Privacy Policy
Last updated July 27, 2026
What we deliberately don't store
Subscription Concierge does not store a subscriber's name, email address, or physical address in our own database. Every customer record we hold is keyed by Shopify's own opaque customer identifier — the actual name/email/address stays in Shopify, which remains the source of truth. We access Shopify's Customer and Order objects only through Protected Customer Data-gated APIs, and as of this writing we have not requested that access — we've deliberately deferred it until a specific feature actually needs it, rather than collecting it preemptively.
Data we collect from merchants (via Shopify OAuth)
| Data | Why |
|---|---|
| Product & variant details | To let you configure subscription tiers, bundles, and checkout upsell rules |
| Subscription contract IDs, billing dates, status | Core subscription management — skip/pause/resume/swap/reschedule, dunning, anchoring |
| Shopify OAuth access token | Authenticates our API calls to your store. Encrypted at rest; never logged or displayed in plain text. |
| Staff account emails & roles | So your team can log into the merchant dashboard with appropriate permissions (Admin/Viewer) |
Data we collect from your customers (storefront self-service portal)
When a shopper uses the customer portal (skip, pause, swap, reschedule, combine subscriptions, or request cancellation), we store: their Shopify customer identifier, their subscription/queue state, and any cancellation reason they choose to provide. We identify them via Shopify's own signed App Proxy session — we don't ask for or store a separate login/password.
How data is protected
- Encryption at rest — OAuth access and refresh tokens are encrypted before being written to the database; losing the encryption key would make stored tokens unrecoverable (which is by design — it means the key is never stored alongside the data it protects).
- Encrypted backups — daily database backups are encrypted with a public key whose private counterpart is kept offline, not on the server that produces the backups.
- Staff access logging — every time someone on your team views a customer or subscription record through the dashboard, it's logged (who, what, when) and visible to admins in the dashboard's Access Log.
- Data retention — canceled-subscription history and staff access-log entries are automatically purged after 365 days. Data tied to an active subscription is kept for as long as the subscription is active.
- Multi-tenant isolation — every record is scoped to a specific shop; one merchant's data is never visible to another.
Infrastructure & subprocessors
Subscription Concierge is hosted on our own server infrastructure, sitting behind Cloudflare for DNS, TLS, and basic traffic analytics (page views/visit counts — not behavioral ad tracking). We don't use third-party advertising trackers. Session authentication in the merchant dashboard uses browser local storage, not cookies.
Your rights & deletion
We support Shopify's mandatory privacy webhooks: customers/data_request,
customers/redact, and shop/redact. When a merchant uninstalls the app, or a data
erasure request comes through Shopify, associated subscription, queue, dunning, and access-log records for that
shop (or customer) are deleted. If you're a merchant's customer and want to make a data request directly,
contact your merchant, or reach us at [email protected].
Security incidents
If we confirm an incident affecting merchant or customer data, we notify the affected store owner directly, without undue delay and no later than 72 hours after confirmation, including what happened, what data was affected, and what we've done about it.
Changes to this policy
We'll update this page if what we actually do changes, and update the "last updated" date above. We don't expect to make retroactive changes that materially expand what we collect without letting merchants know first.
Contact
Questions about this policy or how your data is handled: [email protected].