Pound Pixel Apps / Shipping Rules / Privacy Policy
Privacy Policy
Effective March 2026
What We Collect
Shipping Rules collects only the minimum data required to operate:
- Shop domain (e.g., yourstore.myshopify.com)
- Encrypted Shopify access token
- Shipping rule configurations (rule names, conditions, target shipping methods)
What We Do NOT Collect
We do not collect, store, or process any of the following:
- Customer personal information (names, emails, addresses)
- Order data or order history
- Payment information
- Browsing or tracking data
- Product inventory data
How We Use Your Data
- Access token: Used solely for Shopify API calls to manage delivery customizations and write rule configuration metafields
- Shop domain: Used for app authentication and session management
- Rule configurations: Stored to power your shipping rules at checkout
Data Storage
- MySQL database hosted on Railway (US region)
- Access tokens encrypted at rest
- All API communication over HTTPS
Data Retention
Your data is retained while the app is installed on your store.
On uninstall, the shop/redact GDPR webhook deletes all shop data — including rules, configuration, subscription records, and the shop record — within 48 hours.
Third-Party Sharing
None. Your data is never shared with, sold to, or accessed by third parties.
GDPR Compliance
We support all three mandatory Shopify GDPR webhooks:
customers/data_request— We store no customer data, so no data to returncustomers/redact— We store no customer data, so no data to deleteshop/redact— Deletes all shop data on uninstall
Contact
For privacy questions, reach us at [email protected].