← Back to Checkout Upsell Engine Shopify App Privacy Policy

Privacy Policy

Last Updated: October 8, 2026 • Effective Date: October 8, 2026

1. Introduction & Overview

Checkout Upsell Engine ("we", "our", or "the App") is developed and operated by ModApps ("ModApps-Dev"). This Privacy Policy describes how we collect, process, and protect merchant and customer data when you install and use the Checkout Upsell Engine app on your Shopify store.

We are committed to full compliance with the European Union General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and Shopify's Partner Security & Privacy Requirements.

2. Information We Collect

When you install and use the App, we collect only the minimum required data to operate checkout extensibility features:

  • Merchant Store Information: Store primary domain (e.g. myshopify.com), store owner email, installed app scopes, and app plan subscription status.
  • Campaign Configuration: Threshold dollar amount, reward types, product variant IDs, order bump title, and add-on pricing configured in the Shopify Admin.
  • Aggregated Telemetry Data: Total widget impression counts, bump conversions, and revenue lift amounts to calculate metrics on your dashboard.

Important: We NEVER collect, process, or store credit card numbers, CVVs, or full payment credentials. All payment processing is handled exclusively by Shopify's native PCI-DSS certified checkout infrastructure.

3. How We Use Information

We use the collected information solely for:

  • Rendering reactive Free Shipping progress bars and Order Bumps during checkout sessions.
  • Computing return on investment (ROI) analytics on your Polaris dashboard.
  • Processing recurring application charges through the official Shopify Billing API.
  • Diagnosing technical issues and delivering customer support.

4. GDPR & Data Subject Rights

We fully support automated GDPR compliance webhooks provided by Shopify:

  • Customers Data Request (customers/data_request): We fulfill requests for any customer data within 30 days.
  • Customers Redact (customers/redact): We automatically purge any requested personal data.
  • Shop Redact (shop/redact): When a merchant uninstalls the App, all associated store sessions, campaign configurations, and analytics records are permanently purged within 48 hours.

5. Data Storage & Security

All database records are stored in encrypted PostgreSQL databases utilizing industry-standard TLS 1.3 encryption in transit and AES-256 encryption at rest. We never sell, rent, or trade merchant or customer data to third-party advertisers or data brokers.

6. Contact & Data Protection Officer

If you have any questions or wish to exercise your data privacy rights, please contact our support team:

ModApps Data Protection Team

Email: support@modapps.dev

Website: https://modapps.dev