Privacy Policy
Effective Date: August 26, 2026
This Privacy Policy describes how CodeBot (“the App”, “we”, “us”, or “our”) collects, uses, and protects information when you install or use the App in connection with your Shopify-supported store.
1. Information We Collect
When you install and use the App, we collect certain information to provide our services. We strictly adhere to privacy-by-design principles and Shopify’s protected customer data policies:
- Merchant Account Information: We store your Shopify store domain name, access tokens, and installation configuration settings required to authenticate and power the App.
- Discount & Campaign Data: We collect and process store discount rules, batch titles, generated discount codes, and campaign tags created within the App.
- Order & Sales Metadata (Attribution): To calculate campaign revenue and code usage, we process incoming order webhooks. We only extract anonymized numerical metadata (e.g., order ID, discount code used, subtotal amount, and currency). We never collect or store customer Personally Identifiable Information (PII) such as names, email addresses, phone numbers, or delivery addresses.
2. How We Use Your Information
We use the collected information solely to perform the functions of the App, including:
- Generating, importing, and updating discount codes in your Shopify store.
- Tracking campaign-level revenue and usage analytics.
- Auditing store discounts for configuration errors and revenue risks.
- Providing merchant support and troubleshooting app errors.
3. Data Sharing and Third Parties
We do not sell, rent, trade, or monetize any merchant or store data. We only share information with third parties in the following limited circumstances:
- Shopify: We communicate directly with Shopify’s APIs to read and write store configurations authorized by your app permissions.
- Legal Requirements: We may disclose information if required to comply with applicable laws, regulations, or valid legal requests.
4. Data Retention & Mandatory Deletion
We store your configuration and campaign metadata only for as long as the App is installed on your store.
- App Uninstallation: When you uninstall the App, your store metadata and tokens are flagged for deletion and purged in accordance with our data retention schedule.
- GDPR / Mandatory Webhooks: We fully support Shopify’s mandatory privacy webhooks (
customers/data_request,customers/redact, andshop/redact). Upon receiving ashop/redactrequest, all data associated with your store is permanently purged from our databases.
5. Security
We implement industry-standard security practices to protect your data, including encrypted database storage, secure HTTPS communication, and isolated job execution loops to protect system integrity.
6. Your Rights
If you are located in certain jurisdictions (such as the EEA or UK under the GDPR, or California under the CCPA), you have rights regarding your data. Because our App does not retain customer personal data, requests regarding individual customer records should be fulfilled directly through your Shopify Admin panel.
7. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. Updated versions will be posted on this page with a revised effective date.
8. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at:
App Support Team
Email: codebot@quickmedia.com