Privacy policy

How AppsTint collects, uses, stores, and deletes merchant and customer data.

Effective date: July 15, 2026

AppsTint ("we", "us") provides a suite of Shopify apps for merchants. This policy explains what data we process, why, how long we keep it, and your rights.

App URL: portal.appstint.com
Support & documentation: support.appstint.com
Contact: privacy@appstint.com

Who this applies to

  • Merchants who install AppsTint on their Shopify store
  • Customers of those merchants who interact with AppsTint features on the storefront, checkout, or customer account

AppsTint does not sell personal data. We process data only to provide the app features the merchant enables.

What we collect

Merchant data

  • Shopify store domain, shop name, and country
  • OAuth access tokens (encrypted) to call Shopify APIs on the merchant's behalf
  • App configuration (calendars, upsell offers, protection rules, document templates, carrier credentials)
  • Billing status via Shopify App Pricing (we do not store payment card numbers)

Customer and order data

When a merchant activates an app, AppsTint may store order-scoped records derived from Shopify:

AppData stored
Delivery CalendarRequested delivery/pickup dates, order line items (mirror), calendar snapshots
UpsellOffer impressions and accept/decline events (no standalone customer profiles)
Store ProtectionOrder fingerprints: IP address, email, phone, normalized address line, COD flag, rule-match audit log
Shipping LabelsOrder GID, carrier, service, tracking number, label artwork (may include ship-to addresses)
DocumentsOrder data is fetched from Shopify at print time; templates are merchant-owned

We do not operate a separate customer database. Data is keyed by Shopify order ID and store.

How we use data

  • Deliver features the merchant activates (delivery dates, upsells, fraud screening, labels, documents)
  • Write delivery dates back to Shopify order metafields when configured
  • Screen orders against merchant-defined protection rules
  • Generate shipping labels through the merchant's own carrier accounts
  • Respond to mandatory Shopify GDPR webhooks (customers/data_request, customers/redact, shop/redact)
  • Maintain security, audit logs, and app reliability

We process data as a data processor acting on the merchant's instructions (GDPR Art. 28). Merchants are the data controllers for their customers. We process merchant account data to perform our contract with the merchant.

Data retention

  • Active installs: data retained while the app is installed and the merchant keeps the feature enabled
  • Customer redaction: when Shopify sends customers/redact, we delete all order-scoped records for the listed orders
  • Uninstall: when Shopify sends shop/redact (48 hours after uninstall), we permanently delete all data for that store
  • Logs: compliance and security logs may be retained up to 90 days

Data access requests

When a customer requests their data through Shopify, the merchant receives a customers/data_request webhook. AppsTint compiles an export of order-linked records (delivery dates, protection fingerprints, shipping label metadata) and records it in our audit log for the merchant to fulfil the request.

Security

  • All traffic uses HTTPS/TLS
  • Shopify access tokens and carrier credentials are encrypted at rest
  • Webhooks are verified with HMAC signatures
  • Embedded admin access uses Shopify session tokens (no third-party cookies)

Sub-processors

  • Shopify — hosting, OAuth, billing, APIs
  • Fly.io — application hosting (embedded app relay)
  • Laravel Cloud / your portal host — portal application and database

Carrier APIs (FedEx, UPS) are called only when the merchant configures Shipping Labels, using the merchant's own carrier account.

Merchant responsibilities

  • Activate only the apps you need
  • Configure protection rules and upsell offers appropriately
  • Complete Shopify's Protected Customer Data review if using customer account features
  • Respond to customer privacy requests using data from Shopify and AppsTint exports

Changes

We may update this policy. Material changes will be reflected on this page with a new effective date.

Contact

Questions about privacy: privacy@appstint.com