Last updated August 16, 2026. Refract is the product at refractreports.com.
This page explains what we collect when you use Refract, why we collect it, and how to get it deleted. It applies to the website, the signed-in app, and emails we send you (verification, password reset, billing).
When you sign up we store your name, email, and a hashed password. We send a verification link to that email and, if you forget your password, a reset link. Those messages come from our business Gmail. We keep a session cookie so you stay signed in. We do not store your card number. Stripe does, and we only keep the Stripe customer / subscription ids we need to show plan status and open the billing portal.
You choose what to connect. Depending on that, we store:
Each store lives in its own warehouse. We do not mix one merchant’s orders with another’s. Credentials are encrypted at rest. We do not sell your data, and we do not use your store data to train public models.
To run the product: sign you in, sync the sources you connected, build your profit report, bill the plan you pick, send auth and (when billing is live) receipt-related email, and keep the service working. Nightly jobs refresh connected stores. We look at logs (errors, health, sign-in) to fix outages, not to read your P&L.
Hosting is on DigitalOcean (app + Postgres). Auth and contact mail send from our business Gmail. Card payments are Stripe. Shopify, Meta, Google, ShipStation, and Gmail only see what you already have with them. We call their APIs with the credentials you pasted. We don’t sell lists to advertisers. We may share data if required by law, or with a contractor bound to keep it confidential (for example a host or email provider).
We use a session cookie to know you’re signed in. That’s it for the app. The marketing pages don’t run an ad pixel. Stripe’s checkout and customer portal are on Stripe’s domain and follow Stripe’s cookies.
We keep account and warehouse data while the account is open. If you cancel, access lasts through the period you already paid; after that we can delete the warehouse and account. Ask from the contact form using the same email you signed up with. We will remove the warehouse, encrypted credentials, and login, except records we must keep for taxes or dispute (for example Stripe invoices, which Stripe retains).
Passwords are hashed. API tokens are encrypted. The dashboard is only served to the signed-in organization. No method is perfect. If we learn of a breach that affects you, we will email the account address.
Refract is for business operators. It is not directed at children under 16.
We don’t publish an inbox on this site (scrapers harvest those). Use the contact form, or reply to a Refract message if you already have an account.