Privacy Policy

Last updated: July 6, 2026

1. Data We Collect

Sentri collects the following data to provide bot protection and checkout fraud prevention:

  • Visitor data: IP addresses, user agents, browser fingerprints (canvas hash), device type, screen dimensions, language settings
  • Checkout data: Email addresses, names, phone numbers, order values (when checkout protection is enabled)
  • Network data: Country, region, city, ISP, VPN/Tor/datacenter classification
  • Bot detection signals: WebDriver detection, headless browser detection, automation indicators

2. How We Use Data

All collected data is used exclusively to:

  • Score visitor traffic and identify automated or malicious bots
  • Block fraudulent checkout attempts
  • Generate security analytics and reports for store owners
  • Provide real-time threat alerts

We do not sell, share, or transfer data to third parties for advertising or marketing purposes.

3. Data Retention

  • Bot events and threat signals: Automatically purged after 30 days
  • GraphQL monitoring queries: Automatically purged after 24 hours
  • Expired sessions: Cleaned up hourly
  • On uninstall: All shop data is permanently deleted immediately when the app is uninstalled
  • GDPR shop redact: All remaining data is permanently deleted 48 hours after uninstall via Shopify compliance webhook

4. Data Security

Sensitive credentials (SMTP passwords, API keys) are encrypted at rest using AES-256-GCM. All communication occurs over HTTPS. Session tokens are managed server-side via Shopify's OAuth framework — no authentication data is stored in browser localStorage or cookies.

5. GDPR & Data Subject Rights

Sentri supports Shopify's mandatory GDPR compliance webhooks:

  • Customer data request: We provide all data held about a customer upon request
  • Customer data erasure: We anonymize or delete all customer PII upon request
  • Shop data erasure: We delete all shop data upon uninstall or redact request

Store owners can contact us to request data access, correction, or deletion at any time.

6. Third-Party Services

Sentri may integrate with the following third-party services when enabled by the store owner:

  • Cloudflare Turnstile: For CAPTCHA challenge verification (IP sent to Cloudflare)
  • AbuseIPDB: For IP reputation lookups (IP sent to AbuseIPDB, requires merchant API key)
  • ipapi.is: For IP reputation, VPN/proxy/Tor and geo classification (IP address sent to ipapi.is)
  • proxycheck.io: For VPN/proxy/Tor verification when a key is configured (IP address sent to proxycheck.io)

7. Collaborative Threat Network

Sentri offers an opt-in Collaborative Threat Network. When enabled:

  • Anonymized threat signals (pepper-hashed IP and browser-fingerprint hashes, signal type, score) are shared with other participating stores.
  • No personally identifiable information (PII) like names, emails, or phone numbers is ever shared.
  • Sharing is strictly opt-in and can be enabled or disabled at any time under Settings. Choosing not to participate does not affect core protection features.

8. Contact

For privacy inquiries, data requests, or concerns, please contact us through the Shopify App Store listing or the Help & Support page within the app.