Privacy policy
Effective date: August 6, 2026
Checkout Rules ("the app") helps Shopify merchants control which payment methods and shipping options appear at checkout. This policy describes what data the app touches, what it stores, and what it never collects.
What the app stores
- Store identification and access tokens. When you install the app, Shopify issues authentication tokens for your store. We store them to read and write your rule configuration through Shopify's APIs.
- Your rules. Rule configurations are stored on your own store as Shopify metafields, so they stay inside Shopify's platform.
- Basic app-usage state. We record your store's domain and onboarding progress (for example, whether the rule tester has been opened) to run the in-app setup checklist.
What the app does not collect
- No customer personal data is stored. Rules are evaluated inside Shopify Functions, which run on Shopify's own infrastructure during checkout. Cart contents, addresses, and customer tags are processed there transiently and are never transmitted to or stored on our servers.
- No analytics trackers, advertising pixels, or data resale. Ever.
Billing
Subscriptions are processed by Shopify's billing system. We never see or store your payment details.
Data retention and deletion
When you uninstall the app, Shopify revokes its access tokens and we delete the stored session data for your store. We honor Shopify's mandatory privacy webhooks: customer data requests and customer redaction requests return or remove nothing because nothing is stored, and shop redaction requests permanently delete all remaining data for the store.
Hosting
The app's admin interface is hosted on Fly.io in the United States. Checkout rule evaluation runs on Shopify's infrastructure, not ours.
Contact
Questions about this policy or your data: mouad3ali@gmail.com.