Privacy Policy - Progus Subscriptions for Claude
Last updated: 17.06.2026
This Privacy Policy describes how the Progus Subscriptions connector for Claude (the "Connector") - the remote Model Context Protocol (MCP) server operated by Progus that lets Claude work with a merchant's Progus Subscriptions data - collects, uses and shares information. It supplements the general PROGUS Privacy Policy.
1. Data Controller
Progus sp. z o.o., ul. Sklepowa 27, 97-500 Radomsko, Poland (KRS 0001078024, NIP 7722434496) ("PROGUS") is the controller. Processing follows the GDPR (Regulation (EU) 2016/679) and the California Consumer Privacy Act (CCPA). Contact: [email protected].
2. When the Connector Processes Data
The Connector only acts after a Shopify merchant explicitly connects their store to Claude and authorizes access through Shopify's OAuth consent. It operates strictly on that merchant's own store and only to fulfil the requests the merchant (or their staff) makes in Claude.
3. Data We Process
On the merchant's instruction, the Connector retrieves data from the merchant's Progus Subscriptions app / Shopify store, which may include:
- subscription contracts, plans and selling-plan groups;
- subscriber and customer information (name, email, delivery address, order and billing history, RFM/segment, total spend);
- payment-method metadata only (e.g. card brand, last digits, expiry, status) - the Connector never accesses or stores full card numbers;
- products and variants, and subscription analytics (MRR, churn, etc.).
For authentication, the Connector also processes the store domain and OAuth tokens issued to the connected Claude client.
4. How We Use Data
Data is used solely to execute the merchant's requested operations (viewing, analysing, and - on explicit confirmation - changing subscriptions and plans) and to return the results to the merchant inside Claude. We do not use this data for advertising and we do not sell it.
5. Sharing and Subprocessors
To provide the Connector, data flows between:
- Shopify - the source of the store and subscription data, accessed under the merchant's authorization;
- Anthropic (Claude) - the AI assistant the merchant chose to connect; requested data is returned to Claude to answer the merchant, subject to Anthropic's terms and privacy policy;
- Fly.io - infrastructure hosting the Connector and the Progus Subscriptions backend.
6. Storage and Retention
The Connector retrieves store data on demand and returns it to Claude; it does not maintain its own persistent copy of the merchant's subscription or customer records. The Connector stores only the minimum needed for authentication: OAuth client registrations, short-lived authorization codes (minutes) and refresh-token identifiers, held in PROGUS's database. Authorization codes and expired tokens are purged automatically. The underlying Progus Subscriptions app retains store data per the general PROGUS Privacy Policy.
7. Security
Access is protected by OAuth 2.1 with PKCE and shop-scoped, expiring tokens with single-use refresh rotation. Internal service-to-service calls are HMAC-signed and travel over a private network. All external traffic is encrypted in transit (HTTPS).
8. Merchant Control
A merchant can disconnect the Connector at any time from Claude's Connectors settings; this revokes the Connector's access to the store. To uninstall entirely, remove the Progus Subscriptions app from Shopify.
9. Your Rights and Contact
You may exercise your GDPR/CCPA rights (access, rectification, erasure, restriction, portability, objection) by contacting [email protected]. We have not appointed a Data Protection Officer, as we are not required to under Article 37 GDPR.
10. Changes
We may update this Policy; material changes will be reflected by the "Last updated" date above.