Persistent Cart · Legal
PRIVACY POLICY
Persistent Cart — Privacy Policy
Effective date: 2026-10-01
This Privacy Policy applies to the Persistent Cart Shopify application ("App") published on the Shopify App Store. It is operated by PÉCI Kft., Aradi utca 5., 2119 Pécel, Hungary (Cg. 13-09-089813; EU VAT HU12761609) ("Company", "we", "us", "our"). The Company is established in the European Union.
1. Who this policy applies to
This policy covers two distinct categories of people:
Merchants — Shopify store owners and their admin users who install and configure the App. Merchants are the primary account holders and pay for the service.
Customers — end-users who browse and purchase from Merchant stores where the App is installed. The App processes limited pseudonymous data about Customers on behalf of Merchants.
Throughout this policy we label our role by capacity — as Controller or as Processor — wherever the distinction affects your rights or our obligations.
2. Our role under GDPR
For Merchant data (as Controller): The Company acts as data Controller (GDPR Art.4(7)). We determine the purposes and means of processing Merchant account and billing data.
For Customer data (as Processor): The Company acts as data Processor (GDPR Art.4(8)) on behalf of the Merchant, who is the data Controller. Merchants are responsible for their own legal basis for processing Customer data and for informing Customers that their store uses this App. If you are a Customer with questions about your data, contact the Merchant directly.
Scope of this notice, stated explicitly. This notice governs the App. Within it we hold two distinct roles and they do not overlap: we are Controller for Merchant data (Section 3a), and Processor on the Merchant's documented instruction for Customer data handled through the App (Section 3b), including the data generated when a person who has no prior relationship with that Merchant opens a Share a Cart link to that Merchant's store.
A full Article 28 Data Processing Agreement ("DPA") governing the processor relationship is published at https://peci.io/persistent-cart/dpa, is incorporated by reference into the Terms of Service, and is accepted together with the Terms of Service in the App's acceptance step, before the App is first used (Terms of Service, Section 3A). The DPA prevails over the Terms of Service and this Privacy Policy on any question of data protection (see Terms of Service, Order of Precedence).
EU representative (Art.27). Not applicable. The Company is established in the European Union (Hungary), so the Article 27 requirement to designate an EU representative does not apply.
3. Data we collect and why
3a. Merchant data (as Controller)
| Category | Examples | Source | Purpose | Legal basis (GDPR Art.6) |
|---|---|---|---|---|
| Shop identity | Shopify shop domain (mystore.myshopify.com) | Shopify OAuth | Service delivery, billing | Art.6(1)(b) — contract |
| Store contact e-mail | The store's contact e-mail address (Merchant record) | Shopify Admin API, read at installation | Service notices to the Merchant (plan-limit, billing-grace and upgrade e-mails) | Art.6(1)(b) (contract) for service notices; Art.6(1)(f) (legitimate interest) for upgrade suggestions |
| Authentication tokens | Shopify offline access token and refresh token (Session), Storefront Access Token (MerchantCredential) | Shopify OAuth | API access to merchant store | Art.6(1)(b) — contract |
| Billing and usage | Tier name, monthly cart/link/click counts, generated revenue estimate, plan cost, usage period dates, the dates on which usage and billing-grace notices were sent, link-quota and subscription-freeze flags | App internal | Billing enforcement, usage dashboards, suggesting a suitable App plan | Art.6(1)(b) — contract |
| Shop subscription plan | Shopify plan display name of the Merchant's store (e.g. Basic, Grow, Advanced, Plus) | Shopify Admin API, read live when the page loads | Suggesting a suitable App plan to the Merchant | Art.6(1)(f) — our legitimate interest in offering the Merchant a plan that fits its store |
| Configuration | Redirect-to-checkout toggle, cart icon display and icon type, cart-conflict dialog toggle, cart expiry days, attribution mode, share button and dialog CSS classes | Admin UI | Personalised App behaviour | Art.6(1)(b) — contract |
| App event log | Action type, timestamp, optional structured detail (AuditLog) | App internal | Debugging, GDPR webhook compliance, merchant analytics | Art.6(1)(f) — our legitimate interest in running, debugging and securing the App and in demonstrating that GDPR requests were handled |
| Terms acceptance record | Shop domain, the versions of the Terms of Service and the Privacy Policy accepted, time of acceptance, method (the in-app button), time of uninstall (TermsAcceptance) | App internal, when you click "I accept" | Proof of the contract and of the version accepted | Art.6(1)(f) (legitimate interest: establishing, exercising or defending legal claims) |
| Uninstall record | Shop domain, last plan name, uninstall timestamp (UninstalledRegistry) | App internal | Recognising a returning store: if the store reinstalls within 30 days, the installation record notes the reinstall and the previous plan | Art.6(1)(f) — legitimate interest |
At installation we read the store's contact e-mail address from Shopify and keep it with the shop record to send the service notices listed above; it is deleted with the shop record on uninstall (Section 5).
Plan suggestion. To help the Merchant pick a suitable App plan, the App may mark one plan as suggested. Immediately after installation, when no usage history exists yet, this suggestion is derived from the Shopify plan display name of the store, which is read live from the Shopify Admin API and is not stored. Once usage history exists, the suggestion is derived from the Merchant's own monthly cart and link counts already listed above. This is a display of data we already hold or read on the Merchant's behalf, involves no additional collection, and concerns the Merchant's own account only — no Customer data is used.
Providing the Merchant data above is a condition of using the App: without it the App cannot be installed or run.
3b. Customer data (as Processor — on behalf of Merchant)
We process the minimum data necessary to provide cart persistence and the Share a Cart feature. We do not store customer names, email addresses, postal addresses, phone numbers, payment information, or device fingerprints. We do not persist customer IP addresses in application data; transient processing of IP addresses may occur at the hosting/edge layer (Vercel/Neon) as an ordinary and unavoidable part of routing an internet request, and the App itself holds the requesting IP address briefly in memory to rate-limit requests that open shared links; no IP address is written to the App's database or retained by us.
| Category | Field(s) | Source | Purpose | Legal basis | Retention |
|---|---|---|---|---|---|
| Shopify customer identifier | Shopify customer ID (numeric, pseudonymous) | Shopify Storefront API, webhook | Keying a saved cart and cart token to a customer account | Art.28 — on documented Merchant instruction; Merchant's basis Art.6(1)(b)/(f) | Deleted at cart expiry (plan-dependent, see Section 5) or on shop/customer redact webhook |
| Cart token (stored hashed) | The one-way SHA-256 hash of the Shopify cart token; the raw token is never stored at rest (data minimisation, Art.5(1)(c)) | Shopify Storefront API | Retrieving the correct cart on any device | Art.28 — Merchant instruction | Same as above |
| Cart contents | Product variant IDs, quantities | Shopify Storefront API | Restoring the cart on login | Art.28 — Merchant instruction | Same as above |
| Share a Cart link contents | Product variant IDs, quantities | Customer action in storefront | Generating a shareable short URL | Art.28 — Merchant instruction | Deleted at link expiry (plan-dependent, see Section 5) |
| Link click event | Reference to the short link, or the cart token for a click through a cart-token link, or, for a checkout-direct link, the checkout token (each token stored only as its one-way SHA-256 hash, never raw); referring channel (a category: WhatsApp, Facebook, Instagram, other social, or direct; the web address itself is not stored); variant IDs; click timestamp (LinkClick) | Storefront widget or, for a checkout-direct link, a Shopify Web Pixel at checkout, in each case only when the Customer allows marketing in the store's consent settings | Attribution (recorded on all plans that offer Share a Cart); the analytics dashboard that surfaces it is a paid Pro/Advanced feature | Art.28 — Merchant instruction; recorded only with the Customer's marketing consent as signalled by Shopify's Customer Privacy API | Deleted when the associated share link expires (cascade with the Short URL); a click through a cart-token link is deleted by the daily cleanup once that cart token has expired, and on uninstall; all are deleted on the shop/customer redact webhooks |
| Order attribution | Shopify order ID, order name, total price, attribution method, cart token, referring channel, link-click reference, conversion timestamp (OrderConversion — no Shopify customer ID is stored; the order ID is a pseudonymous identifier and the cart token is stored only as its one-way hash) | Shopify order webhook | Order attribution (recorded on all plans); the analytics dashboard that surfaces it is a paid Pro/Advanced feature | Art.28 — Merchant instruction | Deleted on the shop/customer redact webhooks (on customers/redact: the rows matched by the customer's cart tokens or by the orders Shopify lists in the request); otherwise deleted after 365 days, or 30 days after the uninstall for an uninstalled shop |
The Shopify customer ID is a numeric platform identifier. It does not by itself reveal identity, but it constitutes pseudonymous personal data under GDPR Art.4(1) because it can be linked back to an individual by Shopify or by the Merchant. We process it solely to match a logged-in session to a saved cart.
Referring channel. The LinkClick record stores only a category for where a Share a Cart link was clicked (WhatsApp, Facebook, Instagram, other social, or direct, which also covers every other source), derived from the referring address the browser sends with the request; the address itself is not stored. It is used solely to attribute a recovered cart to the correct sharing channel in the Merchant's analytics. It is not used to profile individuals, is not enriched, and is deleted together with the click record (see the table above).
Attribution data is recorded on all plans, for Customers who allow marketing in the store's consent settings. The App logs link clicks (LinkClick) and attributes completed orders back to shared/recovered carts (OrderConversion) regardless of the Merchant's plan (on every plan, the App also uses it to recognise when it first produced an order for the Merchant); the analytics dashboards that surface this data are a paid feature available on the Pro and Advanced plans. This data is used only for attribution and is never used for advertising, resale, or profiling. See the "Shopify Protected Customer Data" section below.
Attribution and consent. Cart persistence is strictly necessary to deliver a service the Customer has actively requested, and it does not depend on consent. Link clicks and the order attribution built on them are marketing measurement: the storefront widget records a click only when the Customer allows marketing in the store's consent settings, as signalled by Shopify's Customer Privacy API, and records nothing where the store asks for consent and the Customer has not given it. An order is attributed to a shared link only through the cart token recorded with the click; orders of Customers whose click was not recorded are not attributed. For a Share a Cart link that takes the Customer straight to checkout, where the storefront widget does not run, the click is instead recorded by a Shopify Web Pixel at the start of checkout, on the same condition: only where the Customer allows marketing. The pixel reads the link code from the checkout attributes and the checkout token to attribute the resulting order, and holds no other personal data about the Customer. Wherever we store a cart token, we store its one-way SHA-256 hash and never the raw token, so the value at rest cannot serve as a live cart token (data minimisation, Art.5(1)(c)). Where the Merchant's jurisdiction requires consent for other processing through the App (e.g. under ePrivacy Directive Art.5(3), whose technical scope the EDPB addresses in its Guidelines 2/2023), the Merchant, as Controller, is responsible for obtaining it.
The person who opens a shared link. Someone who opens a Share a Cart link need not be a customer of that store, and may never have visited it before. We treat the data that click generates as Customer data under this Section: it is processed on the Merchant's documented instruction, solely so that the Merchant can attribute a recovered cart to the correct sharing channel, and never for a purpose of our own. The record holds no name, no email address, no postal address and no customer identifier, and we hold no other data about that person; it is deleted together with the share link, or, for a click through a cart-token link, once that cart token has expired.
4. How we use data
- Delivering the service: restoring carts on customer login, generating and resolving Share a Cart links, and tracking link clicks and order conversions for attribution (recorded on all plans; the resulting analytics dashboards are a Pro/Advanced feature).
- Billing and plan enforcement: counting monthly synced carts and links against tier limits, sending plan-limit notifications to merchants.
- Support and debugging: AuditLog entries help diagnose issues on request. We do not proactively monitor cart contents.
- GDPR webhook compliance: processing Shopify's mandatory privacy webhooks on behalf of the Merchant (see Section 8).
- Service improvement: aggregate, non-attributable usage metrics (e.g. total installs, tier distribution). No individual customer data is used for this.
We do not sell, rent, or share personal data with third parties for advertising or marketing.
5. Data retention
The three retention descriptions in this policy — this Section 5, the "Shopify Protected Customer Data" section, and the webhook mapping in Section 8 — describe the same rules; this Section 5 states them in full. For Customer data, the DPA prevails (Terms of Service, Section 20).
Customer data
| Plan | Cart persistence | Share a Cart link | Notes |
|---|---|---|---|
| Free | 2 days | 2 days | On every plan, expired records are deleted by the first scheduled cleanup after expiry |
| Basic | 7 days | 7 days | |
| Pro | 30 days | 30 days | |
| Advanced | 60 days | 60 days |
These are the defaults, and on two plans the Merchant can change them. On Pro and Advanced the Merchant may select a retention window from 7, 14, 30 or 60 days in the App settings; the value is validated against that list and anything else falls back to 7 days. So a Pro shop may run on 60 days and an Advanced shop on 7 -- the plan sets the default, not a ceiling. On Free and Basic the plan value is fixed and cannot be changed. 60 days is the absolute maximum on every plan, which is what makes the "2-60 days" figure used elsewhere in this document an outer bound rather than a range of defaults. The Merchant, as Controller, therefore determines the retention period within that bound.
A saved cart's expiry is set when the cart is saved and moves forward each time it is saved again, so the window runs from the Customer's last cart activity; a share link's expiry is set when the link is created. A temporary link record, created when a shopper opening a cart-token link has to choose between merging and replacing their cart, expires after one hour. Scheduled cleanup runs daily (Vercel Cron, approximately 03:00). On expiry, CartToken and SavedCart records are deleted. ShortUrl records are deleted at expiry; associated LinkClick records are deleted in cascade. LinkClick records made through a cart-token link are deleted in the same run once that cart token has been deleted. OrderConversion records are deleted on a redact webhook, and otherwise 365 days after they were created.
Merchant data — and what happens on uninstall / shop redaction
When a Merchant uninstalls the App, or when Shopify sends the shop/redact webhook, we purge all merchant and shop personal data and all Shopify access tokens (MerchantCredential) promptly — within 30 days of the triggering event, and typically within 48 hours of receiving the webhook. On uninstall we delete the Session (offline access token, refresh token), the Merchant record (including the store contact e-mail), MerchantCredential (Storefront Access Token), and the shop's Customer data (CartToken, SavedCart, ShortUrl, LinkClick). When Shopify's shop/redact webhook follows, we repeat those deletions, delete the operational AuditLog rows, and delete the OrderConversion records. If shop/redact does not arrive (a reinstall within 48 hours cancels it, or the webhook is lost), the scheduled cleanup deletes the operational AuditLog rows and the OrderConversion records itself, 30 days after the uninstall. Operations-monitoring entries are not stored per shop: they are kept under a shared system key and may name the shop domain in their details, so shop/redact does not reach them; the 90-day cleanup deletes them. AuditLog is the one exception and it is split: the operational rows (installs, quota events, billing changes) are deleted, while the GDPR compliance rows (customers/data_request, customers/redact, shop/redact) survive, as set out below. Access tokens are not retained after uninstall.
Records that survive uninstall: the UninstalledRegistry entry (shop domain, last plan name, uninstall timestamp), retained for 30 days so that a reinstall within that period is recognised and recorded with the previous plan, and then deleted by the scheduled cleanup; and a per-shop usage summary (MerchantUsageArchive: shop domain, plan tier, aggregate usage counters and revenue totals) together with the shop's plan/settings rows (MerchantUsage, MerchantSettings), retained for 30 days after uninstall for billing reconciliation and the prevention of plan-quota abuse through repeated reinstalls (legitimate interest, Art. 6(1)(f)), then deleted by the scheduled cleanup; and the GDPR compliance AuditLog rows (customers/data_request, customers/redact, shop/redact), retained for 3 years; and the Terms acceptance record (TermsAcceptance: shop domain, the accepted document versions, the times of acceptance and uninstall, the method), retained for 5 years after uninstall as the proof of the contract for the general limitation period (Hungarian Civil Code (Ptk.), Section 6:22), not deleted on shop/redact, and then deleted by the scheduled cleanup. Thirty days is the period within which the Shopify API License and Terms of Use (Section 6.2.3) require Merchant Data to be deleted after an uninstall. The compliance rows exist to prove that an erasure we performed was in fact performed: shop/redact arrives roughly 48 hours after an uninstall, so deleting them here would destroy, within two days, the record of an erasure carried out earlier. They hold Shopify's own request ids and row counts; they carry no customer identifier. The shop domain does stay in them, which is a business identifier; where the Merchant is an individual trader, it may also be the Merchant's personal data. None of these records contains customer personal data or access tokens.
Invoices and payout records for paid plans are issued and held by Shopify and kept in our accounting records, outside the App, for the period required by Act C of 2000 on Accounting (Art. 6(1)(c)); the App itself retains no billing record beyond the 30 days above. No customer personal data and no access tokens are retained for accounting purposes.
AuditLog entries for active Merchants are retained for 90 days, then purged by the scheduled cleanup. The single exception is the GDPR compliance rows named above (customers/data_request, customers/redact, shop/redact), which are retained for 3 years; 90 days remains the default, and any action nobody has classified keeps the short window.
Application logs. Separately from the database, the App writes application logs at the hosting provider (Vercel) for operation and troubleshooting. Request addresses are logged with their query string; for a logged-in customer, every storefront request to the App carries the Shopify customer ID there. Some log lines also contain the store contact e-mail address. They are kept for one day, the log retention of our hosting plan, and are not used for any other purpose.
6. Shopify Protected Customer Data
The App accesses Shopify Protected Customer Data. Specifically, it processes order data (Shopify order ID, order name, total price via the OrderConversion model; no Shopify customer ID is stored in OrderConversion; the order ID is a pseudonymous identifier and the cart token is stored only as its one-way hash) and the Shopify customer ID used to key a saved cart. We acknowledge this and comply with Shopify's Protected Customer Data requirements as set out below.
Protected scopes requested and why (minimum necessary).
| Data / scope accessed | Why it is necessary | Plans that use it |
|---|---|---|
| Shopify customer ID (supplied by Shopify with each storefront request of a logged-in customer; not a separate access scope) | Keys a saved cart and cart token to a logged-in customer so the cart can be restored on another device. Without it, cross-device persistence — the App's core function — is impossible. | All plans (for persistence) |
| Order data — id, name, total price, attribution fields (read, via order webhook) | Attributes a completed order back to a recovered or shared cart so the Merchant can see, in analytics, whether the App produced revenue. | Recorded on all plans; surfaced in the analytics dashboard on Pro/Advanced |
Access scopes. The App requests these Shopify access scopes: read_orders, write_products, unauthenticated_write_checkouts, unauthenticated_read_checkouts, unauthenticated_read_product_listings. write_products is used to store the App's storefront settings as metafields in the store.
We do not request or store Shopify Protected Customer Data Level 2 fields — customer name, email address, or physical/mailing address are neither requested nor stored by the App.
Mapping to Shopify's Level-1 requirements.
| Requirement | How the App meets it |
|---|---|
| Data minimization | We store only the identifiers and order fields listed above. No Level-2 PII (name/email/address). Attribution data is recorded on all plans that use Share a Cart; only the analytics dashboard that surfaces it is a paid Pro/Advanced feature. |
| Purpose limitation | Data is used only for cart persistence and order attribution (recorded on all plans; the analytics dashboard that surfaces it is a Pro/Advanced feature). It is never used for advertising, resale, or profiling. |
| Transparency | This policy, the Cookie Policy, and the DPA disclose exactly what is accessed, why, and for how long. Merchants must in turn disclose the App's use in their own customer-facing privacy policy. |
| Customer consent decisions | The App reads the Customer's marketing consent from Shopify's Customer Privacy API and records Share a Cart link clicks, and the order attribution built on them, only when marketing is allowed. Saving and restoring carts do not depend on it. Obtaining consent (the store's consent banner) is the Merchant's responsibility as Controller. |
| Optional processing | Link-click recording and order attribution, only for Customers who allow marketing. An order is attributed only through the cart token of a recorded click; there is no other matching mode. |
| Encryption | All data is encrypted in transit (HTTPS/TLS, with sslmode=require and channel_binding=require set on the database connection) and at rest, the latter provided by the database Sub-processor (Neon). Shopify access tokens are stored in the database and are therefore covered by that at-rest encryption. They are purged on uninstall and on shop redaction. |
| Retention limits | Data is retained only for the plan-based cart/link windows, or 365 days for order attribution, and is deleted on redact webhooks — see Section 5. |
Protected data is processed only to deliver the features the Merchant has enabled and is deleted on the customers/redact and shop/redact webhooks as described in Section 8.
7. Sub-processors and platform providers
Shopify is not our sub-processor. Shopify Inc. is the independent e-commerce platform and app marketplace on which both the Merchant and the App operate. In respect of storefront customer data, Shopify acts as an independent controller / platform under its own terms and privacy policy, not as a sub-processor engaged by us. Data reaches the App from Shopify; Shopify does not process on our instruction.
We engage the following sub-processors to deliver the service:
| Sub-processor | Role | Data shared | Region | Safeguard |
|---|---|---|---|---|
| Vercel Inc. | Application hosting and edge delivery | All data in transit; transient IP at edge | United States | EU–US Data Privacy Framework and/or SCCs (see Section 8 international transfers) |
| Neon, LLC (a Databricks, Inc. company) | PostgreSQL database hosting (provisioned via Vercel Marketplace) | All persisted data | United States | Databricks/Neon is certified under the EU–US Data Privacy Framework (the Databricks DPF certification covers Neon); SCCs stand as a fallback. Neon DPA; sub-processor list at neon.com/subprocessors |
| Amazon Web Services (Amazon Simple Email Service) | Delivery of the customer data e-mail to the Merchant when Shopify forwards a customer's access request (customers/data_request) | The data the App holds about the requesting customer, in transit only | eu-west-1 (Ireland, EU) | Processed within the EU; no third-country transfer for this processing |
Other service providers (Merchant data). For the Merchant data in Section 3a we also use the following providers, which process it on our behalf:
| Provider | Role | Data shared | Region | Safeguard |
|---|---|---|---|---|
| Amazon Web Services (Amazon Simple Email Service) | Sending the App's e-mails to the Merchant (plan-limit, billing-grace and upgrade notices) and operations alerts to the Company, which may name the affected shop domain | Store contact e-mail address, shop domain, plan and usage figures | eu-west-1 (Ireland, EU) | Processed within the EU; no third-country transfer for this processing |
| Telegram (Bot API) | Internal operations alerts to our own staff | Error counts and event type only; no shop domain, no Merchant or Customer identifying data | Not applicable | No personal data is sent to Telegram (the shop domain is stripped from the alert; it stays in our own e-mail and logs) |
We will notify Merchants of any new or replacement sub-processor at least 30 days in advance by email to the store's contact e-mail address, and Merchants may object as set out in the DPA (Section 6.4).
8. International transfers and data-subject rights
8a. International transfers
The App's application hosting (Vercel) and its database (Neon) are located in the United States. Because the Company is established in the European Union and processes personal data covered by the GDPR, transfers of that data to the United States are safeguarded as follows:
- EU–US Data Privacy Framework (DPF) is the primary transfer basis where the relevant United States sub-processor is certified under it. Vercel Inc. and Neon/Databricks are DPF-certified (see Section 7).
- The DPF adequacy decision is currently valid but subject to legal challenge before the EU courts. Accordingly, Standard Contractual Clauses (SCCs) adopted by European Commission Decision 2021/914 are incorporated into our agreements with United States sub-processors and stand as a standing operational fallback, not merely a theoretical one, so that transfers remain lawful if the DPF adequacy decision is invalidated.
United Kingdom. For transfers subject to the UK GDPR, the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU SCCs, applies to UK–US transfers, alongside the UK extension to the DPF where the sub-processor participates in it.
Canada. Processing of personal data subject to Canadian law is handled consistently with PIPEDA (the Personal Information Protection and Electronic Documents Act).
Australia. Processing of personal data subject to Australian law is handled consistently with the Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) scheme.
8b. Merchant rights (as data subjects of Controller processing)
Merchants may exercise GDPR rights (access, rectification, erasure, restriction, portability, objection) by contacting privacy@peci.io. We will respond within one month of receiving the request; where necessary, taking into account the complexity and number of requests, this may be extended by two further months, in which case we tell you within the first month (GDPR Art.12(3)).
Right to complain (Art.77) and supervisory authority. You have the right to lodge a complaint with a supervisory authority. The Company's lead supervisory authority is:
Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH) 1055 Budapest, Falk Miksa utca 9-11, Hungary Postal: 1363 Budapest, Pf. 9. Phone: +36 1 391 1400 Email: ugyfelszolgalat@naih.hu Web: naih.hu
You may also complain to a supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement (GDPR Art.77(1)).
8c. Customer rights (Processor context)
Because we act as a Processor for Customer data, Customers should direct data requests to the Merchant (the Controller). The Merchant is responsible for responding. Shopify automatically routes the following mandatory privacy webhooks to us on Merchants' behalf, and we act on them within the timelines below:
customers/data_request — When a customer exercises their right of access. The App compiles the data it holds about that customer (saved carts, cart references, the links they shared and their openings, orders attributed to a shared link, and the event-log entries naming them) and sends it by e-mail to the store's contact e-mail address, so the Merchant can include it in their answer to the customer; if the App holds nothing, the e-mail says so. Where the store has no contact e-mail address, we are alerted and send the data to the Merchant ourselves. The request is recorded in AuditLog with Shopify's request id and the outcome -- that entry is one of the GDPR compliance rows retained for 3 years (see Section 5), and it carries no customer identifier. Completed within 30 days.
customers/redact — When a customer exercises their right to erasure. We delete: all CartToken records for the customer ID on that shop; the SavedCart record for that customer; ShortUrl records created by that customer (customerId match); and the LinkClick records made through that customer's short URLs or cart tokens. OrderConversion records matched by the customer's cart tokens, or by the orders Shopify lists in the request (orders_to_redact), are deleted. AuditLog entries referencing the customer are deleted (matched on the customer id inside the entry, in both the string and numeric form the different code paths write). One new compliance AuditLog row IS written to record that the erasure happened: it holds Shopify's request ids and the row counts, and no customer identifier; it is retained for 3 years (see Section 5). Completed within 30 days, typically within 48 hours of receiving the webhook.
shop/redact — When a Merchant uninstalls and Shopify requests shop-level deletion (Shopify sends this typically 48 hours after uninstall). We delete all data associated with the shop: Session, Merchant, MerchantCredential (including all access tokens), CartToken, SavedCart, ShortUrl, LinkClick, and the operational AuditLog rows. The GDPR compliance AuditLog rows are retained for 3 years (see Section 5) -- they carry no customer identifier and are the proof that the erasure took place. OrderConversion records are deleted. The Terms acceptance record is retained for 5 years (see Section 5). The UninstalledRegistry entry and the usage-summary records (MerchantUsageArchive, MerchantUsage, MerchantSettings — no customer data, no tokens) are retained as described in Section 5. Completed within 30 days, typically within 48 hours of receiving the webhook. The UninstalledRegistry entry (non-personal, no tokens) is retained for 30 days after the uninstall, then deleted, as described in Section 5.
9. United States State Privacy Rights
This section is for residents of United States states with comprehensive privacy laws (such as California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana).
Customers of a Merchant's store. When you use a Merchant's store, the App processes your personal information on that Merchant's behalf. Under these laws we act as the Merchant's service provider / processor / contractor, not as a "third party", and the Merchant is the business responsible for your request. To access, delete, correct or port your data, or to exercise any other right your state gives you, contact the Merchant whose store you used. The Merchant will instruct us, and we will help the Merchant respond (see the DPA, Section 7).
Merchants. For the account and contact data we hold about Merchants and their staff, contact us at privacy@peci.io. The process in Section 8b applies.
We do not sell or share personal information as those terms are defined by the CCPA/CPRA. We do not use personal information for cross-context behavioural advertising, and we do not disclose it for monetary or other valuable consideration.
Sensitive personal information. The App does not seek to collect sensitive personal information (e.g. precise geolocation, government IDs, health, biometric, or protected-class data), and does not use any data to infer characteristics. We process only pseudonymous identifiers and cart/order fields as described in Section 3.
Minors (US). The App is a B2B tool directed at Merchants and is not directed to children. We do not sell or share personal information (see above), and so do not sell or share the personal information of consumers under 16.
De-identified data. Where we use de-identified or aggregated data (e.g. for service metrics), we maintain it in de-identified form, do not attempt to re-identify it, and contractually require the same of any recipient.
10. Article 28 DPA summary and where to find the full DPA
The full Data Processing Agreement under GDPR Art.28 is published at https://peci.io/persistent-cart/dpa, is incorporated by reference into the Terms of Service, and is accepted together with them in the App's acceptance step. It also contains the US service-provider/contractor terms referenced in Section 9. The DPA prevails over the other documents on any data-protection question. Key terms:
- Subject matter: processing Customer pseudonymous data to provide cart persistence and Share a Cart features on behalf of the Merchant.
- Duration: for as long as the App is installed, plus the retention periods in Section 5; deletion or return of data on termination.
- Nature and purpose: storage, retrieval and deletion of cart and attribution data as described in this policy.
- Type of personal data: pseudonymous customer identifiers, cart tokens, product variant IDs, click-event metadata (including the referring channel), order-attribution fields. No Level-2 PII.
- Categories of data subjects: end-customers of the Merchant's Shopify store, and recipients of a shared cart link.
- Processing on instructions only: we process personal data only on the Merchant's documented instructions, including as to international transfers, unless required by EU or Member State law (in which case we inform the Merchant unless the law prohibits it).
- Confidentiality of personnel: persons authorised to process the data are bound by confidentiality (Art.28(3)(b)).
- Security: appropriate technical and organisational measures (Art.32), as summarised in Section 11.
- Sub-processors: we engage sub-processors only under a written contract imposing the same data-protection obligations (flow-down); we give Merchants at least 30 days' prior notice of any new or replacement sub-processor and a right to object within that period (Art.28(2), (4)).
- Assistance with data-subject rights: we assist the Merchant, by appropriate technical and organisational measures, in responding to data-subject requests (Art.28(3)(e)).
- Assistance with security, breach, DPIA: we assist the Merchant with Art.32–36 obligations, including data protection impact assessments and prior consultation with the supervisory authority (Art.28(3)(f)).
- Breach notification: we notify the Merchant without undue delay, and in any event within 48 hours (DPA, Section 8.1), after becoming aware of a personal data breach (Art.33(2)).
- Deletion or return: before uninstalling, the Merchant may request a copy of its data (DPA, Section 9.5); uninstalling is the instruction to delete, and we delete existing copies unless EU/Member State law requires storage (Art.28(3)(g)).
- Audit and inspection: we make available all information necessary to demonstrate compliance with Art.28 and allow for and contribute to audits and inspections conducted by the Merchant or an auditor it mandates, subject to reasonable notice and confidentiality (Art.28(3)(h)).
- Order of precedence: the DPA prevails over the Terms of Service and Privacy Policy on data-protection matters.
11. Security
We implement appropriate technical and organisational measures including:
- HTTPS/TLS for all data in transit
- Database encryption at rest and in transit (at-rest encryption provided by the database Sub-processor, Neon; TLS in transit, with
sslmode=requireandchannel_binding=requireset on the connection) - Shopify API authentication tokens are stored in the database and are covered by that at-rest encryption. They are purged on uninstall and on shop redaction, and no token is retained afterwards.
- Access to production data limited to authorised personnel bound by confidentiality
- Automated daily expiry and deletion of Customer data per Section 5
We will notify affected Merchants without undue delay if we become aware of any personal data breach affecting personal data we process on your behalf. (As a processor, Article 33(2) GDPR imposes no risk threshold on this notification to the controller; the risk assessment governs only the Merchant-controller's own notification duties.)
12. Children
The App is directed at Shopify merchants (business users). We do not knowingly process personal data of children. Where the App operates on storefronts across the EU, the age of digital consent varies by Member State (between 13 and 16); the Merchant, as Controller of storefront customer data, is responsible for the applicable age threshold and for any parental-consent requirements. If you believe we have inadvertently processed a child's data, contact privacy@peci.io.
13. Changes to this policy
We review this policy at least once a year. We will notify Merchants of material changes to this policy by email at least 30 days before the change takes effect. The version of this policy in force when you accept the Terms of Service in the App is recorded with your acceptance (Terms of Service, Section 3A). The effective date at the top of this document is updated on each revision.
14. Contact
For privacy questions, data-subject requests, or the full DPA:
PÉCI Kft. Aradi utca 5., 2119 Pécel, Hungary Data / privacy matters: privacy@peci.io Legal notices: legal@peci.io Full DPA: https://peci.io/persistent-cart/dpa
We have not appointed a data protection officer, as GDPR Art.37 does not require one for our processing; privacy@peci.io is the contact for every data-protection matter.