Legal
Privacy Policy
Effective 10 October 2026
This policy describes how SRH Web Agency (“we”, “us”) handles information when merchants install and use the Shopify app Discountly:All in one Discount (discount campaigns powered by Shopify Functions and optional Theme App Extension widgets). It is written for Shopify’s App Store listing and for merchants who need to know what the app accesses on their shop.
Discountly:All in one Discount is a merchant tool. Shoppers on a merchant’s storefront may see offer widgets and receive discounts at Shopify checkout; they do not create an account with Discountly:All in one Discount.
1. Who is responsible
SRH Web Agency operates Discountly:All in one Discount and the production app at discountly.srhwebagency.com. Shopify remains responsible for the merchant’s store, Admin, and Checkout. Merchants remain responsible for their own storefront privacy notices to shoppers.
2. Shopify permissions we request
Discountly:All in one Discount uses the Shopify Admin GraphQL API (not the REST Admin API) for discount and catalog operations. After install, the app requests these access scopes:
write_discounts— create, update, and deactivate automatic and code discounts tied to your campaigns.read_products— read products, variants, and collections for targeting and storefront offer summaries.read_orders— read order totals and applied discount lines to store aggregate campaign usage metrics (no shopper PII).
Scope values are configured in the Partner Dashboard / app config and may change as features are added. Material scope changes require merchant re-authorization.
3. Merchant data we store
When a merchant installs the app, we store authentication and tenant-scoped records needed to run the embedded admin and campaigns:
- Session — Shopify offline/online session data (shop domain, access token, optional staff identity fields provided by Shopify OAuth).
- Shop — merchant shop domain and install metadata (for example install/uninstall timestamps, billing plan id, and development-store flags).
- ShopSettings — merchant preferences such as locale, default discount combining flags, and optional widget color / badge text. No shopper personal data.
- Campaign — merchant-configured discount campaigns (titles, rules, schedules, stacking preferences). No shopper personal data.
- ShopifyDiscountLink — references to Shopify discount GIDs created for those campaigns so the app can update or deactivate them.
- OrderDiscountMetric / CampaignUsageStat — optional aggregated, shop-scoped discount usage metrics from
orders/createwebhooks, on plans that include analytics: Shopify order id, order name (for example #1001), currency, subtotal and discount totals, and discount titles/values. We do not store customer names, emails, addresses, phone numbers, or discount code strings from those payloads. - ComplianceRequest — audit-only records of mandatory privacy webhook handling (no webhook body / no customer PII stored).
- QueueJob — background job payloads scoped to a shop when product features use the queue.
Checkout price calculations run inside Shopify Functions on Shopify’s infrastructure. Storefront theme widgets may display offer summaries written to app metafields (campaign titles, tiers, collection IDs) — not customer PII.
4. Shopper data
Discountly:All in one Discount does not create shopper accounts and is not intended to collect personal data from storefront visitors directly. Discounts are applied by Shopify at cart/checkout. If a shopper contacts the merchant about an order, that relationship stays between the merchant and Shopify.
5. How we use this data
- Authenticate the merchant and keep the embedded admin working
- Create and manage discount campaigns and linked Shopify discounts
- Optionally publish offer summaries for theme widgets
- Respond to Shopify compliance webhooks and support requests
- Operate hosting, database, and transactional email infrastructure
We do not sell merchant data.
6. Where data is stored
- Hostinger (Node.js) — the production app process that serves the embedded admin, public pages, and webhook endpoints runs on Hostinger.
- PostgreSQL (Supabase) — primary store for sessions, shop records, campaigns, settings, discount links, order discount metrics, compliance audit rows, and queued jobs. Access goes through Prisma. Every business table is scoped to the installing shop so one merchant’s rows cannot be read in another merchant’s session.
- PostgreSQL job queue — short-lived
QueueJobrows (job type and shop domain, for example cleanup retries) drained by a background worker. Jobs are not a second copy of your campaigns. - Shopify — your shop, Admin, Checkout, Billing, discount records, and Shopify Function execution stay on Shopify’s systems. Offer summaries for theme widgets are written to Shopify metafields on your shop and app installation.
- Email — if you submit the in-app Contact form, the message is sent by SMTP to our support inbox with your email as Reply-To. A copy may remain in that inbox (see retention).
Access tokens live in the shop’s session row and are used only to call the Shopify Admin GraphQL API for that shop. They are not copied into campaign, metric, or audit tables.
7. GDPR and Shopify privacy webhooks
For App Store distribution, Discountly:All in one Discount implements Shopify’s mandatory compliance webhooks. Shopify authenticates each request (HMAC) before we process it.
customers/data_request— Shopify asks us for data we hold about a customer. Discountly:All in one Discount does not store customer profiles or contact details, so we record an audit row and respond with HTTP 200 and a message stating that no customer personal data is persisted. Merchants may share that response with the shopper.customers/redact— Shopify asks us to erase a customer’s personal data. Because none is stored, there is nothing customer-specific to delete; we record an audit row (statusno_customer_pii) and return HTTP 200. If a future feature stores customer data, this handler must be extended before release.shop/redact— sent after uninstall when a shop’s data must be erased. We first try to remove app-created Shopify resources (widget metafields and app discounts) while a valid session exists, then delete sessions, queued jobs for that shop, and the shop row (campaigns, settings, discount links, and order metrics cascade). If deletion fails we return an error so Shopify retries; a successful purge writes an audit row with statuspurged.app/uninstalled— runs the same purge when you uninstall, without waiting forshop/redact. If the purge fails we enqueue a durable retry job and return an error so Shopify retries the webhook.
Audit table. Webhook receipts are stored in a separate ComplianceRequest table keyed by shop domain (not a foreign key to the shop), so evidence survives the shop purge. Each row holds only the shop domain, Shopify’s webhook request id, topic, status, and timestamp.
No raw PII in logs or database. Compliance webhook bodies are not stored. Application logs for these handlers record shop domain, topic, and request id — not customer names, emails, phone numbers, or addresses.
Other webhooks we subscribe to are operational only: orders/create (aggregate discount metrics, see above), app_subscriptions/update (billing plan state), and app/scopes_update (granted scopes).
8. Data retention
- While installed: sessions, shop record, campaigns, settings, discount links, and aggregate order metrics are kept so the admin, discounts, and optional widgets keep working.
- After uninstall: we delete sessions, queued jobs, and all shop-scoped rows when the
app/uninstalledwebhook is processed. If that cleanup fails, a retry job and Shopify’s webhook retries continue until it succeeds. - shop/redact: the same deletion path runs if any tenant data is still present when Shopify sends this webhook (typically within 48 hours of uninstall).
- Shopify-side objects: where a session is still valid at purge time we remove app-created widget metafields and app discounts. Anything we cannot reach (for example after the session is revoked) may remain in Shopify until you delete it in Admin.
- Compliance audit rows: kept after purge as evidence for Shopify and legal obligations. They contain no customer PII and are not used to run discounts.
- Support email: messages you send us may remain in our support inbox until we delete them.
- Backups: database provider backups may retain deleted rows for a limited rolling period before they expire.
You can also request deletion by uninstalling the app and/or contacting sohilhunani11@gmail.com.
9. Cookies
The embedded admin relies on Shopify’s session and App Bridge mechanisms, which may set session cookies or use browser storage so you stay signed in inside Shopify Admin. Our public pages (home, FAQ, Privacy, Terms) do not use advertising or cross-site tracking cookies and do not run third-party analytics.
The optional Theme App Extension widgets render offer information from Shopify metafields. They do not set a Discountly:All in one Discount cookie and do not write shopper identifiers to localStorage or sessionStorage. Merchants remain responsible for their own cookie banner and for any other apps or theme code on their storefront.
10. International transfers
The app process runs on Hostinger (Node.js) and data is stored in Supabase PostgreSQL. Shopify hosts your store, Billing, and Checkout. Depending on the regions those providers use, merchant data described above may be processed outside your country, including in the United States or EEA, to provide the app. Shopify also processes data under your agreement with Shopify. We rely on provider contracts and safeguards appropriate for operating a Shopify app. Because we do not store customer profiles, transfers of shopper personal data by Discountly:All in one Discount are not expected.
11. Your choices
- Uninstall the app from Shopify Admin to stop processing
- Contact sohilhunani11@gmail.com for privacy questions or deletion requests
- Review Shopify’s own privacy materials for Admin and Checkout data
12. Children
Discountly:All in one Discount is directed at merchants operating Shopify stores, not at children.
13. Changes
We may update this policy as the product or legal requirements change. The effective date at the top will be revised. Material changes may also be noted in the app or by email when practical.
14. Contact
Privacy requests: sohilhunani11@gmail.com
Also see our Terms of Service and FAQ.