Privacy policy
This policy explains what Nock Deals accesses inside a Shopify store, whatNockSolutions stores on its own servers, and how that data is removed. It covers the app and this website.
Who we are
NockSolutions operates Nock Deals, a Shopify app that creates discount campaigns. For any question about this policy, or to make a data request, write tosupport@nocksolutions.app.
What the app is allowed to access
When a merchant installs Nock Deals, Shopify asks them to approve a fixed set of permissions. The app requests only what its features need.
| Permission | Why it is needed |
|---|---|
| Read and write products | To target campaigns at products and variants, and to attach the image badge. |
| Write discounts | To create and update the discount that applies a campaign at checkout. |
| Read orders | To attribute sales to the campaign that produced them, which is also how usage is measured for billing. |
| Read customers | To evaluate customer targeting, such as tags, logged-in status, and B2B versus D2C. |
| Read markets and locales | To restrict campaigns by country and to present the widget in the store's language. |
| Write files | To store badge images the merchant uploads. |
What we store
- Store details. The store's myshopify domain, name, currency, plan, locale and timezone, and the access token issued at install. Tokens are encrypted at rest.
- Campaign configuration. Everything a merchant types into a campaign, plus the widget and notification settings.
- Order lines a campaign discounted. The order's numeric identifier, the discounted line items, their price, quantity, discount and any refunds, and the numeric customer identifier.
- Aggregate storefront counts. How often the widget rendered, how often a discounted product was added to the cart, and which quantity level was chosen, counted per session.
- Billing state. Plan, packs, trial, and usage against the current 30-day period.
What we do not store
The app does not store customer names, email addresses, shipping addresses, phone numbers or payment details. Where an order is linked to a customer, only Shopify's numeric identifier is kept, which on its own does not identify a person outside the merchant's own Shopify admin.
Shoppers on a storefront
The widget runs on the merchant's product and cart pages. It reads what is on the page in order to show the right offer and reports anonymous counts back so the merchant can see how the campaign performs. It does not set advertising cookies and does not build a profile of a shopper across stores.
Service providers
We use a small number of processors, each for one job:
- Shopify. Source of all store data and the channel through which the app is billed.
- Google Cloud. Receives Shopify webhooks so events are never lost while the app restarts.
- Resend. Sends the app's notification emails, such as a quota warning.
- Crisp. Powers the support chat inside the app; a message you send there is stored by Crisp.
- Our hosting provider. Runs the application servers and database.
Deletion and data requests
- Uninstall. Uninstalling stops all processing for that store and revokes the access token.
- Store erasure. On Shopify's shop redaction request, every record belonging to that store is permanently deleted in one transaction.
- Customer erasure. On Shopify's customer redaction request, the numeric customer identifier is erased from the stored order lines.
- Customer data request. Because the app holds no data that identifies a customer beyond that numeric identifier, there is nothing further to return.
A merchant can also write to support@nocksolutions.appto ask for their store's data to be exported or deleted.
Retention
Campaign configuration and attributed order lines are kept while the app is installed, because they are what the analytics and the billing period are calculated from. After a redaction request they are deleted immediately rather than archived.
Security
Access tokens are encrypted at rest. Webhook payloads are verified against Shopify's signature before anything is written. The application database is not reachable from the public internet.
Changes
If this policy changes in a way that affects what is collected or who it is shared with, the date at the top changes and merchants are notified in the app.