How we handle your data
This policy explains what data the app collects, why it's needed, and how it's stored and deleted.
Last updated: July 6, 2026
Overview
This app ("LogicCart Checkout Rules") applies rules at checkout: which payment methods buyers see, whether their delivery address is accepted, and whether the order meets the limits you set. It accesses your Shopify store data only through Shopify's official APIs and only as needed to deliver that functionality. We do not sell your data, and we do not share it with third parties for marketing.
Data we collect and store
- Shop identifier & access token. Stored to authenticate your installation, as required by Shopify's OAuth flow. The token is kept in your app database and used to call Shopify's Admin API on your behalf.
- Shop owner email. Used to identify your account and respond to support requests.
- App configuration you create. This includes your payment method selections, the rules and workflows you build on the flow canvas, your address checks and order limits, the buyer messages you write for them, and onboarding state. This data is required for the app to apply your rules at checkout.
- Cart and checkout data (read-only, in real time). The Shopify Functions that run at checkout read only what the rules you enabled need: cart total and line items, the delivery address, the buyer's email domain and whether they are signed in, their tags, past order count and amount spent, their company if the order is B2B, and the selected delivery method. This decides which payment methods to show and whether the order may proceed. It is processed in memory for the length of one checkout request and is not stored.
- App usage metadata. Anonymous technical logs (used to troubleshoot errors) and review-request state (used to comply with Shopify's reviews API throttling rules).
Data we do not collect
- We do not store customer personal data (names, addresses, emails of your buyers).
- We do not store order history or financial transactions.
- We do not place tracking pixels on your storefront.
How long we keep data
We retain your app configuration data for as long as the app is installed on your store. When you uninstall the app, your sessions are deleted immediately. Forty-eight hours later, Shopify sends a shop/redact webhook and we permanently delete all remaining business data (rules, payment methods, onboarding state, and review records) — well within Shopify's 30-day requirement.
Your privacy rights (GDPR & CCPA)
The app responds to Shopify's mandatory privacy webhooks:
- customers/data_request — we acknowledge the request. Because we store no buyer-level data, there is nothing to export.
- customers/redact — we acknowledge the request. Because we store no buyer-level data, there is nothing to delete.
- shop/redact — we delete all data we hold about your store.
Data security
All data in transit is encrypted using TLS. Access tokens are stored in a database restricted to the app's backend. We follow Shopify's guidance on secure app development and request only the scopes needed to deliver the app's features.
Changes to this policy
We may update this policy as the app evolves. Material changes will be reflected in the updated date above and, where appropriate, surfaced in the app or by email.
Contact
Questions about this policy? Email privacy@logiccart.app or see the Support page.