Privacy
Privacy Policy
How AfterCheck collects, uses, discloses, retains, and protects personal information.
Last updated:
Overview
This Privacy Policy explains how AfterCheck collects, uses, discloses, retains, and protects personal information when business users, website visitors, connected merchants, and individuals who submit feedback use AfterCheck.
Tyler Heshka operates AfterCheck from Saskatchewan, Canada as a business-to-business software product and brand. The business customer that uses AfterCheck controls its customer relationship and decides when to send or publish feedback links. AfterCheck processes personal information to provide the service to that business customer.
If a separate written agreement, order form, or customer notice identifies a specific legal operator or additional privacy terms, that document applies together with this Policy.
Privacy Law Posture
AfterCheck is designed for Canadian private-sector commercial use and is written with the Personal Information Protection and Electronic Documents Act (PIPEDA) principles in mind, including accountability, identifying purposes, consent, limiting collection, limiting use, disclosure and retention, accuracy, safeguards, openness, individual access, and challenging compliance.
Business customers remain responsible for the privacy, consumer protection, anti-spam, industry, employment, and other laws that apply to their own customer communications and use of AfterCheck.
Personal Information We Collect
We collect personal information that is needed to provide, secure, and improve AfterCheck. AfterCheck aims to collect and retain only the data reasonably needed for the product, security, legal, provider, and support purposes described in this Policy.
- Business user and account information: name, email address, authentication metadata, account activity, support communications, security events, and settings.
- Workspace information: organization name, business type, locations, public profile settings, branding settings, notification preferences, API key metadata, webhook endpoint metadata, billing status, and team membership records.
- Feedback and request information: sentiment selection, response status, category, comment text, customer name, customer email, permission-to-contact selection, campaign or request context, external references, source and UTM attribution, timestamps, and neutral next-action clicks.
- Connected integration information: provider connection metadata, Shopify shop domain, safe webhook receipt details, sync status, provider object identifiers, and order or customer fields needed to create feedback requests when a workspace connects an integration.
- Technical and security information: browser or device metadata, user agent, hashed IP or privacy-safe fingerprint values where used, request identifiers, security logs, rate-limit data, consent preferences, diagnostics, and error records.
- Support, privacy, and legal communications: information provided when someone contacts us for support, account help, privacy requests, security reports, or legal notices.
AfterCheck is not intended for health records, payment card numbers, bank account numbers, government identification numbers, children's data, special-category data, or other highly sensitive personal information unless a separate written agreement expressly allows that use.
Sources Of Information
We may collect information directly from business users, administrators, team members, feedback respondents, website visitors, and people who contact support, privacy, legal, or security channels.
We may also receive information from the business customer that uses AfterCheck, from connected providers such as Shopify when a workspace authorizes an integration, and from operational providers such as Supabase, Vercel, Stripe, Resend, Klaviyo, PostHog, Sentry, Upstash, and Svix when those providers are configured for the service.
How We Use Information
- Provide, maintain, secure, monitor, and improve AfterCheck.
- Authenticate users, manage workspaces, apply organization-scoped access, and show account or workspace settings.
- Capture feedback selections, details, follow-up permission, and neutral next-action clicks.
- Display feedback, requests, campaigns, locations, notes, analytics summaries, and exports to authorized workspace users.
- Support API keys, manual exports, webhook endpoint setup, notification preferences, delivery records, and other integration features requested by a workspace.
- Send service, security, account, support, or notification emails when the relevant configuration and user or workspace settings allow it.
- Sync configured integration records, such as Shopify paid-order events, into AfterCheck request workflows.
- Detect misuse, troubleshoot errors, protect service availability, maintain audit records, and enforce our Terms of Service.
- Comply with legal obligations and respond to lawful requests.
Data Minimization And Automated Decisions
AfterCheck uses customer and integration data for private feedback workflows, workspace administration, security, support, billing, analytics, and provider operations. We do not sell customer feedback data, Shopify customer data, or business user data, and we do not use feedback content to operate a public review platform.
AfterCheck does not currently make automated decisions that have legal or similarly significant effects on individuals. Product status, sentiment, routing, analytics, billing state, and integration sync may help a workspace organize work, but they do not replace the business customer's own review and decision-making.
Customer Communications And CASL
Businesses using AfterCheck are responsible for making sure their customer communications are lawful. This includes having the required consent or other legal basis to send feedback requests, identifying the sender, keeping consent records where required, and providing any required unsubscribe or preference mechanism for commercial electronic messages.
AfterCheck may provide feedback links, snippets, email notification infrastructure, API features, webhook setup, and future delivery tools. Those tools do not replace the business customer's own obligations under Canada's Anti-Spam Legislation (CASL) or other messaging laws.
Where marketing messages are enabled by AfterCheck, recipients should be able to use the unsubscribe or preference mechanism provided in the message, or contact AfterCheck through the contact details below.
Shopify Integrations
If a workspace connects Shopify, AfterCheck uses Shopify authorization, verified webhooks, and the Shopify Admin API to connect the store, receive paid-order events, and create tracked feedback request records for that workspace.
The current Shopify workflow uses the read_orders scope and may receive or store the shop domain, connection status, webhook receipt identifiers, Shopify order ID, order name, order timestamps, customer email, and customer first and last name when Shopify permits those fields. AfterCheck does not intentionally request Shopify customer phone numbers or addresses for the current workflow.
Shopify order-triggered feedback requests are created as "not sent" records. AfterCheck does not automatically email Shopify customers from an order event unless a separate send action is configured and performed. If Shopify redacts or withholds protected customer fields, AfterCheck should use only the fields available to it.
AfterCheck uses Shopify data for the connected merchant's private feedback request workflow, troubleshooting, security, provider compliance, and support. It does not use Shopify protected customer data for unrelated marketing, resale, or public review-gating.
Cookies, Preferences, And Analytics
AfterCheck uses necessary cookies, local storage, and similar technologies for authentication, security, user preferences, consent choices, and product operation.
Optional analytics and marketing tools are disabled by default and should only load when configured and permitted by the applicable consent settings. When PostHog analytics is enabled, AfterCheck uses sanitized route templates and product events instead of raw page URLs or feedback content. Session replay is disabled by default; if it is enabled, it is route-scoped, masked, and blocked on sensitive routes such as public feedback, authentication, billing, and API paths.
If marketing email is enabled, AfterCheck uses saved marketing consent and marketing-specific providers such as Klaviyo. Withdrawing marketing consent does not stop required transactional, billing, security, request, invite, or workspace notices.
Disclosures And Subprocessors
We may disclose personal information to service providers and subprocessors that help us operate AfterCheck. Depending on the environment and enabled configuration, these may include:
- Vercel for hosting, deployment, and application logs;
- Supabase for database, authentication, and related services;
- Resend for transactional email delivery when email sending is enabled;
- Klaviyo for marketing email profile sync and marketing messages when enabled and consented;
- Stripe for hosted checkout, billing portal, subscription state, and payment processing when billing is enabled;
- Shopify for merchant-store integration when a workspace connects a Shopify store;
- PostHog for optional product analytics, surveys, and route-scoped replay when configured and consented;
- Sentry for error monitoring and diagnostics when enabled;
- Upstash for rate limiting or related operational data when enabled;
- Svix for outbound webhook delivery and signing when enabled;
- professional advisors, support vendors, authorities, or parties to a business transaction where needed for legal, compliance, security, restructuring, or enforcement purposes.
Modern SaaS infrastructure may process or store information outside Saskatchewan or Canada. When information is processed outside Canada, it may be subject to the laws of the jurisdiction where it is processed.
Data Portability And Integrations
AfterCheck includes manual exports, API keys, and webhook endpoint setup so business customers can move feedback data into their own systems. Business customers are responsible for securing exported data, API keys, webhook endpoints, and systems that receive AfterCheck data.
We do not sell customer feedback data, Shopify customer data, or business user data. We do not use feedback content to operate a public review platform.
Retention
We retain account, workspace, campaign, request, response, export, integration, notification, security, and support records for as long as needed to provide the service, maintain auditability, troubleshoot issues, resolve disputes, prevent abuse, enforce agreements, and meet legal obligations.
AfterCheck maintains an internal data retention policy for operational use. That policy is reviewed at least annually and after material legal, privacy, Shopify protected customer data, billing, lifecycle, backup, integration, or schema changes.
Account closure, workspace deletion, and some exports may require a support-reviewed request rather than full self-service deletion. The current deletion request workflow records intent, blockers, schedule and recovery status where applicable, but final account deletion, final workspace deletion, hard deletion, and Auth user deletion are not fully self-service product features.
When a deletion request is approved and a final deletion process is available, we aim to remove or de-identify active service records within a reasonable period, subject to backups, logs, fraud prevention, security obligations, legal holds, billing/accounting records, and records we must retain.
Access, Correction, Export, And Deletion
Business customers can request access, correction, export, or deletion support for their workspace data. Individuals who submitted feedback through an AfterCheck link may contact the business that sent or published the link, or contact us and we will help route the request where appropriate.
Send privacy requests to legal@aftercheck.app. We may need to verify identity, workspace authority, and request scope before acting on a request.
Shopify merchants and Shopify customers may also have privacy rights handled through Shopify's required privacy request process. Where a request relates to Shopify data, AfterCheck may need to verify the store, customer, workspace authority, and retention obligations before acting.
Safeguards And Breach Response
AfterCheck uses technical and organizational safeguards appropriate for a pre-release business SaaS product, including authenticated access, organization-scoped authorization, Supabase Row Level Security, hashed API keys, server-only provider secrets, transport security, sanitized logs, environment-scoped configuration, and provider boundaries.
AfterCheck also maintains documented security incident response, privacy incident response, data loss prevention, backup/restore, and retention procedures. These procedures are operational controls, not a guarantee that incidents, data loss, or service interruption cannot occur.
No system is perfectly secure. If we identify a privacy or security incident that creates a real risk of significant harm or otherwise triggers legal notice obligations, we will investigate, keep required records, and provide notices as required by applicable law.
Children
AfterCheck is not directed to children and should not be used to knowingly collect children's personal information. Business customers must not use AfterCheck for children's data unless they have the required authority and written approval from AfterCheck.
Changes To This Policy
We may update this Policy as AfterCheck, its subprocessors, or its legal obligations change. The "Last updated" date shows when the Policy was last revised. Material changes may be announced in the app, by email, or through another reasonable notice path.
Contact
Privacy and legal notices can be sent to legal@aftercheck.app. AfterCheck's current operating jurisdiction is Saskatchewan, Canada.