Privacy Policy

How Cratewake handles your store and customer data.

Last updated: 2026-08-18

Introduction

Cratewake is a multichannel message-triage tool for solo merchants. Today its job is narrow: read the customer email address off each new order as it arrives in your connected channels, use it to match incoming customer messages (WISMO questions, return requests, complaints) to the order they belong to, and surface those conversations next to the order so a single operator can reply quickly.

What we collect

Cratewake today collects two narrow categories of data, and nothing else about your customers:

The customer email address from each order

Cratewake connects to your stores via each marketplace’s developer APIs, and you authorize Cratewake at each step. The only buyer field Cratewake currently reads — on any connected channel — is the customer email address associated with the order (Shopify exposes this through the OAuth-scoped read_orders permission; equivalent scopes apply on other channels). We store it alongside the order ID so that when a buyer emails you about that order, Cratewake can match the message to the correct order for triage.

Account data for the Cratewake user who installed the app

To operate the app, Cratewake stores the email address of the merchant or operator who installed it, along with the login credentials and session data needed to keep them signed in.

No other customer personal data is currently collected through Cratewake. We do not read the buyer’s name, phone number, shipping or billing address, payment information, or browsing history. If Cratewake later expands the data it reads from any connected channel, this policy will be updated to match.

Why we collect it

  • To identify the order behind an incoming customer message.
  • To keep a single operator signed into Cratewake.
  • To deliver transactional notifications from Cratewake to that operator.

How we use it

  • To surface buyer messages next to the matching order in the Cratewake inbox.
  • To route WISMO, return, and complaint messages based on the best-known template policy.
  • To keep the operator signed in and send transactional notifications.

Cratewake does not run advertising, does not sell data, and does not use the content of buyer messages to train any model.

Who we share it with

Today the customer email data Cratewake reads from your connected channels is not shared with any third party. Cratewake shares data only with the minimum subprocessor set required to operate the app:

  • Hosting and infrastructure— the platform that stores your data at rest and serves the app.
  • Connected marketplaces— Cratewake calls each connected channel’s own API, under the OAuth scope you granted on that channel, to read orders and surface the buyer messages that arrive on those orders.

No payment processor is wired up to Cratewake at this time, and no third-party advertising, analytics, or model-training partner receives customer data today.

Your rights

You (or a buyer on your behalf) can, at any time:

  • Revoke any of Cratewake’s channel connections — either from that channel’s own app-installation page, or from the disconnect control inside Cratewake.
  • Ask what data Cratewake holds for a given order or for your account.
  • Request deletion of that data.

Send any of these requests to the contact address below; we’ll acknowledge within a few business days and complete the request within thirty days.

Changes to this policy

As Cratewake expands the data it reads from any connected channel — for example, new channels, additional customer fields on existing channels, or new buyer-side data — this policy will be updated to match what the product actually does. The Last updated date at the top will be bumped on each change, and material changes will be noted to active merchants before they take effect.

Contact

Questions, requests, or concerns about privacy — write to cratewake-n4tra9@polsia.app.