Privacy Policy
This policy explains what data the app handles, why, where it is kept, and how to have it deleted. It is written for the merchant who installs the app. The English text is the binding one. An Italian translation is provided for convenience.
1. What the app does
The app lets you hide, rename and sort the shipping rates your customers see at checkout, based on rules you write. The rules run inside Shopify's checkout as a Shopify Function. If the app ever fails, the checkout shows your rates exactly as you set them in Shopify.
2. Data we store about your store
When you install the app, Shopify gives us:
- your store's
myshopify.comdomain; - an access token that lets the app write delivery customizations to your store, and nothing else;
- the list of permissions you granted.
While you use the app, we store:
- the rules you write, with their names, conditions and order;
- a copy of your rules after every change, kept for 30 days so you can restore them;
- the identifier of the delivery customization the app creates in your store;
- the identifiers of the notices Shopify sends us, so each is handled once.
Shopify tells the app which language your admin is set to every time a page loads, so the app can show itself in Italian or English. We do not store it.
If you write to our support address, we store your message, the address you wrote from and any name you give us, so we can answer you and follow up later.
Our servers also keep technical logs of requests for 30 days. These logs include the time, the page requested and the network address of the browser or server that made the request.
3. Data we do not collect
We do not receive or store your customers' names, addresses, email addresses, phone numbers, orders or payment details.
Your rules run inside Shopify's checkout. At that moment, Shopify's own systems read the cart total, the destination country, province and postcode, and the product and customer tags your rules refer to. That reading happens on Shopify's infrastructure. Nothing about the customer or the cart is sent to our servers.
The app asks Shopify for an offline access token only. We do not receive the name or the email address of the person who installs the app or opens it.
The app sets no cookies of its own and uses no analytics or advertising trackers.
4. Our role
For the data we hold about your store and your account, we decide why and how it is used, so we are the controller of it. Where we handle personal data on your behalf, for example a name inside a rule you wrote, we act on your instructions as your processor. If your business needs a signed data processing agreement, write to support@larchline.co and we will send one.
5. Why we use this data
- To run the app for you: storing your rules and writing them to your store. This is necessary to provide the service you asked for.
- To help you: answering your support requests and finding the cause of a problem.
- To keep the app secure and reliable: logs, error tracking and the detection of misuse. We have a legitimate interest in this.
- To meet legal duties, such as answering a request from Shopify or a public authority.
We never sell your data and we never use it for advertising.
6. Where the data is kept
Your store's data is stored on Google Cloud servers in Belgium (region europe-west1). Support email is handled on Microsoft 365. Shopify itself holds your store's data under its own privacy policy.
We are a United States company. If you write to us, your message may be read in the United States. Store data stays on the servers in Belgium.
Google and Microsoft take part in the EU-US Data Privacy Framework. Where that framework does not cover a transfer, we rely on the standard contractual clauses the European Commission has approved, which are part of our contracts with them.
Companies that process data for us:
| Company | Purpose |
|---|---|
| Shopify Inc. | The platform the app runs on |
| Google LLC (Google Cloud) | Hosting and database, Belgium |
| Microsoft Corporation (Microsoft 365) | Support email |
7. How long we keep it
- Your rules, their history and the access token: for as long as the app is installed.
- When you uninstall the app: the access token and the customization record are deleted at once. Your rules and their history are deleted within 48 hours, when Shopify sends us the removal notice. Write to us if you want them deleted sooner.
- Technical logs: 30 days.
- Support emails: up to 24 months, so we can follow up on earlier requests.
8. Your rights
If you are in the European Union, the European Economic Area, the United Kingdom or Switzerland, you can ask us at any time to:
- see the data we hold about your store;
- correct it;
- delete it;
- receive it in a portable format;
- object to a use based on our legitimate interest.
Write to support@larchline.co. We answer within 30 days. You can also complain to your data protection authority. In Italy that is the Garante per la protezione dei dati personali.
9. Requests that come through Shopify
Shopify sends apps three kinds of privacy notices. This is how the app answers them:
- Customer data request: we hold no customer data, so there is nothing to return.
- Customer data deletion: we hold no customer data, so there is nothing to delete.
- Store data deletion: we delete everything we hold about the store. One record that the deletion happened stays, so the same notice is not processed twice.
10. Security
Access tokens and database passwords are kept in a secrets manager, never in code. Data travels encrypted. Only the app and the people who run it can reach the database. If a security problem ever affects your data, we tell you without undue delay.
11. Children
The app is a tool for merchants and is not directed at children.
12. Changes to this policy
When we change this policy, we post the new version with its date. For a change that affects your rights, we email the store's contact address first.
13. Contact
Scena Labs LLC 522 W Riverside Ave, Ste N Spokane, WA 99201 United States support@larchline.co