The short version. Insertly reads a merchant's orders so it can print a personalised card for each one. It never sees payment or card details. It stores nothing about a buyer beyond what is needed to render that buyer's card. It never sells data to anyone.
This policy covers Insertly, an application for OpoShop stores that generates print-ready package inserts — thank-you cards, care cards and reorder offers — from a store's orders. It applies to the merchant who installs Insertly. Insertly has no storefront widget and no buyer-facing web page: buyers only ever encounter it as a printed card in their parcel.
When a merchant installs Insertly, OpoShop grants it an access token scoped to that one store. Insertly uses it only for the following, and requests no permission it does not use:
Insertly does not request or use access to products, customers, collections, or webhooks.
In its own database (a dedicated database used only by this app, with every record scoped to a single store), Insertly keeps:
To personalise a card, Insertly reads a buyer's name, order number and item count from the order at the moment the card is generated. That information is used to render the PDF and is not stored in Insertly's database. Insertly does not store buyer email addresses, postal addresses, or phone numbers, and it never has access to card or payment details at any point — payment is handled entirely by OpoShop and its payment provider.
The only buyer-linked record Insertly retains is the reorder-code ledger described above, which stores an order number — not a person's contact details.
Insertly uses PostHog for product analytics, to understand which features are used. Events are identified by an opaque, store-scoped identifier of the form store_<id>. No personal data is ever sent to analytics — no emails, no buyer names, no order contents, no addresses.
Insertly does not sell data and does not share it with advertisers or data brokers. Data is processed only by the infrastructure providers required to run the app: Fly.io (hosting), MongoDB Atlas (database), and PostHog (analytics, non-personal events only). Generated PDFs are produced on demand and streamed to the merchant's browser; they are not stored on our servers.
Store data, brand settings, card designs and the reorder-code ledger are kept for as long as the app is installed. If a merchant uninstalls Insertly, the store is marked uninstalled and the first-run flag is cleared; the card designs and code ledger are retained so a reinstall restores the merchant's work. A merchant can request complete deletion of their data at any time by emailing the address below, and it will be removed.
All traffic is served over HTTPS. Access tokens are stored server-side and never exposed to the browser. Every record is scoped to exactly one store, and every request is authorised against the store it belongs to — one merchant's data is never reachable from another merchant's session.
You can request access to, correction of, or deletion of the data Insertly holds about your store at any time. Email brandon@tryfound.io and we will respond.
If this policy changes materially, the “last updated” date above changes with it.