Document information
- Owner / operator
- Mugpire, LLC, a Wyoming limited liability company, doing business as OppAction
- Document status
- Effective
- Effective date
- September 7, 2026
- Intended audience
- Business customers, authorized users, website visitors, and relevant individuals
- Primary service
- Shopify-focused ecommerce optimization and AI-assisted listing workflows
- Privacy URL
- View the published Privacy Policy
Introduction
This Privacy Policy explains how Mugpire, LLC, a Wyoming limited liability company doing business as OppAction ("OppAction," "we," "our," or "us"), collects, uses, discloses, and retains Personal Information in connection with the Services. "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual, subject to applicable-law exclusions.
This Policy is a notice of privacy practices, not a contractual warranty, and does not require anyone to waive a non-waivable privacy right. The Terms of Service govern use of the Services. If documents conflict, the order of precedence stated in the Terms applies: (a) a separately signed enterprise agreement; (b) the applicable Order; (c) an applicable Data Processing Addendum ("DPA"); (d) an accepted Feature Addendum; (e) the Terms; and (f) incorporated policies. Each document controls only within its stated scope, and this Policy does not expand OppAction’s contractual obligations unless the Terms expressly state otherwise.
1. Scope and Roles
1.1 Where this Policy applies
This Policy applies to OppAction's website, accounts, Shopify app, AI-assisted listing and catalog workflows, support channels, and other Services that link to it. It does not govern a third party's independent practices, including Shopify's own processing or a merchant's storefront practices.
1.2 OppAction as controller and processor
OppAction acts as a controller (or equivalent business) when it determines the purposes and means of processing website, account, billing, security, support, business-contact, and similar operational information. OppAction acts as a processor, service provider, or contractor when it processes Customer Personal Data in store, catalog, customer, or other Customer Content on the Customer’s documented instructions to provide the Services.
For processor data, the Customer is responsible for its privacy notice, lawful basis, individual requests, and instructions. Individuals whose information appears in a merchant’s store should ordinarily direct requests to that merchant. OppAction will assist the Customer as required by law and the applicable DPA.
The OppAction DPA applies automatically when OppAction processes Customer Personal Data on the Customer’s behalf and the Customer affirmatively accepts Terms or an Order that identifies and makes the DPA available. A countersigned copy is available upon request. The DPA is available at https://oppaction.com/dpa.
1.3 Business service
OppAction is intended for businesses and authorized business users who are at least 18 years old. Some comprehensive state privacy laws exclude information processed solely in a commercial or employment context; other laws may still apply.
2. Information We Collect
The table below maps the principal categories of Personal Information to representative examples, sources, purposes, and recipient categories. Actual collection depends on the features used and permissions granted.
Category | Examples | Sources | Purposes | Service-provider / recipient categories |
|---|---|---|---|---|
Identifiers, business-contact, and professional or employment-related information | Name, business name, email, phone, username, account identifiers, job title or role, Account authority, and Shopify staff identity | You; account owner; Shopify or authentication provider | Create and administer accounts; authenticate; communicate; provide support | Railway; Cloudflare; Resend; Microsoft 365; authentication and security providers |
Commercial, store, and connected-service data | Shop name and contact email; product IDs, titles, handles, HTML descriptions, tags, types, vendors, SEO fields, images and alt text; variant IDs, SKUs and titles; collection IDs, titles and handles; order IDs/dates, product IDs, quantities, amounts and currency | You; your Shopify store; authorized connected services | Provide requested analysis, drafting, scoring, opportunity reporting, workflow, synchronization, write-back, and support functions | Shopify; Railway; Cloudflare; OpenAI; communications providers, as applicable |
Customer content, AI interaction, and electronic or visual information | Prompts, instructions, uploaded content, eligible product-image URLs and alt text, generated drafts, edits, feedback, and workflow history | You and authorized users; service interactions | Generate and refine outputs; maintain context; quality, safety, support, and troubleshooting | OpenAI; Railway; Cloudflare; authorized support providers |
Transaction data | Plan, charge approval, subscription status, invoices, credits, limited billing metadata | You; Shopify or another billing processor | Process and reconcile charges; manage subscriptions; prevent fraud; maintain records | Shopify; Railway; accounting and fraud-prevention providers |
Internet, device, and usage data | IP address, device/browser data, sessions, pages/events, timestamps, Railway request/DNS/application logs, diagnostics, and performance data | Automatically from browsers, devices, app, and infrastructure | Operate, secure, debug, measure, and improve the Services; detect abuse | Cloudflare; Railway; hosting and security providers |
Communications and support data | Support requests, emails, survey responses, feedback, and related records | You and authorized users | Respond, troubleshoot, improve support and Services, and maintain business records | Resend; Microsoft 365; Railway; Cloudflare |
Inferences and derived data | Scores, classifications, recommendations, usage patterns, and de-identified or aggregated metrics | Derived from the categories above | Provide requested functionality; improve reliability, safety, and product performance | OpenAI; Railway; authorized service providers |
OppAction does not intentionally support or authorize the processing of health information, full payment-card data, government identifiers, biometric data, precise geolocation, children’s Personal Information, GDPR special-category data, or comparable sensitive or regulated data. These categories are prohibited in ordinary product, catalog, prompt, and support inputs. If OppAction accidentally receives restricted data, it will apply its containment, deletion, and incident-response procedures. No exception is permitted unless an authorized OppAction representative approves it in a signed Order or supplemental agreement that documents the lawful basis, security requirements, and supported technical workflow.
3. How We Use Information
OppAction uses Personal Information to:
- provide, personalize, maintain, and support the Services and requested Shopify workflows;
- authenticate users, administer accounts and subscriptions, and communicate service information;
- generate, evaluate, and refine AI-assisted drafts, scores, recommendations, and workflow results;
- monitor performance, troubleshoot errors, maintain logs, and improve safety, reliability, and usability;
- protect accounts and systems, detect fraud or abuse, and investigate security incidents;
- process and reconcile charges, credits, taxes, and subscription status through billing providers;
- comply with law, enforce agreements, respond to legal process, and establish or defend claims; and
- create and use aggregated or de-identified data as described in Section 6.
OppAction will not use controller data for a materially different, incompatible purpose without any additional notice, choice, or consent required by law. Personal Information processed on a Customer’s behalf is used only as permitted by the Agreement, the applicable DPA, the Customer’s documented instructions, and applicable data-protection law.
3.1 Lawful bases for controller processing
- Contract or steps requested before contract: to create and administer accounts, provide requested Services, process subscriptions, communicate about the service, and provide support.
- Legitimate interests: to secure and improve the Services, prevent fraud and abuse, maintain business records, understand service performance, and protect OppAction, Customers, users, and third parties, balanced against applicable individual rights.
- Legal obligation: to comply with tax, accounting, sanctions, legal-process, security, and other binding requirements.
- Consent: where OppAction specifically requests consent for an optional activity; consent may be withdrawn prospectively using the method provided when consent is requested.
4. How We Disclose Information
OppAction may disclose Personal Information:
- to service providers and processors that support hosting, infrastructure, AI functionality, authentication, analytics, observability, communications, customer support, security, billing, accounting, and legal compliance;
- to Shopify or another connected service at the Customer's direction or as necessary to provide an enabled integration;
- within an organization to its account owner, administrators, and authorized users according to account permissions;
- to advisers, auditors, insurers, financing sources, and transaction counterparties subject to appropriate confidentiality protections;
- to regulators, courts, law enforcement, or other parties when reasonably necessary to comply with law, protect rights or safety, investigate misconduct, or respond to legal process; and
- in connection with a merger, financing, acquisition, reorganization, bankruptcy, or transfer of all or part of the business, subject to applicable notice and choice requirements.
Service providers are authorized to process Personal Information only for contracted services and related lawful purposes, subject to contractual restrictions appropriate to their role. Some connected services act as independent controllers for their own purposes; their notices govern that independent processing.
4.1 Current production provider categories
As of this Policy’s revision date, OppAction’s active direct subprocessors are Railway Corporation for application hosting, PostgreSQL, logs, jobs, and backups; OpenAI OpCo, LLC or OpenAI Ireland Ltd., as applicable, for AI-assisted analysis and generation; Plus Five Five, Inc. (Resend) for transactional, support, privacy, security, and operational email; Microsoft Corporation for Microsoft 365 mailboxes; and Cloudflare, Inc. for global reverse-proxy, TLS, traffic-delivery, and security services. Shopify is the merchant-selected platform and source for OAuth, billing, staff identity, webhooks, and store data; it is not an OppAction-appointed subprocessor for the merchant’s independent Shopify relationship. The current register controls if this summary becomes outdated.
OppAction maintains its current subprocessor register at https://oppaction.com/subprocessors. OppAction publishes material changes there and provides advance notice to the Customer’s contractual or account contact when required by the DPA or applicable law. The register identifies legal entities, services, purposes, high-level data categories, locations, transfer safeguards, effective dates, and historical changes.
5. Shopify, Merchants, and Store Data
When a merchant installs or connects OppAction, Shopify provides store and account information allowed by merchant-approved scopes. Shopify is the only production-ready Marketplace connector unless OppAction expressly identifies another connector as production-ready.
Depending on enabled functions, OppAction retrieves product, variant, collection, store, limited order, and Shopify staff-identity fields. It may write merchant-approved product titles, descriptions, tags, SEO fields, and image alt text back to Shopify. Limited order processing uses order and product identifiers, dates, quantities, amounts, and currency and is not designed to retrieve buyer names, addresses, phone numbers, or customer email addresses. Shopify may nevertheless classify limited order data as protected customer data.
Merchants determine what store information is sent to OppAction and remain responsible for notices and lawful processing concerning their customers, personnel, and catalog contributors. OppAction does not have a direct relationship with most merchant end customers and generally cannot independently verify or fulfill their requests without the merchant's involvement.
Uninstalling OppAction revokes application access, disconnects the Shopify authorization, ends active sessions and pending application work, and stops future scheduled processing. Uninstalling does not necessarily erase every record immediately. OppAction processes deletion and redaction through verified Shopify events, verified Customer requests, legal requirements, and the retention practices in Section 9.
When OppAction receives a valid Shopify customer-data request, customer-redaction request, shop-redaction request, or app-uninstall event, it authenticates and processes the event through its documented privacy workflow and records the resulting action.
6. AI Systems, Providers, and Model Training
6.1 Providing AI-assisted features
OppAction uses OpenAI’s API for AI-assisted analysis, generation, scoring, and refinement. Data sent to OpenAI may include text-based product or catalog content, instructions, metadata, permitted store context, previous suggestions and scores, Shopify-hosted product-image URLs, and image alt text. OppAction does not currently send merchant-uploaded documents, support attachments, or other general file uploads to OpenAI. Generated results and relevant recommendations are returned to and may be stored by OppAction.
OppAction does not download, cache, or separately store Shopify product-image files for OpenAI processing. It transmits the existing Shopify-hosted image URL as a temporary image input, and OpenAI may retrieve the image to perform the requested analysis. OppAction retains relevant optimization results and image-alt-text recommendations, but not a separate copy of the source image file.
6.2 Training restriction
OppAction does not use non-public Customer Content to train a generalized model made available to other customers or the public unless the Customer expressly opts in. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer affirmatively opts in to data sharing. OppAction does not represent that OpenAI processing is Zero Data Retention.
6.3 Provider retention and controls
OppAction’s production OpenAI project uses Global processing residency and OpenAI’s default abuse-monitoring retention. OppAction sends Responses requests with application-state storage disabled (store: false) and background mode disabled. Store: false prevents Responses application-state storage but does not disable OpenAI’s separate abuse-monitoring retention, which may retain limited API content for up to 30 days under default controls. Exceptional safety retention may apply to flagged image inputs. OppAction has not documented approval for Zero Data Retention or Modified Abuse Monitoring.
6.4 Product improvement and de-identified data
OppAction may use Usage Data, human feedback, evaluations, and De-identified Data to improve safety, reliability, workflows, and product functionality, provided that use does not disclose Customer Content or identify the Customer. OppAction may use aggregated and De-identified Data for lawful analytics, benchmarking, security, research, and product improvement. OppAction takes reasonable measures designed to prevent that data from being associated with a Customer or identifiable individual, maintains and uses it in de-identified form, and does not attempt to reidentify it except where law permits testing safeguards, investigating abuse or security events, or complying with law.
7. Cookies and Similar Technologies
The authenticated OppAction application uses the essential technologies listed below. OppAction does not currently use an advertising pixel, remarketing tool, session-replay product, customer analytics SDK, or third-party support widget in the application. Google Fonts has been removed. Resend open tracking and click tracking are disabled for OppAction email.
Technology | Provider | Purpose | Duration | Status / gating |
|---|---|---|---|---|
__oppaction_session | OppAction | Authenticated session | 12-hour maximum; 60-minute production idle timeout | Essential |
__oppaction_csrf | OppAction | Cross-site request-forgery protection | 24 hours | Essential |
__oppaction_shopify_oauth | OppAction | Shopify OAuth state validation | 10 minutes by default | Essential |
__nicheforge_provider_admin | OppAction | Internal administrator session | 8-hour maximum; 120-minute idle timeout | Essential internal administration |
__nicheforge_session | OppAction | Legacy session compatibility; no current issuance found and cleared during migration | Not currently issued; existing cookie cleared during migration | Legacy compatibility only |
Essential cookies support authentication, security, OAuth, and internal administration and are not consent-gated where applicable law permits. Browser controls may block them, but doing so can prevent sign-in or core functions. OppAction will not activate a future non-essential tracking technology in a jurisdiction requiring prior consent until valid consent is obtained.
8. Sale, Sharing, Targeted Advertising, and Opt-Out Signals
8.1 Current position
OppAction does not sell Personal Information for money, knowingly sell or share Personal Information for cross-context behavioral advertising, or use Personal Information for targeted advertising as those terms are defined by applicable comprehensive state privacy laws.
8.2 Opt-out preference signals
Where legally required, OppAction will treat a recognized browser-based universal opt-out preference signal, such as Global Privacy Control, as a request to opt out of sale, sharing, or targeted advertising for the browser or device that sends the signal. A user may enable such a signal through a supporting browser or extension. The signal applies to the browser or device that sends it and, when the user is signed in and applicable law requires, may be associated with the Account. If OppAction does not engage in the relevant processing, the signal will not change other necessary or permitted processing.
If OppAction begins selling or sharing Personal Information or using it for targeted advertising, it will update this Policy, provide any required conspicuous opt-out link or mechanism outside the Policy, and honor applicable preference signals before beginning the activity.
9. Data Retention and Account Closure
OppAction retains Personal Information only for as long as reasonably necessary for the disclosed purpose, taking into account account status, Customer instructions, feature requirements, record type, volume and sensitivity, security needs, provider schedules, legal obligations, limitation periods, disputes, and applicable agreements. Retention is not determined solely in OppAction’s discretion, and a deletion request is subject to applicable legal, security, backup, fraud-prevention, and dispute-preservation exceptions.
Data group | Retention approach |
|---|---|
Account, subscription, and transaction records (identifiers, business-contact/professional information, commercial and transaction data, and related communications) | For the account or subscription relationship and afterward as reasonably needed for accounting, tax, fraud prevention, disputes, and legal compliance. |
Customer Content in active systems (store/catalog data, AI interaction data, electronic or visual information, communications, and inferences) | Following termination, a verified deletion request, or a Shopify redaction event, access is disabled and deletion or anonymization begins under applicable law, Shopify requirements, implemented workflows, and any applicable DPA. |
Secure backups (the same categories present in backed-up account records and Customer Content) | Railway currently provides PITR/archive storage associated with production. Published Railway materials describe roughly four weeks of PITR WAL history and deletion of Pro plan volume data 90 days after cancellation. These statements do not promise that every protected copy is finally overwritten within 90 days; provider terms and schedules govern residual copies. |
Railway logs and diagnostics (Internet, device, session, usage, security, and operational data) | Production Railway Pro logs are retained under the active provider configuration and published schedule; current operational records document a 30-day log period. Logs may include IP addresses and operational metadata. |
OpenAI API data (eligible store/catalog content, AI interaction data, product-image URLs, and generated inferences or outputs) | Responses application-state storage is disabled with store: false, but OpenAI default abuse-monitoring retention may retain limited API content for up to 30 days. Exceptional safety retention may apply to flagged image inputs. No Zero Data Retention representation is made. |
Support and legal records (identifiers, business-contact information, communications, transaction data, and security or legal records) | Support, privacy, legal, security, and billing communications may be retained in Resend and Microsoft 365 for as long as reasonably necessary to address the matter, fulfill requests, and maintain required business or legal records. Verified deletion requests use documented vendor-specific workflows. |
De-identified and aggregated data | May be retained while it remains de-identified or aggregated and useful for lawful analytics, security, research, or product improvement, subject to commitments not to reidentify except as stated in this Policy. |
OppAction responds to verified access, portability, deletion, and Shopify privacy requests as required by law, the applicable DPA, and implemented workflows. Available product features may permit direct export of particular records, but OppAction does not promise a universal post-termination export package or fixed export window unless an Order or DPA expressly provides one.
10. Security
OppAction maintains administrative, technical, and organizational safeguards designed for the nature of the information and risks involved. Current measures include access restrictions, multi-factor authentication for known human production-access accounts where supported, provider-managed encryption in transit and at rest, scoped credential storage, logging and audit records, vulnerability scanning with Semgrep, security patching, documented recovery testing, and incident-response procedures. No system is completely secure, and these safeguards do not guarantee that an incident will never occur.
If OppAction confirms a Personal Data Breach, it will investigate, contain, document, and provide notice to the affected Customer without undue delay when required by an applicable DPA, and to individuals, regulators, or others when and as required by applicable law or contract. Notification timing depends on the applicable law, contract, geography, data, harm, Shopify obligations, and provider terms; OppAction does not promise a universal fixed-hour notification deadline.
11. U.S. State Privacy Rights
Subject to residence, context, legal thresholds, effective dates, and exceptions, an individual may have rights to confirm processing; access, correct, delete, or obtain a portable copy of Personal Information; obtain information about certain third-party disclosures; opt out of sale, sharing, targeted advertising, qualifying profiling, or qualifying automated decisionmaking technology (ADMT); access information about qualifying ADMT; limit certain uses of sensitive Personal Information; withdraw consent; and appeal a denied request or qualifying significant decision. OppAction will not discriminate or retaliate for exercising a privacy right.
11.1 Making a request
Submit a request or appeal to privacy@oppaction.com or legal@oppaction.com with the subject line "Privacy Request" or "Privacy Appeal." Describe the right, state or country of residence, relationship to OppAction, account email if applicable, and information reasonably necessary to locate relevant records. Do not email passwords, full payment-card numbers, government identifiers, or unnecessary sensitive data.
11.2 Verification, agents, and appeals
OppAction may verify identity, account association, residency, and authority using information proportionate to the request's sensitivity. Authorized agents may submit requests where permitted, subject to proof of authority and direct verification when allowed. OppAction will respond and, where applicable, decide appeals within legally required periods. If an appeal is denied, OppAction will provide any regulator-contact information required by the applicable law.
11.3 Processor data
If OppAction processes information only for a merchant or other customer, it may direct the requester to that controller and assist the controller. OppAction may deny or limit a request only as permitted by law and will explain the basis when required.
12. California Notice
This Section supplements the Policy for California residents and uses terms defined by the California Consumer Privacy Act, as amended ("CCPA").
12.1 Categories collected and disclosed
During the preceding 12 months, OppAction may have collected the categories described in Section 2, including identifiers; commercial information; Internet or other electronic-network activity; approximate geolocation inferred from IP address; professional or employment-related information; audio, electronic, visual, or similar information included in submitted content; and inferences. OppAction’s sources and specific business or commercial purposes are mapped in Section 2. For each collected category, OppAction may have disclosed that category to the service-provider or recipient categories shown in the corresponding row for the stated business purposes. Relevant categories may also have been disclosed to advisers, auditors, insurers, transaction counterparties, regulators, courts, or law enforcement for the purposes described in Section 4. OppAction did not sell or share any category for cross-context behavioral advertising during the preceding 12 months.
12.2 Sale, sharing, and sensitive Personal Information
OppAction has not sold or shared the categories in Section 2 for cross-context behavioral advertising during the preceding 12 months and has no actual knowledge that it sells or shares Personal Information of consumers under 16. OppAction does not use or disclose sensitive Personal Information to infer characteristics or beyond purposes permitted without a right to limit under the CCPA.
12.3 California rights and requests
California residents may request to know, access, correct, or delete Personal Information; opt out of sale or sharing; limit qualifying uses or disclosures of sensitive Personal Information; and receive equal service and price. Request methods are described in Section 11. OppAction operates online and maintains a direct relationship with relevant account users, so the designated email methods are used for these requests unless applicable law requires an additional method.
12.4 Notice at collection
Section 2 identifies each category collected and its purposes of use; the retention table in Section 9 maps those categories to a retention approach; and Section 8 states OppAction’s sale and sharing position. OppAction provides a timely direct link to this notice-at-collection information at or before relevant online collection points and supplies any additional notice required for a materially different use.
13. International Processing
OppAction is based in the United States. OppAction and its providers process Personal Information in the United States and other documented locations, including through globally routed services. Railway’s primary application and database processing is in Virginia, with current PITR/archive storage in California; OpenAI’s production project uses Global residency; Cloudflare uses its global network; and authorized support and onward subprocessors may involve additional locations listed in the subprocessor register.
Where the EEA, UK, or Swiss transfer rules apply, OppAction uses an available lawful mechanism such as an adequacy decision or framework, the European Commission Standard Contractual Clauses, the UK International Data Transfer Addendum, Swiss adaptations, and appropriate supplementary safeguards. Customers may request information about applicable safeguards through the contacts in Section 16.
Where OppAction acts as controller under applicable EEA, UK, or Swiss law, individuals may have rights to access, correct, erase, restrict, object to, or port Personal Information; withdraw consent prospectively; and complain to a competent supervisory authority. In particular, an individual may object to controller processing based on legitimate interests. OppAction does not currently use controller Personal Information in ADMT that makes or substantially replaces a human decision producing legal or similarly significant effects about an individual. If that practice changes, OppAction will provide any pre-use notice, choice, access, or appeal required by applicable law before the change applies.
14. Children and Restricted Data
The Services are offered only to business users age 18 or older and are not directed to children. OppAction does not knowingly collect children’s Personal Information through the Services. If it learns that restricted children’s information was received, it will apply its containment and deletion procedures, subject to law.
The restricted-data prohibition in Section 2 does not eliminate duties for information OppAction actually processes. It defines authorized use and requires accidental receipt to be handled through documented containment, deletion, and incident-response procedures.
15. Changes to This Policy
OppAction may update this Policy prospectively to reflect changes in law, providers, features, or practices. The revised Policy will identify its revision or effective date. OppAction will provide additional notice and obtain affirmative acceptance or consent when required for a material change, including where the Terms or DPA require reacceptance. Passive publication alone does not override a legal or contractual requirement for notice, acceptance, or consent.
16. Contact and Requests
Mugpire, LLC d/b/a OppAction
PO Box 2869, Jackson, Wyoming 83001
Privacy requests and appeals: privacy@oppaction.com or legal@oppaction.com
Website: OppAction website
DPA and processor questions may be sent to privacy@oppaction.com. Security reports should be sent to security@oppaction.com. OppAction maintains its DPA and current subprocessor register at the URLs stated in Sections 1 and 4.