Legal

Privacy Policy

Last updated: 31 August 2026

This policy explains what data the CheckoutOS Shopify app ("the App", "we", "us") collects, why we collect it, how long we keep it and how we protect it. CheckoutOS is operated by CommercePilot.

If you have any question about this policy, email [email protected].

1. Who this applies to

Two groups of people are covered:

  • Merchants — Shopify store owners and staff who install and configure the App.
  • Customers — shoppers who reach the checkout of a store where the App is installed.

2. What we collect

From merchants

  • Store identity — your myshopify.com domain, shop ID, plan level and installation status.
  • Authentication data — the OAuth access token Shopify issues so the App can act on your behalf. It is stored encrypted at rest and never exposed to a browser.
  • Your configuration — the blocks, rules, discounts, validation logic, offers and branding settings you create.
  • Subscription state — plan, trial dates and billing status, as reported by Shopify's Billing API. We never see or store your payment card details; billing is handled entirely by Shopify.
  • Support correspondence — if you contact us or use the in-app support form, we keep the message and your reply address.

From your store, via the Shopify API

With the permissions you grant at install, the App reads store data needed to make its features work — products and variants (to build offers and rules), discounts, delivery and payment customizations, metaobjects, and orders.

From shoppers at checkout

  • Cart and order context — cart value, line items, country, and currency, evaluated so rules and blocks can decide what to show or enforce. This evaluation happens per request.
  • Anonymous interaction events — impressions, clicks and conversions per block, plus post-purchase offer outcomes. These power your analytics funnel.
  • Order references — order and checkout identifiers received through Shopify webhooks, used to attribute upsell revenue and to apply post-purchase changes to the correct order.

Cookies and tracking

The App does not set advertising or tracking cookies on shoppers' devices, and it does not follow shoppers across sites. Merchant sessions in the Shopify admin are authenticated with Shopify's own session tokens.

We do not build shopper profiles. Analytics events are aggregate counters tied to a block and a store — not to a named individual. We do not sell data, we do not share it with advertisers, and we do not use it to train machine-learning models.

3. Why we collect it

DataPurposeLawful basis (GDPR)
Store identity & access tokenOperate the App on your storePerformance of a contract
Your configurationDeliver the features you set upPerformance of a contract
Cart / order contextEvaluate rules and render blocksPerformance of a contract
Analytics eventsReport which blocks convertLegitimate interest
Application logsDiagnose faults, prevent abuseLegitimate interest
Subscription stateBilling and access controlPerformance of a contract

4. How long we keep it

  • Configuration and subscription data — for as long as the App is installed.
  • Application logs — 30 days on Starter and Growth, 90 days on Pro.
  • Analytics events — retained while the App is installed so historical funnels stay comparable.
  • After uninstall — we receive Shopify's app/uninstalled webhook and delete your store's data within 48 hours, except where we must retain records to meet a legal obligation.
We do not sell personal data, and we do not disclose it to third parties for their own marketing.

5. Where your data lives

Application data is stored in the European Union (EU West region). If you are outside the EU, your data is transferred there and protected by appropriate safeguards, including Standard Contractual Clauses where required.

6. Security

  • All traffic is served over HTTPS with TLS.
  • Access tokens are stored encrypted and never sent to the browser.
  • Every webhook from Shopify is verified by HMAC signature before it is processed.
  • Rule logic runs server-side as Shopify Functions, so it cannot be tampered with from a shopper's browser.
  • Access to production systems is restricted and credentials are rotated.

No system is perfectly secure. If we become aware of a breach affecting your data, we will notify you and the relevant supervisory authority as required by law.

7. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict or delete your personal data, and to object to processing based on legitimate interest. Residents of California have equivalent rights under the CCPA, including the right not to be discriminated against for exercising them.

To exercise any of these, email [email protected]. We respond within 30 days.

Shopify's mandatory data requests

The App implements Shopify's three compliance webhooks. When a shopper asks a merchant for their data, or asks to be forgotten, Shopify notifies us and we respond automatically:

  • customers/data_request — we return whatever data we hold that relates to that customer.
  • customers/redact — we erase that customer's data.
  • shop/redact — we erase the store's data, 48 hours after uninstall.

8. Children

The App is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

9. Changes to this policy

If we make a material change we will update the date at the top of this page and, where the change significantly affects you, notify merchants inside the App or by email. Continuing to use the App after a change means you accept the revised policy.

10. Contact

CommercePilot
Surat, Gujarat, India
Email: [email protected]

Note: this policy describes how CheckoutOS actually handles data, but it is not legal advice. Have a qualified adviser review it against your jurisdiction before you rely on it, and add your registered business name and address before publishing.