Public policy
Privacy
Effective July 29, 2026
RecordVane: Email DNS Guard is operated by Automated Solutions Group. The app is built to diagnose public email-authentication DNS with less merchant data, not more.
Data the app handles
To install and operate the app, we store the Shopify shop identity, Shopify session credentials, install and billing state, and the limited account fields Shopify includes with an authorized session. We do not request Shopify customer, order, or product scopes.
When a merchant configures monitoring, we store the brand domain, sender addresses and domains, provider labels, provider-issued DNS expectations, public DNS observations, check reports, incident history, acknowledgement state, and Shopify Flow delivery state. We also retain authenticated webhook identifiers, topics, shop domains, and event timestamps so Shopify retries can be processed safely. The app does not read email content or send email.
Why we use it
We use this data only to authenticate the store, verify the active Shopify plan, compare public DNS with merchant-supplied expectations, schedule checks, show repair instructions, maintain incident history, operate Shopify Flow triggers, prevent abuse, and support the merchant.
Service providers
Shopify supplies installation, authentication, billing, embedded app, and Flow services. Render supplies application hosting, scheduled execution, and managed PostgreSQL for the production deployment. Cloudflare's public recursive DNS service may process the domain names needed to answer DNS lookups; no customer list or email content is sent with those lookups.
Retention and deletion
Completed checks, resolved incidents, terminal Flow delivery records, and manual-check counters are retained for up to 90 days when no active incident or pending delivery requires them. While the app remains installed, its latest completed report may be kept longer as the comparison baseline for the next scheduled check. Active operational records remain while the app is installed.
Uninstalling removes Shopify sessions, marks the store uninstalled, stops scheduled monitoring, and cancels pending Flow delivery. When Shopify sends the required shop-redaction webhook, the app deletes the store, webhook-retry metadata, and its related configuration and history from the active database. Encrypted recovery copies age out under the hosting provider's configured backup window.
Security and choices
Production traffic uses HTTPS. Application credentials and database connection values are stored as platform secrets rather than in the source repository. Merchants can correct monitored sender settings in the app and can request help or deletion information from the support address below.
Contact
Privacy and data requests: creatormarketinggroup@gmail.com. Do not email Shopify access tokens, passwords, DNS-provider credentials, customer lists, or message content.