Privacy Policy

This policy explains what data Riptide collects, why we collect it, who processes it on our behalf, and how long we keep it. Riptide is a live-session queue tool for Shopify breakers and rip-and-ship sellers. Our data footprint is deliberately small: we do not store buyer shipping addresses, card details, or payment instruments.

Effective
September 7, 2026
Applies to
Sellers, their team members, and buyers in a show
Hosted in
United States
Data requests
privacy@riptidequeue.com

Sellers, the team members they invite, and the buyers whose orders pass through a show.

Riptide is operated by Riptide Queue LLC, a New Jersey limited liability company ("Riptide," "we," "us"). This policy applies to sellers who create a Riptide workspace, team members that a seller invites to that workspace, and buyers whose order data a seller routes through Riptide during a live show. When we say "you" we mean the seller or team member; we say "buyer" explicitly when we mean an end buyer of a Shopify order.

Account, workspace, settings, Shopify and order data, webhook receipts and logs. Never shipping addresses or card details.

Seller and team-member data

  • Account identity: your email address and display name, provided through our identity provider Clerk. Clerk stores sign-in metadata such as the time and IP of sign-in.
  • Workspace membership: which Clerk organization(s) you belong to and your role in each (owner, admin, mod, viewer).
  • Settings you configure: Discord webhook URLs (stored encrypted), alert-snooze preferences, ETA confidence settings, brand preferences.

Shopify integration data

  • Shop metadata (domain, timezone, currency, status) and the Shopify-assigned shop identifier.
  • Encrypted Shopify access and refresh tokens, stored with per-workspace encryption keys.
  • The set of webhook topics registered for your store so we can reconcile drift with Shopify.

Order and queue data

  • Order records that Shopify sends us via webhook: order number, source channel (for example, Shopify, TikTok Shop via Shopify), line items (title, variant, SKU, quantity), order timestamps.
  • Queue projection: each order's position in a live session, its status (queued, on deck, live, completed, cancelled), ETA, and the public queue token we generate.
  • Queue events: the append-only audit of every queue state change and operator action, with actor identity and payload.
  • Webhook receipts: the raw headers and payload of each Shopify webhook, its signature validity, and processing status. Used for idempotency and debugging.

Service operation data

  • Server logs (requests, errors, performance metrics) via Fly.io.
  • Minimal cookies required to keep you signed in through Clerk.

What we do not collect

We do not collect or store buyer shipping addresses, billing addresses, payment instruments, or card details. Those stay with Shopify. We do not run third-party advertising trackers and we do not sell data.

To sign you in, run your queue, deliver your Discord messages, serve the pass and overlay, alert you, and keep the service running.

We use this data only to:

  • Authenticate you and authorize actions in your workspace.
  • Ingest Shopify orders and project them into your live-session queue.
  • Deliver Discord webhook messages you have configured and retry delivery on failure.
  • Serve the public buyer queue pass and the on-stream overlay.
  • Alert you to stalled queues, Discord delivery failures, and other operational issues.
  • Provide audit trails and wrap-up summaries so you can trust and debug your own data.
  • Operate, secure, and improve the service, including troubleshooting and capacity planning.
  • Meet our legal, accounting, and tax obligations.

Only with the subprocessors that run the service. Never sold, never to advertisers. Legal process and a sale are the exceptions.

We share data only with subprocessors we rely on to run the service, and only to the extent they need it for their role. The current list is at /subprocessors. We do not sell data, do not share it with advertisers, and do not train third-party machine-learning models on it.

We may disclose data when legally required (a subpoena, court order, or similar process), to protect Riptide's legal rights, or to prevent imminent harm. We will attempt to give you notice when we can.

If Riptide is acquired, merged, or reorganized, your data will transfer to the successor entity. We will notify you before that happens.

On Fly.io and Neon, both in the United States.

Riptide's application runs on Fly.io (primary region iad, Ashburn, Virginia) and its database is managed Postgres hosted by Neon, both in the United States. If you access Riptide from outside the United States, your data will be processed in the United States under US law.

Account data for the subscription plus 30 days; orders and queue records for the workspace’s life; raw webhooks and logs for 90 days.

  • Workspace and account data: for the life of your subscription, and for up to 30 days after cancellation, then deleted.
  • Orders, queue entries, queue events: retained for the life of the workspace as your business record. You can request deletion of a specific session's data before the workspace is closed.
  • Webhook receipts (raw payloads): pruned to a rolling 90-day window in production.
  • Server logs: retained for up to 90 days by default.
  • Records we must keep for legal, tax, or accounting reasons may be retained beyond these periods.

TLS everywhere, encrypted tokens and webhook URLs, secrets outside source control. Breaches are notified as the law requires.

Traffic to Riptide is served over TLS. Shopify access and refresh tokens and Discord webhook URLs are stored encrypted with a per-environment encryption key. Database credentials and other secrets are held as Fly app secrets, never in source control. Database connections are made over TLS. No system is immune to breach; if we discover a breach that affects your data, we will notify you in accordance with applicable law.

Access, correct or delete most data from Settings, export on request. CCPA and GDPR requests are answered within 30 days.

You can access, correct, or delete most of your workspace data directly from Settings. You can export order and queue records on request. Depending on where you live, you may have additional rights under laws like the California Consumer Privacy Act (CCPA/CPRA) or the General Data Protection Regulation (GDPR), including the right to request a copy of your data, the right to ask us to delete it, and the right to object to certain processing. Email privacy@riptidequeue.com to exercise these rights; we will respond within 30 days.

Riptide is for people running a business, not for anyone under 16.

Riptide is intended for sellers operating a business and is not directed to children under 16. If you believe a child has given us personal data, contact us and we will delete it.

Clerk sign-in cookies only. PostHog analytics stay off until you allow them; Do Not Track and Global Privacy Control keep them off.

Clerk uses cookies to keep you signed in. Optional PostHog product analytics are off until you choose to allow them. Browser analytics use a persistent random identifier in local storage; signed-in activity is associated with a Riptide seller identifier and workspace identifier, without sending names or email addresses. Your browser preference applies to this browser, and Do Not Track or Global Privacy Control keeps browser analytics off.

Workspace owners and administrators can separately allow completed-operation analytics in Settings. This measures successful automations and seller tasks, such as importing a paid order, completing a turn and verifying a package. Disabling the workspace setting stops collection and discards undelivered events. Your operational records and business reports remain in Riptide.

We collect only explicitly selected event names, normalized page names, workspace context, source labels and bounded task durations or error categories. We do not send customer contact details, addresses, order contents, payment details, tracking numbers, signed overlay links, form text or secrets. Public overlays and buyer queue pages are excluded. Autocapture, session replay, surveys and automatic exception capture are disabled. PostHog is configured for US Cloud; see our subprocessors page. We do not run advertising cookies.

Product analytics

Optional analytics help us understand which Riptide tasks work well. Order contents, customer details, signed links, recordings and form text are excluded. Your business reports work with analytics off.

Browser analytics are switched off in this deployment, so nothing is sent.

Off by default. Do Not Track and Global Privacy Control keep browser analytics off.

Material changes are posted here with a new effective date and emailed to paid workspace owners.

We may update this policy as Riptide evolves. Material changes will be posted on this page with a new effective date, and for active paid subscriptions we will email the workspace owner.

Data questions go to the privacy mailbox. Everything about your workspace goes to support.

Questions about this policy or your data should go to privacy@riptidequeue.com. General support goes to support@riptidequeue.com. The contact page explains which mailbox reads what.