Scope and roles
ForensiMark is a Shopify application for product-media protection, traceable delivery, public-web discovery, evidence collection, merchant alerts, and reviewable DMCA drafting. Taqwa Vows LLC develops the product within its Shopify Partner organization.
The Shopify merchant controls the store and decides how the application is configured. Store customers should normally direct privacy requests to the merchant, who can use Shopify's standardized privacy-request process.
Information processed
Store and merchant records
Shopify store identifiers, shop domain, store name, currency, timezone, application status, merchant settings, notification preferences, subscription records, support-ticket content, and any contact email voluntarily entered by the merchant.
Product and media data
Product identifiers, titles, handles, media metadata, source URLs, image hashes, protected-image delivery tokens, watermark profiles, video assets, and technical preparation or delivery status.
Delivery and storefront signals
Session-linked delivery identifiers, hashed browser or network indicators, user-agent hashes, customer or order identifiers where needed for purchase entitlement, and optional storefront security signals. A network address can be processed transiently to create a hash; the corresponding delivery record stores the hash rather than the raw address.
Investigations and evidence
Merchant investigation uploads, recovered watermark or QR data, public result URLs, public-page evidence, search classifications, screenshots or HTML captured from public result pages where available, merchant review decisions, ownership certificates, and DMCA draft records.
Operational logs
Activity events, background-job status, rate-limit counters, security and delivery events, error information, and deterministic audit hashes used to operate and protect the service.
Secret material
Watermark key material is stored encrypted. Public certificates can include a non-secret fingerprint, but raw watermark secrets and encrypted key ciphertext are not exposed to storefront visitors or included in public evidence certificates.
How information is used
- Deliver session-linked protected product media and purchase-based access.
- Prepare, recover, and verify visible or invisible ForensiMark signals.
- Detect limited browser-side risk indicators and create merchant alerts.
- Search publicly accessible webpages for Potential Matches and preserve review evidence.
- Generate merchant-requested reports, ownership certificates, analytics, and reviewable DMCA drafts.
- Provide billing, subscription, support, security, abuse prevention, and service operations.
- Respond to authenticated Shopify customer-data, customer-redaction, and shop-redaction requests.
Service providers and external processing
ForensiMark relies on Shopify for installation, authentication, merchant administration, webhooks, and billing. It also uses hosting and private-storage infrastructure to operate the application.
Where configured and invoked, public product references, public search queries, and public webpage evidence can be processed through Bright Data for web discovery. Limited public evidence can also be sent to DeepSeek for assistive classification. AI output remains subject to mandatory merchant review and is not treated as a legal conclusion.
Retention, deletion, and exports
Different records serve different operational and evidence purposes, so this policy does not invent one universal retention period. Active merchant data remains available while needed for the configured service, subject to deletion workflows and operational retention settings.
Authenticated merchants can export ForensiMark data, delete application data, or uninstall the app from Settings → Privacy & Data. Deletion removes shop records, private files, jobs, and sessions according to the implemented workflow. Shopify compliance webhooks handle customer data requests, customer redaction, and shop redaction.
To prevent repeated use of the one-time onboarding allowance after deletion, ForensiMark retains only a non-reversible HMAC identity marker and the related trial usage counters. The shop domain is not stored in that tombstone record.
Merchant and customer choices
Merchants can adjust optional storefront protection signals and notification settings inside the application. A store customer who wants access, correction, or deletion should contact the Shopify merchant that controls the store; Shopify can then send the applicable standardized request to installed applications.
Security and technical limitations
ForensiMark uses authenticated merchant routes, signed or verified webhook boundaries, private storage, encrypted secret material, hashes, and private no-store evidence downloads as described in the public Security & Trust Center.
Browser signals cannot prove that a screenshot occurred and are classified only as possible capture signals. No browser technology can completely prevent screenshots, cameras, copying, cropping, recompression, or deliberate removal attempts.
Privacy requests and contact
Installed merchants should use the authenticated in-app Support page and Settings → Privacy & Data. Store customers should submit privacy requests to the merchant that controls the Shopify store. ForensiMark does not publish an unverified public privacy email address on this page.
Legal review
Privacy laws apply differently by jurisdiction and use case. This page describes the current technical implementation and is not legal advice. Taqwa Vows LLC and merchants should obtain qualified legal advice for jurisdiction-specific obligations before public distribution or material processing changes.