Privacy Policy
Last updated 10 August 2026 · Coverly is published by Found.
The short version. Coverly stores your store's settings, a list of the orders that bought package protection, and any claims your buyers file. To gate a claim it stores the buyer's name and the email address on that order — because that email is the only thing standing between a real buyer and a stranger filing in their name. It never sees card details. Everything is scoped to your store, and nothing is ever sold or shared for advertising.
Who this covers
This policy covers Coverly (the "app"), an application for OpoShop stores published by Found. It applies to the merchant who installs Coverly and to the shoppers who use the protection toggle or the claim page on that merchant's storefront.
Merchant store data
When you install Coverly, OpoShop's OAuth grants it a scoped access token for your store. Coverly uses it to do four things and nothing else:
- read your store's name, owner email and currency, to fill in the app;
- create and rename its OWN unlisted protection products (it can never write to a product it did not create);
- read your orders, to work out which ones bought protection;
- subscribe to order webhooks, so a protected order is recorded promptly.
Your access token is stored encrypted at rest in Coverly's own database and is never shared, logged in full, or exposed through the API.
Buyer data
For every order that bought protection, Coverly stores the order number and date, the items and their values, what was paid for protection, and the buyer's name and email address as they appear on that order. The email is stored for one reason: filing a claim requires it to match exactly, so that somebody who merely guesses an order number cannot file in a buyer's name.
If a buyer files a claim, Coverly also stores what they wrote about what went wrong, which items they said were affected, and the status history of that claim.
Coverly does not collect buyer postal addresses, phone numbers, IP addresses (beyond a short-lived, in-memory rate-limit counter that is never written to disk), or any tracking identifier. It does not build profiles and does not follow shoppers across sites.
Payment data
Coverly never sees or stores card details. The protection fee is charged by your store through OpoShop's own checkout, as a normal line item. Coverly holds no card, no balance and no payout account, and there is no code path in the app that moves money in either direction.
Where data is stored
In Coverly's own MongoDB database, in a database used only by this app, with every record scoped to the store it belongs to. One merchant's stores are isolated from each other as well as from other merchants: each store install gets its own user record, and every query is scoped by store.
Analytics
Coverly sends product analytics to PostHog so we can see which features are used. Events
are identified by an opaque store identifier (store_<uuid>) only.
No personal data is ever sent — no buyer email, no buyer name, no claim
text, no order contents.
Sharing
Coverly does not sell data and does not share it for advertising. Data is shared only with the infrastructure providers required to run the app (hosting, database, analytics as described above), and where the law requires it.
Retention and deletion
Protected orders and claims are kept while the app is installed, so that a buyer inside your claim window can still file and you keep a record of what you promised. Uninstalling pauses the store and stops all processing; your data is retained so a reinstall picks up where you left off. To have a store's data deleted permanently, email brandon@tryfound.io and it will be removed within 30 days.
Your rights
Merchants and their buyers may request access to, correction of, or deletion of personal data held by Coverly. Buyers should contact the store they bought from in the first instance, since the merchant is the controller of their order data; we will assist any merchant with such a request.
Changes
If this policy changes materially we will update this page and the date at the top. Your continued use of Coverly after a change means you accept the updated policy.