Privacy Policy
Last updated: 2026-08-11 · Effective: 2026-08-11
Shopvolt ("Shopvolt", "we", "us", "our") provides a Shopify app for creating and managing bundle offers on merchant stores. This Privacy Policy explains what data we collect, how we use it, and the rights you have over it.
This policy covers data we receive from (a) merchants who install the app and (b) shoppers who interact with bundles on merchant storefronts.
1. Data we collect
From merchants (Shopify store owners)
When you install Shopvolt, Shopify grants us access to data needed to run the app:
- Shop information — your shop's myshopify.com domain, primary email, timezone, currency, plan, and locale settings.
- Products, variants, and collections — read access so you can build bundles from your catalog.
- Themes — read access to detect whether the Shopvolt theme block is enabled.
- Discounts — write access so we can create and update the discount that powers your bundles at checkout.
- Markets and locales — read access for multi-region and multi-language bundles.
- Orders — read access to count bundle orders and verify discount application for analytics.
We do not collect or store payment methods, customer billing information, or personally identifiable information about your customers beyond what Shopify provides for analytics attribution (see below).
From shoppers (your customers)
When a shopper views a product page with a Shopvolt bundle:
- Anonymous session ID — a UUID we generate to tie an impression to a later order. Stored in
localStorageand as a cart attribute (_shopvolt_session_id). Not linked to any personal identifier. - Impression events — which deal was shown, on which product, at what time. No PII.
- Order events (via Shopify Web Pixel) — line items, quantities, prices, and discount allocations for completed orders that contain a bundle. Used to attribute revenue and check whether the bundle discount was correctly applied at checkout. The Web Pixel runs in Shopify's sandboxed environment; we do not collect customer name, email, address, or any payment information.
From our infrastructure
Like any web service, our hosting platform records standard request metadata (IP address, user agent, request time) for security, abuse prevention, and reliability monitoring. We do not use this data for tracking or advertising.
2. How we use this data
- Run the bundle widget on your storefront and ensure the configured discount applies at checkout.
- Show you analytics — visitors, bundle orders, conversion rate, added revenue, and applied rate.
- Provide support when you contact us at support@shopvolt.io.
- Improve the product by identifying errors, bugs, and patterns in aggregated, non-personal data.
We do not sell your data, your customers' data, or any aggregated derivative of it. We do not use this data for advertising.
3. Legal basis for processing (GDPR)
If you or your customers are in the European Economic Area, we process data on the following bases:
- Contract — to provide the service you signed up for.
- Legitimate interest — to improve the service, prevent abuse, and provide support.
- Consent — where required (e.g. some web pixel signals where Shopify's customer privacy framework requires it).
4. Who has access to your data
Third-party sub-processors
We share data only with the third parties strictly required to deliver the service:
- Shopify — the platform on which the service operates. Your data is governed by Shopify's own privacy policy.
- Fly.io — our hosting and managed Postgres database provider (regions: Paris and Amsterdam). See Fly's privacy policy.
- Sentry — error tracking. Limited request metadata and stack traces for failed operations. See Sentry's privacy policy.
- Crisp — customer support chat. When you use the in-app chat, your message, shop domain, plan tier, and a compact diagnostic snapshot (deal count, sync status, error counts — no shopper PII) are shared with Crisp so we can respond. See Crisp's privacy policy.
We do not share data with advertising networks, data brokers, or any third party for marketing purposes.
Shopvolt support-team access
To provide support, our team may need to view and, where you've explicitly requested it, modify your app configuration on your behalf. This access is:
- Logged — every read and write action is recorded to an internal audit log with the operator's identity, timestamp, and affected resource.
- Purpose-limited — used only to diagnose issues you've reported, or perform maintenance actions you've explicitly requested (for example, fixing a mis-configured bundle after you email us).
- Restricted — access is limited to Shopvolt personnel with an authorized "support" role in our internal system, protected by strong authentication.
You can request a copy of the audit-log entries covering your shop at any time by emailing support@shopvolt.io.
5. How long we keep data
- Merchant configuration (deals, bars, modules, styles, translations) — for as long as you have the app installed. Deleted within 48 hours of uninstall, and immediately on receipt of Shopify's
shop/redactwebhook (which fires 48 hours after uninstall). - Analytics events (impression / click / order events tied to a bundle, plus the anonymous session ID) — retained for 24 months for cycle-over-cycle attribution and revenue reporting, then automatically deleted. Deleted immediately on receipt of Shopify's
customers/redactwebhook for the affected customer scope. - Subscription and billing records — retained for 7 years after the subscription ends, to meet accounting and tax record-keeping obligations. Contains plan tier, price, and cycle dates only — no payment-method data (that lives with Shopify).
- Audit log (support-team read and write actions against your shop's data) — retained for 12 months for security review, then automatically deleted.
- Application logs (request metadata, error traces) — retained for 90 days for security and reliability monitoring, then automatically rotated out.
Aggregated, anonymized statistics (e.g. "the average bundle raises AOV by X%") that cannot be traced back to a specific merchant or shopper may be retained indefinitely for service-improvement purposes.
6. Your rights
You have the right to:
- Access the data we hold about you.
- Correct data that is inaccurate.
- Delete data (right to be forgotten) — you can trigger this by uninstalling the app, or by emailing us.
- Export data in a portable format.
- Object to specific processing activities.
- Withdraw consent where processing is based on consent.
To exercise these rights, email support@shopvolt.io with your request. We respond within 30 days.
California residents (CCPA / CPRA)
If you are a California resident, you have the additional rights to know what personal information is collected, disclosed, or sold; to request deletion; to correct inaccurate information; and to opt out of any sale or sharing of personal information. Shopvolt does not sell personal information and does not share it for cross-context behavioral advertising. To exercise your CCPA rights, email support@shopvolt.io; we will not discriminate against you for exercising them.
UK residents
UK residents have equivalent rights under the UK GDPR; the same request process applies.
7. Security
Data is encrypted in transit (TLS) and at rest. Access to production systems is restricted to authorized personnel and protected by strong authentication. We follow industry best practices for application security and infrastructure hardening, and we will notify affected merchants without undue delay if we become aware of a personal-data breach.
8. Cookies and tracking
The Shopvolt app uses localStorage (not cookies) to store a single anonymous session ID on shopper devices, used solely for attributing bundle orders. We do not use third-party tracking cookies, advertising pixels, or fingerprinting techniques.
The Shopvolt admin app uses first-party session cookies set by Shopify's authentication library, required to keep you signed in.
The Shopvolt marketing site (shopvolt.io) does not currently use third-party analytics or advertising tools. If we adopt one in the future (for example a cookieless product-analytics tool), we will update this policy before enabling it.
9. International transfers
Shopvolt is operated from France. The primary production database and application servers are hosted in Fly.io's Paris (CDG) and Amsterdam (AMS) regions inside the European Economic Area. Some data is transferred to and processed in countries where our other infrastructure providers operate, including the United States (Shopify, Sentry, Crisp). Where a transfer leaves the EEA, we rely on the EU Standard Contractual Clauses (SCCs) or an equivalent safeguard published by the relevant provider.
10. Children
Shopvolt is a service for businesses and is not directed at children under 16. We do not knowingly collect personal data from children.
11. Changes to this policy
We may update this policy from time to time. When we do, we'll update the "Last updated" date at the top of this page. For material changes, we'll notify installed merchants by email.
12. Contact
Questions about this policy, requests to exercise your rights, or notifications of a suspected security incident?
Email: support@shopvolt.io
Shopvolt · France.