1. Scope and privacy-minimizing architecture
This privacy policy applies to the WS Checkout Control Shopify application, embedded merchant interface, Shopify Functions extensions (Payment & Delivery Customization Functions), storefront signal app embeds (WS Checkout Signals), app-proxy endpoints, and related product website routes.
WS Checkout Control is built on a privacy-minimizing design: storefront signal extensions classify incoming visitor requests in server memory into broad policy labels. Raw IP addresses are processed in-flight and are never stored in the application database or persistent log files.
2. Information we may process
Merchant and shop information
- Shopify myshopify.com domain, shop ID, access tokens, granted scopes, and session identifiers.
- App settings, failure-handling preferences (e.g. anti-hide-all safety controls), default simulator currencies, and theme embed confirmation flags.
- Payment and delivery rule definitions, condition parameters, priority rankings, and custom action titles.
- Audit history records (timestamps, rule modification events, synchronization revision state, and user actions).
Checkout & cart parameters (transient processing)
- Cart subtotal amounts, currency codes, line item counts, total quantity, total weight, and product physical/digital tags.
- Shipping address destination parameters (country code, province/state, city, and ZIP/postcode).
- Customer B2B membership status, customer login state, and customer tags passed via theme embed or native API inputs.
- Storefront locale preferences, selected delivery options, and custom cart attributes.
Data excluded from collection
- We do NOT collect, request, or store buyer names, email addresses, phone numbers, street addresses, or credit card numbers.
- We do NOT save raw buyer IP addresses or build individual buyer profiles across sites.
3. Purposes of processing
Information is processed strictly to provide payment and delivery customization rules, execute Shopify Functions during checkout, evaluate rule conditions, maintain audit logs, sync configuration revisions, provide fail-open error handling, and support merchant administration.
4. Data storage and security
Merchant configurations and audit logs are persisted securely in a PostgreSQL database using Prisma ORM. Secrets and sensitive API credentials are encrypted using AES-256-GCM encryption. Transport across App Proxy endpoints and Shopify Admin APIs uses HTTPS/TLS encryption and HMAC signature verification.
5. Shopify mandatory privacy webhooks
WS Checkout Control fully supports and responds to Shopify's mandatory privacy webhooks:
- customers/data_request: Reports data associated with a customer. Because no buyer PII or buyer IP logs are retained, zero buyer records are returned.
- customers/redact: Processes customer data deletion requests automatically.
- shop/redact: Upon store uninstallation and expiration of the 48-hour purge window, all stored rules, state, settings, and audit logs for the shop are permanently deleted from the database.
6. Data retention
Merchant rules and settings are retained while the app remains installed on the merchant's Shopify store. Following uninstallation, shop data is purged in accordance with Shopify Partner platform requirements.
7. Rights & contact
Merchants and site visitors may contact WS Themes regarding privacy practices or data inquiries at support@wsthemes.com.