Privacy Policy
Effective July 16, 2026
Serial Trail is a unit-level serial number application operated by Metigro (“Metigro”, “we”, “us”). This policy describes the data processed when a merchant installs or uses Serial Trail.
Data we process
We process merchant account and store configuration needed to authenticate the app, provide support, manage billing, and operate commerce integrations. The Serial Trail domain stores serial units, pools, product and variant references, SKUs and display titles, order, line and fulfillment references, lifecycle events, import and generation audit records, fulfillment queue rows, stock snapshots, and reconciliation findings.
When registration or recall features are used, we also process the buyer contact and registration information submitted by the buyer, supplied by the merchant, or lawfully retrieved from the commerce platform. This may include a name, email address, phone number, product registration answers, proof-of-purchase evidence, and recall contact records. We do not collect payment-card details. Platform order identifiers are pseudonymous references and may still be customer-linked data under applicable law.
How we use data
We use data to provide serial registration and lifecycle tracking, buyer email, recall outreach, fulfillment assignment, platform order metafields, scanning, reconciliation, exports, billing, security, reliability monitoring, and support. We do not sell personal data or use merchant data for third-party advertising.
Merchant-configured integrations
A merchant may configure Serial Trail to send registration and recall event payloads to its HTTPS webhook endpoints. Registration webhook payloads may include the registered owner's email address; recall webhook payloads do not include owner contact details. Webhook signing secrets are encrypted at rest and shown only when created or rotated.
A merchant may also connect its Klaviyo account. Serial Trail sends only enabled registration events for registrations that include marketing consent. The profile email is encrypted while a dispatch is pending; recall and safety events are never sent to Klaviyo. OAuth credentials are encrypted at rest. Data already accepted by a merchant-controlled webhook or Klaviyo is then governed by the merchant's relationship with that recipient and cannot be remotely deleted by Serial Trail.
Service providers
We use Shopify for the commerce platform and app billing, infrastructure and database providers for hosting, Redis-compatible queue/cache infrastructure, and Resend for service email. When a merchant enables it, Klaviyo receives consented registration events as the merchant's selected integration provider. Providers process only the data required for their role under their own contractual and security obligations.
Export, retention, and deletion
Merchants can export units, unit events, and pools from Account settings on every plan. Demo data is excluded.
When the app is uninstalled, active integration credentials are cleared and Serial Trail domain data is retained for up to 30 days to support reinstall recovery. After that window, a fenced purge permanently deletes the domain data and uploaded import files. A Shopify shop/redact request triggers earlier deletion when the store remains uninstalled. Reinstalling starts a new install cycle and prevents a late request for the old cycle from deleting active data.
A valid customers/redact request removes matching registration and buyer-mail personal fields, order, line, and fulfillment references, and related transient queue and reconciliation data. Pending matching webhook deliveries are suppressed and pending Klaviyo dispatch data is redacted. Compliance requests are deduplicated and audited without logging buyer identity. Merchants remain responsible for erasure requests covering copies already delivered to their own webhook systems or Klaviyo account.
Security and access
Embedded requests use authenticated platform sessions, mandatory webhooks are HMAC-verified, merchant queries are tenant-scoped, and commerce operations pass through platform-agnostic capability interfaces. No system can be guaranteed perfectly secure; contact us immediately if you suspect unauthorized access.
Your choices
Merchants may export data, uninstall the app, or contact us about access, correction, deletion, or privacy questions. Shopify customers should generally submit requests through the merchant that controls their order.
Contact
Email [email protected]. We may update this policy as the product or legal requirements change; the effective date above identifies the current version.