Privacy Policy
Last updated: July 29, 2026
Introduction
This Privacy Policy describes how EZ Commerce Apps (“we,” “our,” or “us”) collects, uses, and shares information when you install and use our applications on the Shopify platform, including EZ AOV Boost (the “App”), and when you visit this website.
Information we collect
Store information
When you install the App, we collect:
-
Shop domain — your Shopify store URL (for example,
yourstore.myshopify.com) - Shopify plan — your current Shopify subscription plan
- Store settings — currency, timezone, and locale
- Access token — the Shopify API credential that lets the App act on your store, stored encrypted (AES-256)
Configuration data
We store the App configuration you create, including:
- Cart minimum settings
- Reward tier settings (thresholds and reward details)
- Product recommendation settings
- A/B test (experiment) settings
- Progress bar customization (colors, messages)
- Feature enable/disable preferences
Analytics data
The App's storefront widget collects anonymous cart-session signals to power your analytics dashboard:
- Anonymous, Shopify-generated cart tokens that link events within a single cart session (these are opaque identifiers and are not tied to a customer's identity)
- Widget engagement events (progress bar views, tiers reached, recommendations shown/added)
- Cart and order subtotals, used to compute average-order-value metrics
Order data
When an order is placed on your store, we process:
- The Shopify order ID and order subtotal (for analytics attribution)
- For store credit rewards only: the Shopify customer ID for the order — an opaque identifier used solely to grant the credit to the correct account. We record the grant (order ID, amount) in a ledger to prevent duplicate grants.
What we do NOT collect
- Customer names or contact information
- Customer email addresses or phone numbers
- Customer payment information
- Customer shipping or billing addresses
- Individual browsing histories
This website does not use cookies, advertising trackers, or third-party analytics.
How we use information
- Providing the service — authenticate your store, display the progress bar and recommendations from your configuration, apply rewards, enforce cart minimums, grant store credit, and generate your analytics reports
- Improving the service — analyze aggregate usage patterns, identify and fix bugs, and develop new features
- Communication — send important service notifications and respond to support requests
Data storage and security
All data is stored on servers in the United States:
- Database: Supabase (AWS infrastructure)
- Application: Netlify (AWS/Google Cloud infrastructure)
Security measures include:
- Access tokens encrypted at rest using AES-256
- All data transmitted over HTTPS/TLS
- Row-level security on all database tables (strict per-store isolation)
- Webhook authenticity verified with HMAC-SHA256 before processing
We use Sentry for error monitoring. Error reports may include your shop domain but never customer personal information.
Data retention
| Data type | Retention period |
|---|---|
| Raw analytics events | 90 days (rolling automatic cleanup) |
| Aggregated daily analytics | Up to 2 years |
| Store record, access token, and configuration | While the App is installed |
| After uninstall | Configuration retained for 48 hours (so an accidental uninstall/reinstall keeps your settings), then all data is permanently deleted |
Data sharing
We do not sell, rent, or trade your information. We share data only with the service providers required to run the App:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database hosting | Store data described above (tokens encrypted) |
| Netlify | Application hosting | Request logs (no customer personal information) |
| Shopify | Platform integration | As required by the Shopify APIs |
| Sentry | Error monitoring | Error reports (may include shop domain; no customer data) |
We do not transfer data to advertising networks, data brokers, or third-party analytics services. We may disclose information if required by law, legal process, or government request.
GDPR compliance
The App implements all three of Shopify's mandatory privacy webhooks:
- customers/data_request — because we store no personally identifiable customer information, there is no customer personal data to return; requests are logged and acknowledged
- customers/redact — acknowledged and logged; anonymous cart tokens age out under the standard 90-day rolling deletion
- shop/redact — received 48 hours after uninstall; permanently and irreversibly deletes all data for your store
For transfers of EU data to the United States, we rely on standard contractual protections with our infrastructure providers.
Your rights
GDPR rights (EU/EEA/UK)
- Access — request a copy of your data
- Rectification — request correction of inaccurate data
- Erasure — request deletion of your data
- Portability — receive your data in a portable format
- Objection — object to data processing
CCPA rights (California)
- Know — what information we collect (described on this page)
- Delete — request deletion of your information
- Opt out of sale — we do not sell personal information
To exercise any of these rights, email support@ezcommerceapps.com.
Data deletion
When you uninstall the App:
- Your access token is immediately invalidated
- 48 hours later, Shopify sends the
shop/redactnotice - All of your store's data — configuration, analytics, everything — is permanently deleted
You may also request immediate deletion at any time by emailing support@ezcommerceapps.com.
Children's privacy
Our apps and this website are not intended for use by children under 13. We do not knowingly collect information from children.
Changes to this policy
We may update this Privacy Policy from time to time. Significant changes will be announced by email to your Shopify store's admin email address and/or by a notice within the App. The “Last updated” date at the top of this page reflects the current version.
Shopify data protection
As a Shopify Partner, we comply with:
- The Shopify Partner Program Agreement
- The Shopify API Terms of Service
- Shopify's protected customer data requirements
Contact us
For privacy-related questions, concerns, or requests: support@ezcommerceapps.com
EZ Commerce Apps, Brightwood, Oregon, USA