App privacy policy
Last updated .
This policy covers the Gatekeep Shopify app. This website is separate and collects nothing; see the site privacy policy. Use of the app is also governed by the app terms of service.
Who is responsible
For merchant account data, Gatekeep is the controller. For the customer data the app processes on a merchant's behalf during checkout, the merchant is the controller and Gatekeep is the processor, acting only on the merchant's instructions.
What the app reads
- Shop and account details
- Shop domain, shop ID, plan, contact email and installation state. Used to run the subscription and to contact you about the app.
- Product and collection data
- Titles, tags, types and IDs, so you can map your products to the regulated categories Gatekeep covers.
- Destination of an order in progress
- At checkout the app needs the shipping destination, in practice the state or province and postal code, to decide whether a rule blocks that order.
What the app does not do
It does not sell or rent data, does not use merchant or customer data to train models, does not build advertising profiles, and does not share data with anyone except the subprocessors listed below. It does not read payment card numbers: Shopify handles payment, and the app never sees card data.
Retention
Checkout destination data is used to make a decision and is not retained as a customer record beyond the log needed to show you why an order was blocked. Shop configuration is kept while the app is installed and deleted within 30 days of uninstall, subject to any legal retention duty.
Data deletion and the Shopify GDPR webhooks
Gatekeep implements the three webhooks Shopify requires:
customers/data_request— returns what the app holds about a named customer.customers/redact— deletes that customer's data.shop/redact— deletes the shop's data, sent by Shopify 48 hours after uninstall.
Subprocessors
Shopify, as the platform the app runs on, and the app's hosting and database providers. A current list must be published here before listing, naming each provider and the region its data sits in.
Your rights
Depending on where you live, you may have the right to access, correct, delete or port your data, to object to or restrict processing, and to complain to a supervisory authority. Under the GDPR the lawful bases relied on are contract, for running the app you installed, and legitimate interests, for keeping it secure. California residents have the rights described in the CCPA as amended, including that Gatekeep does not sell or share personal information as those terms are defined there.
International transfers
Where data is transferred out of the UK or EEA, transfers rely on the UK IDTA or the EU standard contractual clauses as applicable. The hosting regions must be stated here before listing.
Security
Data is encrypted in transit and at rest, access is limited to those who need it, and API credentials are held as secrets rather than in source control. No system is perfectly secure, and Gatekeep does not claim otherwise.
Contact
A monitored contact address must be published here before the app is listed. The Shopify App Store requires one, and a rights request needs somewhere to arrive.
Changes
Material changes will be notified in the app or by email to the shop's contact address before they take effect.