Crateful

Privacy Policy

Last updated 4 August 2026 · Crateful is operated by Found.

The short version. Crateful holds the merchant store data it needs to build and price crates. It does not collect or store shopper names, emails, addresses, or any other personal data. It never sees card details. It never sells data to anyone.

1. Who this covers

This policy covers Crateful, an application for OpoShop stores that lets shoppers build their own box from a merchant-defined pool of products. It applies to the merchant who installs Crateful, and to shoppers who interact with a Crateful crate on that merchant's storefront.

2. Merchant store data

When a merchant installs Crateful, OpoShop grants it an access token scoped to that one store. Crateful uses it only for the following, and requests no permission it does not use:

Crateful stores, in its own database: the store id and subdomain, the store owner's name and email as supplied by OpoShop, the access token (used only to call OpoShop on that store's behalf), the crates the merchant creates, and the discount codes Crateful itself owns.

3. Shopper data — what we do not collect

The Crateful storefront widget does not collect shopper personal data. It does not ask for, receive or store a shopper's name, email address, postal address, phone number, IP-based profile, or payment details. Crateful never has access to card data at any point — payment is handled entirely by OpoShop and its payment provider.

What Crateful does record from the storefront is anonymous, aggregate activity so a merchant can see whether their crates are working:

The widget uses the browser's own storage only for functional purposes: the store's existing cart id (which belongs to the storefront, not to Crateful), a note of when a popup was last shown so it is not repeated, and a pending order id so a completed order can be confirmed once. No advertising or cross-site tracking cookies are set.

4. Product analytics

Crateful uses PostHog for anonymous product analytics about how the merchant-facing app is used (for example, that a crate was created). Events are keyed to a store identifier, never to a shopper. No shopper personal data is sent to PostHog.

5. Where data is held, and for how long

Data is stored in a MongoDB database operated for Crateful, and the application runs on Fly.io infrastructure. Each store's data is scoped to that store: one store can never read another store's crates, events or settings.

Data is retained while the app is installed. When a merchant uninstalls Crateful, the store is marked uninstalled and its crates stop working immediately; records are retained for a short period so a reinstall restores the merchant's setup, and are deleted on request at any time.

6. Sharing

Crateful does not sell data and does not share it with third parties for marketing. Data is shared only with the infrastructure providers needed to run the service (OpoShop, the database host, Fly.io, PostHog), each acting on Crateful's instructions.

7. Your rights

A merchant may request a copy of the data Crateful holds for their store, or its deletion, at any time by emailing the address below. Requests are actioned promptly. If you are a shopper: Crateful holds no personal data about you, so there is nothing to export or erase — any request about your order should go to the store you bought from.

8. Changes

If this policy changes materially, the updated date above changes and the current version is always published here.

9. Contact

Questions, data requests or anything else: brandon@tryfound.io.