Keepsy

Privacy Policy

Last updated 5 August 2026 · Keepsy is operated by Found.

The short version. Keepsy stores two things: what a shopper saved on your store, and — if they chose to give it — the email address they want reminders at. We use them for nothing but that. We do not sell, rent or share data with anyone, we never write to your store, and every store's data is kept strictly separate from every other store's.

Who this covers

This policy covers the Keepsy app installed on an OpoShop store, the save widget it adds to that store's storefront, the saved-list pages it serves, and the reminder emails it sends. If you are a shopper, the merchant whose store you saved items on is the controller of your data; Keepsy processes it on their behalf.

Merchant store data

When you install Keepsy, OpoShop grants it an access token through OAuth. Keepsy uses that token to read:

Keepsy never writes to your store. It cannot edit products, change prices or stock, create discounts, alter orders, or modify customers. It holds no permission to do any of those things.

Shopper data

When a shopper taps save, Keepsy stores:

Keepsy does not use cookies for tracking, does not build a cross-site profile, does not fingerprint devices, and does not follow shoppers to other stores. A shopper who saves on two different merchants' stores has two entirely separate, unconnected lists.

What we email, and why

A shopper only ever receives an email from Keepsy if they gave an address, and only when something they personally saved changes: it comes back in stock, its price drops past the merchant's threshold, or (if the merchant enabled it) stock runs low. Every message carries the merchant's identity, states plainly why it was received, and includes one-click unsubscribe. Emails are delivered through OpoShop's own mail system.

Unsubscribing stops all reminders immediately and permanently for that store. It does not delete the shopper's saved list.

How a list moves between devices

Typing an email address never reveals a list. To open a saved list on a second device, the shopper must open a signed link sent to that address — opening it from their own inbox is the proof that the address is theirs. This is deliberate: any design where an address alone returns a list would let anyone read a stranger's wishlist by guessing.

Payment data

Keepsy never sees, handles, transmits or stores card or payment details. It is not part of your checkout.

Where data lives and how it is separated

Data is stored in Keepsy's own MongoDB database, hosted in the United States, and served from Fly.io. Every record carries the store it belongs to and every query is scoped by it; the app runs a data-isolation check on every boot to verify that no record can be reached from another store. Access is limited to Found personnel who need it to operate and support the app.

Analytics

Keepsy records anonymous product analytics (for example, "a widget rendered" or "a reminder was sent") to understand whether features work. These events are keyed to a store identifier — never to a shopper, an email address, or an IP address. No personal data is sent to our analytics provider.

How long we keep it

Saved lists and saver emails are kept while the app is installed, so a shopper's list is still there when they return. If you uninstall Keepsy, processing stops immediately and the data is retained for 90 days so a reinstall restores your shoppers' lists, after which it is deleted. You or a shopper can request earlier deletion at any time and we will action it within 30 days.

Your rights

Shoppers and merchants may request access to, correction of, or deletion of their data, and may object to processing. Email brandon@tryfound.io and we will respond within 30 days. Merchants: please forward shopper requests to us and we will handle them on your behalf.

Sub-processors

Keepsy relies on a small number of providers to operate: Fly.io (hosting), MongoDB Atlas (database), OpoShop (store API and email delivery), and PostHog (anonymous product analytics). No other party receives data, and none of them are permitted to use it for their own purposes.

Changes

If this policy changes materially we will update the date above and notify installed merchants in the app.

Contact

Found · brandon@tryfound.io