Last updated August 7, 2026
Privacy policy
This describes what CheckoutStack does with data. It is written against the app's actual behaviour, not a template.
CheckoutStack (“CheckoutStack”, “we”, “us”) is a Shopify app operated by Digiforte Technologies, based in Saskatchewan, Canada. This policy covers the app, the checkout extension it installs, and this website.
In this policy, merchant means the Shopify store owner or staff member who installs and uses CheckoutStack, and buyer means a shopper going through that merchant’s checkout.
Roles
For merchant data, we act as a data controller. For anything processed on the merchant’s behalf inside their store, including the analytics described below, we act as a data processor and the merchant is the controller. Merchants are responsible for their own privacy disclosures to their buyers.
What we collect
From the merchant’s Shopify store
When a merchant installs the app, we store:
- The store domain (for example
yourstore.myshopify.com) and the Shopify access token that lets the app act on the store’s behalf. - The installing user’s Shopify account details as supplied by Shopify during authentication: name, email address, locale, and whether the account is the store owner. This is the standard Shopify session record.
- Install state: when the store was onboarded, when blocks were last published, and the text of the last publishing error if one occurred, so it can be shown back to the merchant.
Content the merchant creates
Block configurations: the copy, tones, review text, trust items, image URLs, display rules, positions and A/B test settings the merchant enters in the app. This is the merchant’s own content. We store it so the app can show it back and publish it to their store.
From checkout
If the merchant enables analytics or an A/B test, the checkout extension sends us two kinds of event: a view when a block renders in a checkout, and a purchase when that checkout reaches the thank-you page. Each event row contains only:
- the store domain,
- the ID of the block that rendered,
- which variant was shown, A or B,
- the event type, view or purchase,
- Shopify’s opaque checkout token for that checkout,
- a timestamp.
The checkout token is what lets us count one checkout once and match a purchase to the view that preceded it. We do not receive or store buyer names, email addresses, phone numbers, shipping addresses, order contents, order values or payment information. No cookie is set on the buyer’s browser, and no advertising or third-party analytics script runs in checkout.
The buyer-facing part of a block does not call our servers at all. Block content travels to checkout inside a Shopify metafield, so a buyer who simply sees a block sends us nothing.
From this website
This site sets no cookies and runs no analytics or advertising scripts. If you use the support form, the name, email address, store URL and message you type are emailed to our support inbox and are not stored in a database by us. Our host, Vercel, keeps standard server logs including IP addresses for a short period as part of operating the service.
Why we process it
| Data | Purpose | Legal basis (UK and EU) |
|---|---|---|
| Store domain, access token, session | Authenticate the app and publish blocks to the store | Performance of a contract |
| Merchant account details from Shopify | Identify the account, send the one-time welcome email | Performance of a contract |
| Block configurations | Provide the product | Performance of a contract |
| Checkout events and checkout token | Report block performance and decide A/B results | Legitimate interests of the merchant, as their processor |
| Support messages | Answer the question you asked | Legitimate interests |
Who we share it with
We do not sell data and we do not share it for advertising. We use a small number of subprocessors to run the service:
- Vercel (United States) hosts the app and this website.
- Supabase (database hosted in AWS
us-east-1, United States) stores the data described above. - Resend (United States) delivers the install welcome email and support email.
- Shopify is the platform the app runs on and the source of the merchant and store data.
We will also disclose data if we are legally required to, or to protect our rights or the safety of others.
International transfers
Our infrastructure is in the United States. Where data originates in the UK, EEA or Canada, transfers rely on the relevant standard contractual clauses or equivalent safeguards in our agreements with the subprocessors listed above.
How long we keep it
- Sessions and access tokens are deleted when the app is uninstalled.
- Block configurations and install state are kept while the app is installed, so a reinstall does not lose the merchant’s work. They are deleted when Shopify sends a
shop/redactrequest, which arrives 48 hours after uninstall. - Analytics events are deleted along with everything else for that store on
shop/redact. A merchant can also ask us to delete them at any time. - Support email is kept in our mailbox for as long as it is useful for support history, and deleted on request.
Shopify’s mandatory data requests
CheckoutStack implements the three compliance webhooks Shopify requires.
- customers/data_request and customers/redact: we hold no record keyed to a customer identity. These requests identify a buyer by customer ID and order ID, and the only buyer-adjacent value we store is a checkout token, which those requests do not contain. There is therefore nothing to return or erase.
- shop/redact: we delete the store’s block configurations, its install state, and every analytics row belonging to it.
Security
Data is encrypted in transit. The app connects to its database as a dedicated least-privilege role rather than a superuser, row level security is enabled on every table with a policy scoped to that role alone, and the database’s public API roles have no grants, so Shopify access tokens are not reachable through it. Access to production is limited to the people who operate the service.
No system is perfectly secure. If we become aware of a breach affecting merchant data, we will notify affected merchants and the relevant authorities as required by law.
Your rights
Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. Canadian merchants have equivalent rights under PIPEDA, and California residents under the CCPA and CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under California law.
Write to support@checkoutstack.app and we will respond within 30 days. If you are in the UK or EEA and are not satisfied with our response, you may complain to your local supervisory authority.
If you are a buyer on a store that uses CheckoutStack, your relationship is with that merchant. Contact them first. We will support them in handling your request.
Children
CheckoutStack is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.
Changes
If we change this policy in a way that materially affects how we handle merchant data, we will update the date at the top of this page and notify installed merchants by email before the change takes effect.
Contact
Digiforte Technologies, Saskatchewan, Canada
support@checkoutstack.app
See also our terms of service.