Privacy policy

Last updated 5 August 2026

Endcap is a Shopify app that audits product data. This policy explains exactly what it reads, what it stores, and what it never touches.

Who is responsible

Endcap is operated by Felix Francia, an individual established in Uruguay. There is no company behind it, which is worth saying plainly: you are contracting with a person, and that person is the data controller for everything described below.

Processing is governed by Ley N° 18.331, Ley de Protección de Datos Personales y Acción de Habeas Data, supervised by the Unidad Reguladora y de Control de Datos Personales (URCDP). The European Commission recognised Uruguay as providing an adequate level of data protection in 2012 by Decision 2012/484/EU.

That adequacy decision describes where the operator is established. It does not describe where your data is stored, which is the United States, on Railway. Both facts are set out in the third parties section below so that neither is read without the other.

What we do not collect

Endcap does not request, receive or store customer data of any kind. The app asks Shopify only for product permissions, so it has no technical ability to read customers, orders, carts, addresses or payment information, even if asked to.

This is why our responses to Shopify's customer data request and customer redaction webhooks confirm that no customer data exists to return or erase.

What we read

What we store

DataWhyKept for
Scan results and scoresTo show whether your catalog improved or regressedUntil uninstall
Your question setVisibility trends require identical questions between runsUntil uninstall
Visibility resultsTo chart share of voice over timeUntil uninstall
Applied fixes with previous valuesSo any bulk change can be undoneUntil uninstall
App usage eventsTo see where merchants drop from the ranking-check and upgrade flowUntil uninstall
Shopify session tokenTo authenticate API calls on your behalfUntil uninstall
Email address entered for a public scan reportTo deliver the report, record the request as a lead, and send product updates only when separately acceptedUntil you request deletion
Public store domain, report and connection identifierTo return the scan, prevent duplicate crawling and limit abuseCached in application memory for 15 minutes

Deletion

When you uninstall, Shopify notifies us and we delete your session immediately. Shopify then sends a shop redaction request, on receipt of which we erase every scan, question set, visibility run, usage event and fix history belonging to your store. You can also request deletion at any time by emailing [email protected].

Third parties

The processors below receive only the data needed for their role. None receives Shopify customer or order data.

What we never do

Your rights

Under Ley N° 18.331 you may ask what data is held about you, have inaccurate data corrected, and have it deleted. In practice the fastest route to deletion is uninstalling, which triggers the process described above without you having to ask anyone.

Requests go to [email protected] and are answered within one business day. If you are not satisfied with how a request was handled, you can complain to the Unidad Reguladora y de Control de Datos Personales (URCDP).

Changes to this policy

The date at the top of this page is the last time it changed. Material changes to what is collected or who receives it will be announced in the changelog rather than applied quietly.

Contact

Felix Francia, Uruguay. [email protected]. See also our terms of service.