Coverly

Privacy Policy

Last updated 10 August 2026 · Coverly is published by Found.

The short version. Coverly stores your store's settings, a list of the orders that bought package protection, and any claims your buyers file. To gate a claim it stores the buyer's name and the email address on that order — because that email is the only thing standing between a real buyer and a stranger filing in their name. It never sees card details. Everything is scoped to your store, and nothing is ever sold or shared for advertising.

Who this covers

This policy covers Coverly (the "app"), an application for OpoShop stores published by Found. It applies to the merchant who installs Coverly and to the shoppers who use the protection toggle or the claim page on that merchant's storefront.

Merchant store data

When you install Coverly, OpoShop's OAuth grants it a scoped access token for your store. Coverly uses it to do four things and nothing else:

Your access token is stored encrypted at rest in Coverly's own database and is never shared, logged in full, or exposed through the API.

Buyer data

For every order that bought protection, Coverly stores the order number and date, the items and their values, what was paid for protection, and the buyer's name and email address as they appear on that order. The email is stored for one reason: filing a claim requires it to match exactly, so that somebody who merely guesses an order number cannot file in a buyer's name.

If a buyer files a claim, Coverly also stores what they wrote about what went wrong, which items they said were affected, and the status history of that claim.

Coverly does not collect buyer postal addresses, phone numbers, IP addresses (beyond a short-lived, in-memory rate-limit counter that is never written to disk), or any tracking identifier. It does not build profiles and does not follow shoppers across sites.

Payment data

Coverly never sees or stores card details. The protection fee is charged by your store through OpoShop's own checkout, as a normal line item. Coverly holds no card, no balance and no payout account, and there is no code path in the app that moves money in either direction.

Where data is stored

In Coverly's own MongoDB database, in a database used only by this app, with every record scoped to the store it belongs to. One merchant's stores are isolated from each other as well as from other merchants: each store install gets its own user record, and every query is scoped by store.

Analytics

Coverly sends product analytics to PostHog so we can see which features are used. Events are identified by an opaque store identifier (store_<uuid>) only. No personal data is ever sent — no buyer email, no buyer name, no claim text, no order contents.

Sharing

Coverly does not sell data and does not share it for advertising. Data is shared only with the infrastructure providers required to run the app (hosting, database, analytics as described above), and where the law requires it.

Retention and deletion

Protected orders and claims are kept while the app is installed, so that a buyer inside your claim window can still file and you keep a record of what you promised. Uninstalling pauses the store and stops all processing; your data is retained so a reinstall picks up where you left off. To have a store's data deleted permanently, email brandon@tryfound.io and it will be removed within 30 days.

Your rights

Merchants and their buyers may request access to, correction of, or deletion of personal data held by Coverly. Buyers should contact the store they bought from in the first instance, since the merchant is the controller of their order data; we will assist any merchant with such a request.

Changes

If this policy changes materially we will update this page and the date at the top. Your continued use of Coverly after a change means you accept the updated policy.

Contact

brandon@tryfound.io