Privacy Policy
Hello Shop HQ · Last updated 10 July 2026
Hello Shop HQ (“we”, “us”) is an internal command-center dashboard used by our team to manage our own e-commerce store brands and their connected social and commerce accounts in one place. This policy explains what data we handle and how.
Who uses this app
Hello Shop HQ is a private, internal tool for our own staff. It is not a consumer product and does not offer public sign-ups.
Data we access
When an authorized team member connects one of our own accounts (for example TikTok, Meta/Facebook/Instagram, Shopify, YouTube, Zoom or eBay) via that platform’s official OAuth, we access only the data needed to operate the dashboard — such as the connected account’s identifier, display name and profile image to show which account is linked, and, where enabled, business content and metrics for those accounts. We request the minimum scopes required for each feature.
How we use it
Connected-account data is used solely to display connection status and to operate the features our team has enabled (such as viewing content, metrics, or managing communications for our own accounts). We do not sell personal data, and we do not use it for advertising or share it with third parties except the platform providers whose APIs we call and our infrastructure vendors (hosting and database).
Storage & security
Access tokens and connection details are stored securely and used only to make authorized API calls on behalf of our own accounts. Access is restricted to authenticated administrators of Hello Shop HQ.
Revoking access & deletion
A connected account can be disconnected at any time from within Hello Shop HQ, or revoked directly in the relevant platform’s settings. On disconnection we delete the stored tokens for that account. To request deletion of any related data, contact us at the address below.
The Chrome extension (Hello Shop HQ Helper)
Our team uses a Chrome extension that works inside a staff member’s own signed-in browser. It is private to our team and is not offered to the public.
What it stores on your machine. Two things, both in the browser’s own local extension storage: a connection token you generate inside Hello Shop HQ, and the store you last selected. No browsing history, cookies or page contents are retained.
What it sends to us, and only when you click. A comment you record as posted, together with the address of the post it was left on; a screenshot of a Shopify Analytics page you explicitly capture; or the visible text of a page you explicitly send. It sends nothing in the background, and it does not watch pages you merely visit.
What it never touches. It does not read or fill password, email or username fields — those are refused outright. It does not post, submit, like or follow on your behalf: it fills a comment box, and a person presses the site’s own button. It does not bypass CAPTCHAs or bot checks, and it does not gather data about anyone other than the accounts we operate ourselves.
Who it talks to. One server only — app.hello-shop.com.au. Nothing is sent to a third party, sold, or used for advertising.
Ending it. Press Disconnect in the extension, revoke the token inside Hello Shop HQ, or uninstall the extension. Any of the three cuts the connection; revoking in HQ takes effect immediately for every browser.
Contact
Questions about this policy: riccoautomation.email.team@gmail.com.