Skip to content

Privacy policy

Last updated 22 September 2026

This policy explains what Nock Deals accesses inside a Shopify store, whatNockSolutions stores on its own servers, and how that data is removed. It covers the app and this website.

Who we are

NockSolutions operates Nock Deals, a Shopify app that creates discount campaigns. For any question about this policy, or to make a data request, write tosupport@nocksolutions.app.

What the app is allowed to access

When a merchant installs Nock Deals, Shopify asks them to approve a fixed set of permissions. The app requests only what its features need.

PermissionWhy it is needed
Read and write productsTo target campaigns at products and variants, and to attach the image badge.
Write discountsTo create and update the discount that applies a campaign at checkout.
Read ordersTo attribute sales to the campaign that produced them, which is also how usage is measured for billing.
Read customersTo evaluate customer targeting, such as tags, logged-in status, and B2B versus D2C.
Read markets and localesTo restrict campaigns by country and to present the widget in the store's language.
Write filesTo store badge images the merchant uploads.

What we store

  • Store details. The store's myshopify domain, name, currency, plan, locale and timezone, and the access token issued at install. Tokens are encrypted at rest.
  • Campaign configuration. Everything a merchant types into a campaign, plus the widget and notification settings.
  • Order lines a campaign discounted. The order's numeric identifier, the discounted line items, their price, quantity, discount and any refunds, and the numeric customer identifier.
  • Aggregate storefront counts. How often the widget rendered, how often a discounted product was added to the cart, and which quantity level was chosen, counted per session.
  • Billing state. Plan, packs, trial, and usage against the current 30-day period.

What we do not store

The app does not store customer names, email addresses, shipping addresses, phone numbers or payment details. Where an order is linked to a customer, only Shopify's numeric identifier is kept, which on its own does not identify a person outside the merchant's own Shopify admin.

Shoppers on a storefront

The widget runs on the merchant's product and cart pages. It reads what is on the page in order to show the right offer and reports anonymous counts back so the merchant can see how the campaign performs. It does not set advertising cookies and does not build a profile of a shopper across stores.

Service providers

We use a small number of processors, each for one job:

  • Shopify. Source of all store data and the channel through which the app is billed.
  • Google Cloud. Receives Shopify webhooks so events are never lost while the app restarts.
  • Resend. Sends the app's notification emails, such as a quota warning.
  • Crisp. Powers the support chat inside the app; a message you send there is stored by Crisp.
  • Our hosting provider. Runs the application servers and database.

Deletion and data requests

  • Uninstall. Uninstalling stops all processing for that store and revokes the access token.
  • Store erasure. On Shopify's shop redaction request, every record belonging to that store is permanently deleted in one transaction.
  • Customer erasure. On Shopify's customer redaction request, the numeric customer identifier is erased from the stored order lines.
  • Customer data request. Because the app holds no data that identifies a customer beyond that numeric identifier, there is nothing further to return.

A merchant can also write to support@nocksolutions.appto ask for their store's data to be exported or deleted.

Retention

Campaign configuration and attributed order lines are kept while the app is installed, because they are what the analytics and the billing period are calculated from. After a redaction request they are deleted immediately rather than archived.

Security

Access tokens are encrypted at rest. Webhook payloads are verified against Shopify's signature before anything is written. The application database is not reachable from the public internet.

Changes

If this policy changes in a way that affects what is collected or who it is shared with, the date at the top changes and merchants are notified in the app.