Skip to content
CheckoutStack

Last updated August 7, 2026

Privacy policy

This describes what CheckoutStack does with data. It is written against the app's actual behaviour, not a template.

CheckoutStack (“CheckoutStack”, “we”, “us”) is a Shopify app operated by Digiforte Technologies, based in Saskatchewan, Canada. This policy covers the app, the checkout extension it installs, and this website.

In this policy, merchant means the Shopify store owner or staff member who installs and uses CheckoutStack, and buyer means a shopper going through that merchant’s checkout.

Roles

For merchant data, we act as a data controller. For anything processed on the merchant’s behalf inside their store, including the analytics described below, we act as a data processor and the merchant is the controller. Merchants are responsible for their own privacy disclosures to their buyers.

What we collect

From the merchant’s Shopify store

When a merchant installs the app, we store:

  • The store domain (for example yourstore.myshopify.com) and the Shopify access token that lets the app act on the store’s behalf.
  • The installing user’s Shopify account details as supplied by Shopify during authentication: name, email address, locale, and whether the account is the store owner. This is the standard Shopify session record.
  • Install state: when the store was onboarded, when blocks were last published, and the text of the last publishing error if one occurred, so it can be shown back to the merchant.

Content the merchant creates

Block configurations: the copy, tones, review text, trust items, image URLs, display rules, positions and A/B test settings the merchant enters in the app. This is the merchant’s own content. We store it so the app can show it back and publish it to their store.

From checkout

If the merchant enables analytics or an A/B test, the checkout extension sends us two kinds of event: a view when a block renders in a checkout, and a purchase when that checkout reaches the thank-you page. Each event row contains only:

  • the store domain,
  • the ID of the block that rendered,
  • which variant was shown, A or B,
  • the event type, view or purchase,
  • Shopify’s opaque checkout token for that checkout,
  • a timestamp.

The checkout token is what lets us count one checkout once and match a purchase to the view that preceded it. We do not receive or store buyer names, email addresses, phone numbers, shipping addresses, order contents, order values or payment information. No cookie is set on the buyer’s browser, and no advertising or third-party analytics script runs in checkout.

The buyer-facing part of a block does not call our servers at all. Block content travels to checkout inside a Shopify metafield, so a buyer who simply sees a block sends us nothing.

From this website

This site sets no cookies and runs no analytics or advertising scripts. If you use the support form, the name, email address, store URL and message you type are emailed to our support inbox and are not stored in a database by us. Our host, Vercel, keeps standard server logs including IP addresses for a short period as part of operating the service.

Why we process it

DataPurposeLegal basis (UK and EU)
Store domain, access token, sessionAuthenticate the app and publish blocks to the storePerformance of a contract
Merchant account details from ShopifyIdentify the account, send the one-time welcome emailPerformance of a contract
Block configurationsProvide the productPerformance of a contract
Checkout events and checkout tokenReport block performance and decide A/B resultsLegitimate interests of the merchant, as their processor
Support messagesAnswer the question you askedLegitimate interests

Who we share it with

We do not sell data and we do not share it for advertising. We use a small number of subprocessors to run the service:

  • Vercel (United States) hosts the app and this website.
  • Supabase (database hosted in AWS us-east-1, United States) stores the data described above.
  • Resend (United States) delivers the install welcome email and support email.
  • Shopify is the platform the app runs on and the source of the merchant and store data.

We will also disclose data if we are legally required to, or to protect our rights or the safety of others.

International transfers

Our infrastructure is in the United States. Where data originates in the UK, EEA or Canada, transfers rely on the relevant standard contractual clauses or equivalent safeguards in our agreements with the subprocessors listed above.

How long we keep it

  • Sessions and access tokens are deleted when the app is uninstalled.
  • Block configurations and install state are kept while the app is installed, so a reinstall does not lose the merchant’s work. They are deleted when Shopify sends a shop/redact request, which arrives 48 hours after uninstall.
  • Analytics events are deleted along with everything else for that store on shop/redact. A merchant can also ask us to delete them at any time.
  • Support email is kept in our mailbox for as long as it is useful for support history, and deleted on request.

Shopify’s mandatory data requests

CheckoutStack implements the three compliance webhooks Shopify requires.

  • customers/data_request and customers/redact: we hold no record keyed to a customer identity. These requests identify a buyer by customer ID and order ID, and the only buyer-adjacent value we store is a checkout token, which those requests do not contain. There is therefore nothing to return or erase.
  • shop/redact: we delete the store’s block configurations, its install state, and every analytics row belonging to it.

Security

Data is encrypted in transit. The app connects to its database as a dedicated least-privilege role rather than a superuser, row level security is enabled on every table with a policy scoped to that role alone, and the database’s public API roles have no grants, so Shopify access tokens are not reachable through it. Access to production is limited to the people who operate the service.

No system is perfectly secure. If we become aware of a breach affecting merchant data, we will notify affected merchants and the relevant authorities as required by law.

Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict or object to our processing of your personal data, to data portability, and to withdraw consent where we rely on it. Canadian merchants have equivalent rights under PIPEDA, and California residents under the CCPA and CPRA, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined under California law.

Write to support@checkoutstack.app and we will respond within 30 days. If you are in the UK or EEA and are not satisfied with our response, you may complain to your local supervisory authority.

If you are a buyer on a store that uses CheckoutStack, your relationship is with that merchant. Contact them first. We will support them in handling your request.

Children

CheckoutStack is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 16.

Changes

If we change this policy in a way that materially affects how we handle merchant data, we will update the date at the top of this page and notify installed merchants by email before the change takes effect.

Contact

Digiforte Technologies, Saskatchewan, Canada
support@checkoutstack.app

See also our terms of service.