What Hooked collects, why, and the choices merchants and their customers have.
This policy covers the Hooked application for Shopify ("Hooked", "the Service"), operated by DKN Technologies ("we", "us"). It applies to merchants who install Hooked and, indirectly, to their customers whose subscription records the Service processes on the merchant's behalf.
Data is used solely to operate subscriptions: creating and fulfilling delivery cycles, generating Shopify orders, powering the customer portal, producing merchant analytics and recovering from failures. We do not sell personal data or use it for third-party advertising.
Hooked never receives or stores card numbers, UPI handles or bank credentials. Payment instruments are processed by Razorpay and/or Shopify Payments under their own terms. Hooked stores only payment references — identifiers, amounts and statuses — required to reconcile subscriptions with orders.
Credentials are stored AES-256-GCM encrypted. All traffic is TLS. Admin, webhook, storefront and portal entry points are each cryptographically authenticated. Every tenant-data query is scoped to the owning shop. Material actions are recorded in an audit log.
Subscription records are retained while the merchant uses the Service. On uninstall, OAuth sessions are deleted immediately and shop data is deactivated; Shopify GDPR webhooks (customer data request, customer redact, shop redact) are honoured on Shopify's schedule. Operational logs are pruned automatically (webhook logs after 90 days; job history after 30 days).
Merchants may export their data as CSV from the admin or request deletion at any time. End customers should direct requests to the merchant they subscribed with; we support the merchant in fulfilling them via the GDPR endpoints and manual assistance.
Privacy questions and grievances: hello@dkntechnologies.com (DKN Technologies Grievance Desk, Mumbai, Maharashtra, India). Acknowledged within 48 hours, resolved within 30 days.