Workbench

Privacy policy

Workbench for Shopify · Last updated 14 August 2026

The short version. Workbench records which stage an order is at. It stores the order number and the stage — not the customer's name, email, address or phone. Those are read from Shopify each time a page is shown and thrown away when the request ends.

The one thing we keep about a person is a do-not-email record, and that is stored as a one-way hash. We cannot read it, and neither could anyone who took our database.

Who we are

Workbench is operated by Mick O'Callaghan, trading as Workbench. You can reach us at support@workbenchorders.com.

If you are a shopper rather than a merchant: the shop you bought from decides how your order is handled. We process data on that shop's behalf, and you can contact either them or us.

What we store

For each order a merchant has moved through a stage, we store:

No customer name, email, address or phone number is stored against an order. The order number is not personal data on its own; the customer's details are read from Shopify each time a page is displayed and are discarded when the request ends.

We also store the merchant's own settings — their stage names, sender name and reply-to address — and the access token that lets the app read their orders.

The one exception: the do-not-email list

If an email address unsubscribes, hard-bounces, or is reported as spam, we record it so it is never emailed again.

That record is a one-way keyed hash, not the address. We can check whether a given address is on the list, but we cannot read the list or recover any address from it — and neither could anyone who obtained a copy of our database.

We keep these records for as long as the app operates. Deleting one would resume sending to somebody who asked us to stop, which is the opposite of what they requested.

What we do with customer email addresses

Email addresses reach us in two ways, and are used for one thing each.

We do not build profiles, track behaviour across sites, run advertising, or sell or share personal data with anyone for their own purposes.

Who else sees the data

Two services process data on our behalf:

That is the complete list. We add no analytics, advertising or tracking services to the app.

How long we keep things

Stage records last while the app is installed. When a merchant uninstalls, Shopify sends us a deletion request 48 hours later and we erase everything belonging to that shop — stage history, settings, sessions and order links.

Order details themselves are never retained, because they are never stored. The do-not-email hashes are kept indefinitely, as described above.

Your rights

You can ask what data we hold about you, ask for it to be corrected or erased, or object to how it is used. Because we act on a shop's behalf, the quickest route is usually to ask the shop; they can pass the request to us and Shopify has a built-in way to do so.

You can also write to us directly at support@workbenchorders.com.

The practical answer to most requests is short: we hold nothing about you against an order. The exception is a do-not-email record, which exists specifically so we do not contact you.

Security

The app can read orders. It cannot edit an order, change fulfilment, or write anything to a merchant's shop.

Data is encrypted at rest and in transit. Access to production systems is limited to the app's developer. Customer status pages require the order number and matching email together, and unsubscribe links are cryptographically signed so they cannot be used to affect anyone else's mail.

Changes

If this policy changes materially we will update the date at the top and, for changes that affect merchants, tell them in the app.