Givly

Privacy Policy

Last updated 10 August 2026 · Givly is operated by Found.

The short version. Givly holds the merchant store data it needs to add a donation to a cart and to build the merchant's donation ledger. It does not collect or store shopper names, emails, addresses, or any other personal data. It never sees card details. It never sells data to anyone.

Who this covers

This policy covers Givly, an app that merchants install on their OpoShop store to offer checkout donations and round-up. There are two groups of people involved, and they are treated differently:

What Givly collects from a merchant's store

When a merchant installs Givly, OpoShop's OAuth flow grants an access token scoped to that store. Givly uses it to read and store only what the product needs:

What Givly collects from shoppers

Nothing personal. A shopper never signs in to Givly, never gives it an email address, and never enters payment details anywhere near it. The donation is a normal line on the merchant's own order, paid through the merchant's own checkout.

The storefront control makes two kinds of request:

Card and payment data

Givly never sees, receives, or stores card numbers or any payment credentials. It cannot take a payment and it cannot make a payout. The donation is collected by the merchant through their existing OpoShop checkout, exactly like any other line on the order, and reaches the merchant in their normal payout.

Analytics

Givly uses PostHog for product analytics so we can see which features are used. Every event is recorded against a non-identifying store id of the form store_<uuid>. No personal data is ever sent to analytics — no shopper identifiers, no email addresses, no order contents, no customer names.

How data is stored

Givly's data lives in its own MongoDB database, scoped per store. Every record is tied to exactly one store, and each merchant's account is bound to exactly one store — one store can never read another's data. Access tokens are stored to make API calls on the merchant's behalf and are never exposed to a browser or to any third party.

Sharing

Givly does not sell data, and does not share it with anyone except the infrastructure needed to run the service: our hosting provider (Fly.io), our database provider (MongoDB Atlas), and our analytics provider (PostHog, non-identifying events only). Data is disclosed otherwise only where required by law.

Retention

Store data and the donation ledger are kept while the app is installed, so that a merchant's historical records and remittance history stay intact. When a merchant uninstalls, the store is marked uninstalled and processing stops; the records are retained so a reinstall does not lose the merchant's own accounting history. A merchant may request permanent deletion of their store's data at any time by emailing us, and we will complete it within 30 days.

Your rights

Merchants may request access to, correction of, or deletion of their store's data. Because Givly holds no shopper personal data, there is nothing shopper-specific for us to disclose or delete — a shopper's donation record lives in the merchant's own order in OpoShop, which the merchant controls.

Changes

If this policy changes materially, the date at the top of this page changes and the current version is always published here.

Contact

Questions about privacy, or a data request: brandon@tryfound.io.