Privacy Policy
Last updated: September 2026
This Privacy Policy explains how Checkout Rules ("we", "us") handles information when a merchant installs and uses the Checkout Rules Shopify app (the "Service"). By installing the Service, you agree to this policy.
Information we process
- Rule configuration:the order rules a merchant configures (minimum/maximum order value, quantity rules, blocked countries, allowed email domains, blackout days). This is stored as a metafield on the merchant's own Shopify store — we do not maintain a separate database of this data.
- Checkout data, read transiently:at the moment a customer checks out, the Service reads cart data needed to evaluate the merchant's configured rules — order total, item quantities, shipping country, buyer email domain, and whether the order is a B2B/company order. This data is used only to decide whether to allow or block that specific checkout; we do not store or retain it afterward.
- Session data:standard Shopify app authentication tokens needed to keep the app installed and connected to the merchant's store.
How we use information
- To evaluate and enforce the merchant's configured checkout rules.
- To let the merchant view and update their rule configuration in the app's settings page.
- To operate and secure the Service.
We do not use this data for advertising, profiling, or any purpose beyond the app's core functionality, and we do not sell it.
Billing
Subscription billing is handled entirely through Shopify's own Billing API, as part of the merchant's existing Shopify subscription. We never see or store payment card details.
Sharing & subprocessors
We share data only with Shopify, as the platform the Service runs on, and our hosting provider. We do not sell personal data to third parties.
Data retention & security
Rule configuration is retained for as long as the app remains installed and is removed by Shopify when the app is uninstalled. Checkout data used to evaluate rules is not retained after the checkout decision is made. We use industry-standard measures to protect data, though no system is perfectly secure.
Your rights
Merchants can access or update their rule configuration at any time from the app's settings page, and can request data deletion by uninstalling the app or contacting us directly.
Contact
Questions? Email support@foxrate.io.