Stackproof Bundles

How we handle data

A record-by-record explanation of what this version processes, stores, and retains.

  • Shopify app
  • Version in development

01

Summary

This page describes the version in development, not a public Marketplace listing. Read the privacy policy for the legal terms.

Stackproof stores the minimum merchant installation data needed to authenticate the embedded app, reject duplicate webhooks, and report aggregate offer performance. It does not retain customer or order payloads or identifiers.

Personal data stored
Yes. See the records below.
What happens after uninstall
Product-owned records are deleted on uninstall.
Where data is sent
Runtime data stays between the Shopify APIs and the app's Cloudflare Worker and D1 database. No additional analytics or advertising service receives it.

02

Records and retention

Shopify installation sessions

Purpose
Authenticate a shop and, for online sessions, its associated Shopify user.
Location
Cloudflare D1
Retention
Shop domain, OAuth token, scopes, and optional Shopify user identifier remain for the active installation and are deleted on uninstall or shop-redaction.

Webhook replay receipts

Purpose
Prevent the same signed webhook from being processed twice.
Location
Cloudflare D1
Retention
Webhook identifier, topic, and shop domain expire after 24 hours.

Offer rules

Purpose
Configure bundle, volume, and gift behavior for Shopify Functions.
Location
Shopify-owned app metafields
Retention
Rules follow the Shopify installation and metafield lifecycle; Stackproof does not copy them into D1.

Storefront offer events

Purpose
Report offer impressions, selections, cart additions, and seven-day last-touch checkout revenue by currency.
Location
Cloudflare D1
Retention
Installation-scoped event IDs, offer IDs and kinds, timestamps, and browser-reported checkout attribution totals/currencies are deleted by an hourly cleanup 90 days after Worker receipt and on uninstall or shop-redaction. A durable installation-scoped pixel token and a 120-events-per-minute-per-Cloudflare-location installation limit protect public ingestion; neither authenticates purchases. No customer, checkout, order, or browser identifier is stored.

03

Privacy

Read the privacy policy for the legal terms that apply to this product and the support channel.