MKT Skills VA Toolkit
How the connection handles information
This notice describes the public release candidate. The public service and support mailbox still require launch verification.
Updated September 30, 2026. Operator: Vince Servidad.
What it reads
After the store owner approves access, the connection uses fixed Shopify queries for store identity, products, variants, stock and limited order information. It requests only read_products, read_inventory and read_orders.
Order queries exclude customer names, addresses, emails, phones and payment details. Shopify still treats order resources as protected data. Pages are limited and may not cover every record.
What it retains
The server retains encrypted authorization records needed to connect an AI client to the approved store. These include the store domain, approved scopes, Shopify access/refresh credentials, client name and registered return addresses, and connection creation and expiry times.
It does not store client briefs, uploaded files, customer messages, or product/order query results as documents. A store read is processed to answer the request and returned to the requesting client.
Shopify authentication may provide store-user identity details. The app uses the owner-status check for connection approval and does not retain user names, email addresses or other unnecessary identity details.
MCP access tokens last one hour. Connection grants and rotating MCP refresh credentials last at most seven days and require reconnection. Client registrations expire after 28 days. Pending approvals expire after ten minutes; review and authorization codes expire after two minutes. Expired records are cleaned hourly. Encrypted Shopify installation credentials are retained for at most seven days from the latest owner connection approval, or until Shopify's refresh credential expires if earlier. Routine token refresh does not extend that retention period. Uninstall or applicable shop redaction removes them earlier. Hashed lifecycle markers last 28 days and hashed webhook receipts seven days; they contain no store domain, customer data or credentials.
Where information goes
Shopify supplies the store data. Cloudflare runs the hosted connection and its encrypted authorization storage. ChatGPT, Claude or the MCP client you choose receives the supported query results. Its own privacy settings and retention policies govern your chats, project files and results.
Requests to the connection use HTTPS. Service invocation logging is disabled, query strings are redacted, and credentials and document contents must not be recorded in support logs. Platform security and rate limiting may process network metadata to operate the service.
Your control
The owner reviews each offline AI connection inside Shopify. The owner can disconnect a client in the app; uninstalling invalidates the store's connections. Shopify's required data-request and redaction webhooks are handled, including removal of retained shop authorization records when applicable.
Customer/order documents are not retained by this connection. Removing a store connection does not delete data already in ChatGPT, Claude, another client or a support conversation. Request deletion there separately.
Support and privacy requests
Contact support@mktskills.com. The incoming mailbox is being prepared; use GitHub for a general contact request until forwarding is verified. GitHub issues are public. Do not include secrets, personal customer data or private store documents in an issue.
Only share the minimum information needed for support. The service is free and does not process app payments. It does not sell stored authorization records or run advertising trackers.