1. Overview
CommerceOps for ClickUp (“CommerceOps,” “we,” “us,” or “our”) is a Shopify application that helps merchants turn Shopify events into tasks and related work in ClickUp. The merchant that installs the application controls which automations are configured and which Shopify data is sent to ClickUp.
For personal data contained in Shopify store records, the merchant is generally the data controller and CommerceOps acts as a service provider or processor on the merchant's behalf. For account administration, security, billing support, and this public website, CommerceOps may act as a controller.
2. Information we collect
Merchant and Shopify account information
We receive the shop domain, store name, contact email, installation and uninstallation status, Shopify user identifiers and, when made available by Shopify, the user's name, email, locale, account-owner status, and granted access scopes. Shopify authentication tokens are stored so the application can perform authorized operations.
Shopify commerce data
Based on the triggers enabled by a merchant, the application can receive and temporarily or persistently process webhook payloads and API data relating to:
- orders, payment state, totals, currency, discounts, tags, and line items;
- customer names, email addresses, tags, order count, and total spend;
- products, variants, SKUs, vendors, product types, status, and tags;
- inventory levels and locations;
- refunds, fulfillment status, carriers, and tracking information.
The exact fields processed depend on the merchant's automation trigger, conditions, templates, and Shopify Flow configuration.
ClickUp information
When a merchant connects ClickUp, we receive and store an OAuth access token, workspace identifiers and names, connected-user details, and cached metadata such as Spaces, Folders, Lists, statuses, assignees, Teams, and supported custom fields. The access token is encrypted at rest.
Configuration and operational records
We store automation definitions, drafts and published versions, conditions, task templates, ClickUp destinations, billing plan state, linked resource identifiers, execution history, logs, notifications, audit events, and Shopify Flow action configurations. Logs can include limited data required to explain an execution result or error.
Support and email information
We process the recipient address and message metadata needed to send welcome, service, limit, failure, and resolution emails. If you reply or contact us for support, we process the contents of that communication and your contact details.
3. How we use information
We use information only as reasonably necessary to:
- authenticate the merchant and operate the embedded Shopify application;
- receive Shopify events and evaluate merchant-configured workflows;
- create, update, assign, and link ClickUp tasks and related work;
- display execution history, audit history, usage, and troubleshooting details;
- manage subscriptions, plan limits, onboarding, and application settings;
- send transactional and operational notifications;
- detect duplicate deliveries, prevent abuse, secure the service, and diagnose failures;
- respond to support requests and comply with legal obligations.
We do not sell merchant or customer personal data. We do not use Shopify customer data for independent advertising or unrelated profiling.
5. Data retention
We retain information while the application is installed and for as long as necessary to provide the service, maintain reliable execution and audit records, resolve disputes, enforce agreements, and meet legal obligations. Different records can have different retention periods.
Merchants can disconnect ClickUp and can request deletion from the application's Settings page. When Shopify sends a mandatory customer-redaction request, matching stored webhook payloads are replaced with a redacted marker. When Shopify sends a shop-redaction request, stored webhook payloads are scrubbed, the ClickUp token is removed, and active automations are archived. Some non-personal or minimally identifying records may be retained where required for security, billing, idempotency, auditability, or legal compliance.
6. Security
We use administrative, technical, and organizational safeguards designed to protect information. These include HTTPS in transit, Shopify request and webhook authentication, access controls, encrypted ClickUp tokens at rest, deduplication, and restricted production secrets. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
7. International processing
CommerceOps and its service providers may process information in countries other than the merchant's or customer's country. These locations may have different data-protection laws. Where required, appropriate contractual or legal safeguards are used for international transfers.
8. Your privacy rights
Depending on applicable law, individuals may have rights to access, correct, delete, restrict, or object to processing of personal data, or to request data portability. A Shopify customer should normally contact the merchant from whom they purchased because that merchant controls the store data. We support merchants in responding through Shopify's mandatory privacy webhooks.
Merchants can submit a request using the contact information below. We may need to verify the request and may retain information where permitted or required by law. Individuals may also have the right to complain to their local data-protection authority.
10. Changes to this policy
We may update this policy as the service, providers, or legal requirements change. We will publish the updated version on this page and revise the “last updated” date. If a change materially affects how personal data is used, we will provide additional notice where required.
11. Contact us
Questions, privacy requests, and data-protection inquiries can be sent to: