Privacy Policy
Effective date: 21 April 2026 Last updated: 21 April 2026
This Privacy Policy explains how Shopify Discount Engine (“we”, “us”, “our”) handles information in connection with the Shopify Discount Engine application (the “App”) and this documentation website (the “Site”).
We aim to collect the minimum data needed to operate the App, support merchants, and improve the product. We do not sell personal information.
Who we are
Shopify Discount Engine is a Shopify application that applies tier, bundle, split bundle, and trade discounts at checkout and POS using Shopify Functions. The App is distributed via custom install link to approved merchants and is not currently listed on the Shopify App Store.
If you have any questions about this policy, contact hassan.jsx@gmail.com.
Information we collect
From merchants who install the App
When the App is installed on a Shopify store, Shopify provides us with information necessary for the App to function, including:
- Store identifiers: shop domain, store ID, plan, primary locale, currency, and time zone.
- Discount configuration: the discount rules you create in Shopify Admin (mode, products, variants, tiers, codes, platform, and similar settings) so the App can apply them to carts.
- Cart and order data at evaluation time: Shopify provides cart contents (line items, quantities, prices, customer tags, discount codes) to the discount function at checkout and POS so the function can return the correct discount. This data is processed in-flight by Shopify Functions and is not stored on our infrastructure beyond what is required to serve the request.
- Authentication tokens: access tokens issued by Shopify so the App can read configuration and write discount definitions.
We do not request or store customer personal data beyond what Shopify supplies to the discount function for the duration of evaluating a single cart.
From visitors to this Site
When you visit the Site we receive standard request data, including IP address, user-agent, referrer, and timestamps. We use Vercel Analytics and Vercel Speed Insights to measure aggregate traffic, page performance, and Core Web Vitals. These tools are configured to use privacy-friendly, cookie-less measurement where available; please review Vercel’s privacy notice for details on their processing.
We do not run advertising trackers on this Site.
Information you provide directly
If you contact us by email or request access to the App, we receive the information you choose to share (name, email address, store URL, message contents) and any follow-up correspondence.
How we use information
We use the information described above to:
- Operate, maintain, and improve the App and Site.
- Apply discounts at checkout and POS as configured by the merchant.
- Provide support, respond to enquiries, and assist with installation.
- Diagnose issues, prevent abuse, and improve performance and reliability.
- Communicate operational notices (security advisories, breaking-change notifications, billing, and similar service messages).
- Comply with legal obligations.
We do not use App data or Site data for advertising, profiling, or to train third-party machine-learning models.
Legal bases (where applicable)
Where the EU/UK GDPR or similar laws apply, we rely on the following legal bases:
- Contract: to provide the App to merchants who have installed it.
- Legitimate interests: to secure, maintain, and improve our services, and to communicate with merchants about the App.
- Consent: where required, for example for any optional analytics that require consent in your jurisdiction.
- Legal obligation: to comply with applicable laws and lawful requests.
Sharing and sub-processors
We share information only with parties that help us operate the App and Site:
- Shopify — platform provider and payment processor; Shopify provides the cart, customer, and store data the App processes.
- Vercel — hosting, edge delivery, analytics, and speed insights for the Site.
- Email providers — to receive and respond to support enquiries.
We do not sell personal information. We may disclose information if required by law, to enforce our terms, or to protect the rights, property, or safety of our users or the public.
Data retention
- Discount configuration: retained for as long as the App remains installed. When you uninstall the App or delete a discount, the corresponding configuration is deleted within 30 days.
- Authentication tokens: revoked when the App is uninstalled.
- Support correspondence: retained for up to 24 months unless a longer period is required by law.
- Analytics: retained per Vercel’s default retention windows.
Security
We use industry-standard safeguards to protect data, including TLS in transit, access controls, and least-privilege credentials. Shopify Functions execute inside Shopify’s sandboxed runtime; we do not operate a separate server-side discount evaluation pipeline. No method of transmission or storage is perfectly secure, but we work to protect your information and to notify you of material incidents as required by applicable law.
Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to our processing of your personal information, and to data portability. To exercise these rights, email hassan.jsx@gmail.com. We will respond within the timeframes required by applicable law.
You also have the right to lodge a complaint with your local data protection authority.
International transfers
We are based in Australia, and our service providers (including Shopify and Vercel) operate globally. Where personal information is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses or equivalent mechanisms recognised by the receiving jurisdiction.
Children
The App and Site are not directed to children under 16, and we do not knowingly collect personal information from them.
Cookies
We do not set advertising or tracking cookies. The Site may set strictly necessary cookies (for example, to remember theme or layout preferences if applicable) and Vercel may set short-lived measurement cookies where its cookie-less mode is unavailable.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page. Material changes will be communicated to merchants by email or in-App notice where appropriate.
Contact
Questions, complaints, or data requests:
hassan.jsx@gmail.com