Reporting by WIP

Privacy policy

Last updated 21 August 2026

Reporting by WIP is a reporting app for Shopify stores, built and operated by Work In Progress. It reads a merchant’s own commerce and marketing data, and turns it into a monthly performance report for that merchant. This policy explains what the app stores, why, who else sees it, and how to have it deleted.

It covers the Shopify app and the reports it produces. Where the app processes data belonging to a merchant’s customers, the merchant is the data controller and Work In Progress is a processor acting on their instructions.

What the app stores

About the store

The store’s myshopify domain, display name, timezone and currency, the date it installed the app, its subscription tier, and which data sources it has connected or skipped. Timezone matters beyond bookkeeping: month boundaries are cut in it, which is what makes the figures agree with the merchant’s own Shopify dashboard.

Credentials for connected sources

An access token for the Shopify Admin API, issued when the app is installed. If the merchant connects Google Analytics or Search Console, the email address of the Google account they authorised and a refresh token for it. If they connect Klaviyo, an API key. Google refresh tokens and Klaviyo API keys are encrypted before they are stored.

Commerce and marketing data

Aggregated figures used to build the report: revenue, orders, average order value, products sold, traffic sources and channel performance, email and campaign performance, and search impressions and clicks. These are totals and time series, not individual records.

Customer-level data — specifically

One report section ranks a store’s highest-spending customers. For that, and only that, the app stores up to twenty-five rows per report, each containing a Shopify customer ID number, that customer’s total spend, and their order count.

It does not store customers’ names, email addresses, postal addresses, phone numbers, order contents, or any payment information. The customer ID is Shopify’s own numeric identifier, which is meaningless outside the merchant’s own admin.

Assistant conversations

On plans that include the report assistant, questions asked of it and the answers given are stored against the store, so the merchant and the agency can revisit them. The question and the relevant report figures are sent to Anthropic to generate the answer.

What it is used for

Building and serving the merchant’s reports, keeping their connected sources authorised, answering their questions about their own figures, and billing them for the tier they chose.

It is not used for advertising, not sold, and not shared with other merchants. Data from one store is never combined with another’s, and never used to build any cross-merchant benchmark or model.

Who else processes it

The app relies on these services, and on no others:

How long it is kept, and how to have it erased

Reports are kept while the app is installed, so a merchant can look back across months and compare like for like.

Uninstalling

When a store uninstalls, the app marks it uninstalled and stops processing. Shopify then sends an erasure request forty-eight hours later, at which point everything held for that store is deleted — every report, every connection setting, and every credential. That step is deliberate and is not reversible.

An individual customer

When a merchant requests erasure for one of their customers, Shopify notifies the app and that customer’s row is removed from every stored report and every live window. When a merchant requests a copy of what is held about a customer, the app returns the months, spend and order counts it holds — which, as above, is all it holds.

Merchants can also make either request directly, using the contact details below, without going through Shopify.

Security

Report data is held in private, access-controlled storage and is not publicly listable. Google refresh tokens and Klaviyo API keys are encrypted at rest. Reports shared outside the Shopify admin are served behind a secret link and a password.

No system is perfect, and this one is small enough to say so plainly: if something goes wrong that affects a merchant’s data, we will tell the merchants affected rather than wait to be asked.

Contact

For any question about this policy, or to make a data request, write to michael@wip.fyi.

Work In Progress

Changes

When the app changes what it collects, this page changes at the same time and the date at the top moves. Material changes are told to installed merchants directly rather than left here to be discovered.