Privacy Policy

Last updated: July 13, 2026

This policy explains how the independently operated, unincorporated software service based in Pune, Maharashtra, India and offered under the MoCRA Ops name ("MoCRA Ops Kit," "we," "our," or "us") handles information on this website and in the MoCRA Ops Kit Shopify app. The app is intended for business users.

Adverse-event records can contain sensitive personal or health-related information. Merchants control what they enter and upload and should collect only information they are authorized to process.

1. Information We Process

Public website visitors

The public website does not use behavioral-advertising pixels or tracking cookies. Cloudflare may process standard network and security information, such as IP address, request metadata, device or browser information, and security signals, to deliver and protect the site.

Shopify App Store listing visitors

When you view our Shopify App Store listing, click Install, or complete installation, Shopify may send Google Analytics events for those actions. Depending on the event, data may include listing or app identifiers, referral context and, for completed installations, shop ID, shop name, and shop URL. Shopify and Google may also process cookies or similar identifiers and device, browser, and network information under their policies and applicable consent controls.

We use this information to measure aggregate listing discovery and installation, evaluate listing changes, and diagnose measurement problems. This configuration applies only to our Shopify-hosted App Store listing; it does not add Google Analytics to mocraops.com. We do not send merchant-uploaded content, product or safety records, adverse-event records, case narratives, or customer information to Google Analytics, and we do not join row-level listing analytics with merchant app records or use it for behavioral advertising. Learn how Google uses this information.

Shopify account and store information

When a merchant installs or uses the app, we may process:

  • Shop domain, installation status, subscription status, and app settings
  • Store-owner or staff account details made available by Shopify, such as name, email, phone number, physical address, locale, and account role
  • Current product display information, including Shopify product ID, title, update time, and featured-image URL
  • Product-change history containing product title, vendor, product type, status and options, plus variant title, SKU, barcode, position and selected options
  • Product-change review metadata, including revision, source, detected and acknowledged times, reviewing staff identity made available to the app, and an optional internal note
  • Authentication sessions, webhook deliveries, audit logs, and security or operational logs
  • First-use milestones such as authenticated install, setup, first stored file, first eligible export snapshot, and subscription or trial state; these milestone records do not contain filenames, product IDs, staff or customer identifiers, URLs, or free-form content

Product-change history does not contain prices, inventory, product descriptions, tags, image history, customer records, or order records. The app uses read-only Shopify product access and cannot edit Shopify products. Product webhook queue entries retain only the product identifiers and update time needed for canonical synchronization; the retained payload is cleared after successful processing.

Information merchants provide

Merchants choose whether to create or upload:

  • Product labels, safety substantiation documents, certificates of analysis, supplier records, and related files
  • Facility, product-listing, batch, retention, notification, and workflow settings
  • Supplier contact names and email addresses used for document requests
  • Adverse-event case data, which can include patient initials, age, gender, dates, narrative, internal notes, seriousness criteria, and attachments
  • Export records and metadata generated from merchant-provided content

Legacy launch-contact records

Before the app launched, the website collected email address, optional store URL, product category, SKU-count range, and a one-way IP hash for launch communications and abuse prevention. The public site no longer accepts these submissions. Legacy records remain segregated in Cloudflare D1 while their retention or deletion is completed. You can request access or deletion by emailing us.

2. How We Use Information

  • Authenticate merchants and provide product synchronization, product-change comparison and review, recordkeeping, deadline, export, and support features
  • Process subscription state and plan entitlements through Shopify
  • Send merchant-requested notifications, reminders, supplier requests, and service communications
  • Protect the service, prevent abuse, troubleshoot failures, and maintain auditability
  • Measure aggregate Shopify App Store listing views, install-button selections, and completed installations
  • Respond to support, privacy, and legal requests
  • Comply with applicable law and Shopify platform requirements

We do not sell personal information or use merchant content for third-party behavioral advertising.

3. Privacy Roles for Merchant-Provided Information

Merchants decide why personal information is entered or uploaded to the Service and are responsible for having an appropriate basis to collect and use it. Where applicable privacy law uses terms such as controller and processor, or business and service provider, the merchant generally acts as the controller or business for merchant-provided records, and MoCRA Ops Kit processes those records on the merchant's behalf to provide, secure, maintain, and support the Service, except where processing is required by law.

For account administration, service security, abuse prevention, billing support, customer support, and compliance with our own legal obligations, MoCRA Ops Kit determines the relevant processing purposes and may act independently. The precise legal roles depend on the processing activity and applicable law.

4. Service Providers and Disclosures

We use service providers only for operating the website and app:

  • Shopify — app distribution, authentication, approved store APIs, and billing
  • Render — application hosting and operational logs
  • Supabase — PostgreSQL database and file storage
  • Resend — transactional and reminder email when email delivery is configured
  • Cloudflare — public website delivery, security, and segregated legacy launch-contact storage
  • Google Analytics — measurement of listing views, install-button clicks, and completed installations for our Shopify App Store listing; not used on mocraops.com through this configuration

Providers process information under their own contractual and security terms and may process it in countries where they operate. We may also disclose information when required by law, to protect rights or service security, or as part of a business reorganization subject to appropriate safeguards.

5. Data Retention and Deletion

  • Active app data is retained while needed to provide the service and according to the retention profile selected by the merchant.
  • Reviewed product-change history follows the selected retention period, measured from detection. Unreviewed changes are retained until review, and the latest product checkpoint is preserved so later changes remain interpretable. Product-change history is included in merchant raw-data, Product Audit, Full Audit, and applicable QA Handoff exports; internal history is omitted from Retailer Dossier Packs.
  • Uninstalling revokes app access and schedules the installation's files and database records for deletion 30 days later. Failed storage or database attempts are retried rather than being treated as complete.
  • A verified Shopify shop/redact request makes deletion of an uninstalled installation immediately due, subject to any legal obligation to retain specific information.
  • Reinstalling creates a new workspace after the prior installation is safely removed; the old workspace is not revived.
  • After deletion, we retain a one-way, secret-keyed shop-domain receipt for up to 60 days to route delayed Shopify redaction webhooks without retaining the shop domain or webhook payload. Minimal incident metadata may be retained for up to 90 days when a destructive webhook cannot safely be mapped to an uninstalled installation.
  • Security, billing, and legal records may be retained for a limited period where necessary for fraud prevention, dispute handling, or legal compliance.
  • Legacy launch-contact records are no longer collected and can be deleted on verified request while final disposition is completed.

Before uninstalling, merchants should export any records they need to retain. To request deletion or ask about a scheduled deletion, contact [email protected].

6. Security

We use HTTPS, authenticated access, shop-level data isolation, restricted service credentials, and provider security controls. No system can guarantee absolute security. Merchants should avoid uploading unnecessary personal data and should redact attachments where appropriate.

7. Privacy Requests

Depending on applicable law, individuals may have rights to request access, correction, deletion, or restriction.

  • Merchants can contact us directly using the email address below.
  • Shopify also sends mandatory data-access and redaction requests to the app through verified compliance webhooks.
  • Requests may require identity or authority verification before we disclose or delete information.

8. Children's Privacy

The service is intended for business users and is not directed to children. We do not knowingly collect information directly from children through the public website.

9. Changes to This Policy

We may update this policy as the service or legal requirements change. We will update the date above and provide additional notice when appropriate.

10. Contact

MoCRA Ops Kit is an independently operated, unincorporated software service based in Pune, Maharashtra, India. Privacy questions, requests, and legal communications can be sent to [email protected].

Privacy laws vary by location. Merchants should obtain legal advice about obligations that apply to their own use of the app and the information they enter.