update that is separately gated and requires explicit merchant confirmation.

Permission to write inventory does not by itself authorize a change. The supported weight-fix flow shows the exact target and before/after weight, requires merchant confirmation, permits at most one Shopify write attempt, does not automatically retry after dispatch, and rereads Shopify to verify settlement.

LaneReady does not use Shopify product-write permission, does not bulk-edit products, does not silently or automatically change catalog data, does not mutate Shopify orders, does not create shipping labels, and does not change storefront checkout behavior.

How data is used

We use Shopify information available to the app to provide readiness checks, merchant review workflows, exports, billing access, and the supported merchant-confirmed weight-fix workflow. LaneReady does not sell merchant store data.

LaneReady does not persist customer names, email addresses, phone numbers, or postal addresses as feature data. Order-style records used by LaneReady are limited to operational identifiers and readiness/amount context needed for the product workflow.

Weight-write event metadata

When a merchant creates or confirms a weight-fix action, LaneReady stores a narrow write-event record for safety, idempotency, auditability, and settlement verification. That record can include the merchant workspace identifier; Shopify product, variant, and inventory-item identifiers; the prior weight state; the intended weight; an action fingerprint; write state and timestamps; and a sanitized error category when applicable.

The write-event record does not store customer contact information, payment credentials, Shopify access tokens, session tokens, or raw authentication secrets.

Retention and deletion

LaneReady defines a 365-day retention target for Shopify weight-write event metadata. Automated retention enforcement is active through a governed weekly GitHub Actions process for eligible settled states; unresolved or safety-sensitive states are preserved rather than deleted automatically.

Authenticated Shopify privacy/compliance webhook handling is active. Shop-redaction processing removes the exact merchant workspace transactionally, including the exact shop's Shopify session records and merchant root, with related workspace data removed through verified cascades.

Security and operational safeguards

LaneReady uses authenticated Shopify app and webhook flows, keeps mutation authority separate from AI review, and avoids exposing access tokens or authentication secrets in merchant-facing evidence. Weight-write activity is designed to fail closed when target identity, permission, activation, or settlement cannot be verified.

Contact

For privacy questions or deletion requests, contact [email protected].