Privacy Policy
Last updated: 10 August 2026
Sweeply runs enter-to-win giveaways on OpoShop stores. This policy explains exactly what data Sweeply processes, why, and how it is protected. Sweeply is operated by Found.
Who controls the data
The OpoShop merchant who installs Sweeply is the data controller for the entrant data collected through their giveaway. Found operates Sweeply as that merchant’s data processor, handling the data only to provide the service. If you entered a giveaway, contact the store you entered with for any data request — you can also reach us at the address below and we will route it.
What we collect — merchant data
- Store connection (via OAuth). When a merchant installs Sweeply, OpoShop grants a store-scoped access token. Sweeply requests exactly one permission: read-only user access (users:read), used to confirm the person opening the app really owns the store and to autofill the store’s business name. Sweeply cannot read orders, cannot read or write products, cannot create discounts, and never receives the merchant’s OpoShop password.
- Giveaway configuration. The prize, dates, entry rules, copy, colours and consent text the merchant sets.
- Store identity. Store name, subdomain and owner email, for the app UI and support.
What we collect — entrant data
- Email address. Required to enter. Stored against the merchant’s store so the merchant can view and export their subscriber list.
- Optional first name, if the merchant asks for one.
- Consent record. A consent flag, a timestamp, and a snapshot of the exact consent wording shown at the moment of entry — so what was agreed to can always be demonstrated.
- Entry records. The entries earned, the awards that justify them (signing up, a confirmed referral, a bonus-action click), a unique referral code, and which referral link the entrant arrived through.
- An anti-farming fingerprint — not your IP address. To tell twenty different people apart from one person entering twenty times, Sweeply stores an irreversible keyed hash derived from the IP and the giveaway id. The raw IP address is never written to the database, the value cannot be turned back into an IP, it differs for the same person in different giveaways so it cannot be used to track anyone across stores, and it is never returned by any API or included in any export.
- No card or payment data. Sweeply never sees or stores payment details. It moves no money and touches no checkout.
- No behavioural tracking beyond the above. The storefront widget sends only whitelisted, non-identifying event counts (for example “popup shown”) keyed to the store — never to a shopper, and never carrying an email address.
How we use it
- To record entries, calculate entry counts, and credit confirmed referrals.
- To build the merchant’s subscriber list and their dashboard metrics.
- To send the entrant a branded confirmation email with their referral link, and a winner email if they win, through OpoShop’s own email service on the merchant’s behalf.
- To run and publish the winner draw, including a public record showing masked winner addresses (for example a****@example.com) so the result can be verified.
- To keep the service secure, prevent entry farming, and provide support.
What is shown publicly
A giveaway’s public page shows entrant counts, and after a draw it shows winners with their email address masked, never in full. The draw proof contains only entry identifiers and entry weights — no addresses. An entrant’s own live entry count is readable only with their own unguessable referral code, and that endpoint returns counts only: it never returns an email address, not even the caller’s own.
Storage, scoping & security
- Data is stored in Sweeply’s own database, scoped per store — one store can never see another store’s entrants, subscribers or configuration.
- Access to the OpoShop API uses the store’s own token over HTTPS. Session tokens are short-lived and typed, so a refresh token cannot be used as an API credential.
- Merchant CSV exports are escaped against spreadsheet formula injection, so a hostile entry cannot execute anything on a merchant’s machine.
- We do not sell entrant or merchant data, and do not share it with third parties beyond the infrastructure needed to run the service (hosting, database, and OpoShop’s own APIs including its email service).
Retention
Subscriber and entry records are kept for as long as the merchant has Sweeply installed, so the merchant keeps their list. Records for a giveaway that has been drawn are deliberately retained even after an uninstall, because a winner may need to verify the draw months later; that record contains masked addresses and entry weights only. A merchant can request deletion of their store’s data at any time, and an entrant can request removal of their email through the merchant or by contacting us.
Your rights
Depending on where you live you may have rights to access, correct, export or delete your personal data (for example under GDPR or CCPA). For entrant data the merchant is the controller and handles these requests; we assist as their processor. To exercise a right or ask a question, email brandon@tryfound.io.
Changes
We may update this policy; material changes will be reflected by the “last updated” date above.
Contact
Found — brandon@tryfound.io.