Privacy Policy
Last updated: July 20, 2026.
StoreCred ("we", "us") provides a Shopify app that automates store credit issuance for merchants. This policy explains what data we process, why, and what rights you have over it.
Controller and processor roles
If you're a merchant using StoreCred: you are the data controller for your customers' personal data. You decide to install the app and configure how it issues credit. We act as your data processor, handling that data only to provide the service, under your instructions (given by installing and configuring the app) and Shopify's platform terms.
If you're a customer of a store using StoreCred: your relationship is with that merchant, not with us directly. To exercise a data right (below), start with the merchant — we act on their instructions and Shopify's mandatory app webhooks route most such requests through them automatically. If you're unable to reach the merchant, contact us directly (see "Contact" below) and we'll assist.
Data we access
When a merchant installs StoreCred, we request the following Shopify access scopes:
read_customers— to identify which customer a credit or refund belongs to.read_orders— to calculate cashback on paid orders.write_store_credit_account_transactions— to issue and adjust store credit via Shopify's native store credit system.
Data we store
We keep a local record of each store credit transaction we issue (shop, customer reference, amount, trigger event, timestamp) so merchants can see why a customer's balance is what it is, and so we don't double-issue credit on a redelivered webhook. Shopify's own store credit ledger remains the source of truth for actual balances. We do not store payment card details — all payment and billing is handled by Shopify.
Data we send
If a merchant enables reminder emails, we send transactional email (via Amazon SES) to the customer's email address on file, limited to: credit issued notifications and credit expiry reminders. We do not send marketing email to customers, and email content is not personalized beyond the credit amount and expiry date.
Legal basis for processing (GDPR)
We process customer data as a processor under the merchant's instructions, on the legal basis of the merchant's own basis for the underlying transaction — typically performance of a contract (fulfilling the store credit the customer was promised) or the merchant's legitimate interest in operating a loyalty/refund program. We don't independently determine a legal basis; that's the merchant's responsibility as controller, and this app is built to only process what's needed for the features the merchant turns on.
International data transfers
Our infrastructure is split across regions: application hosting is in the EU (Hetzner, Germany); transactional email sending (Amazon SES) and error monitoring (Sentry) may process data in the United States. Where customer data is transferred outside the EU/UK, we rely on our subprocessors' Standard Contractual Clauses (both AWS and Sentry publish and support SCCs for this purpose) as the transfer mechanism.
Data retention
We retain transaction logs for as long as the app is installed, plus the redaction windows below after uninstall or a redaction request. Nightly database backups are kept for a rolling window and age out on the same schedule — a redaction request removes the record from the live database immediately per the webhook below, and from backups within that backup's normal rotation period.
Your rights (GDPR / CCPA)
Depending on where you live, you may have the right to: access the data we hold about you, correct inaccurate data, request deletion, restrict or object to processing, receive your data in a portable format, and (California residents) opt out of the sale or sharing of personal information — we do not sell or share personal information with third parties for their own marketing purposes, so there is nothing to opt out of. To exercise any of these, contact the merchant whose store you interacted with, or us directly (below). EU/UK residents also have the right to lodge a complaint with your local data protection authority.
We implement Shopify's mandatory privacy webhooks to support these rights structurally:
customers/data_request— provides the merchant a copy of data we hold about a customer on request.customers/redact— deletes customer data we hold, 10 days after a customer request or 6 months after last engagement, per Shopify's requirements.shop/redact— deletes all shop data 48 hours after uninstall, per Shopify's requirements.
Security
Data in transit is encrypted (HTTPS/TLS throughout, including to our subprocessors). Access to production systems is restricted to the app operator; database access requires server-level authentication. We don't store payment card data at all — that's handled entirely by Shopify.
Cookies
The embedded app runs inside Shopify admin and relies on Shopify's own session mechanism (App Bridge / session tokens) rather than setting its own tracking cookies. The marketing site (this page and getstorecred.com) doesn't use analytics or advertising cookies.
Children's privacy
StoreCred is a business tool for Shopify merchants and is not directed at children. We don't knowingly process data belonging to children.
Data Processing Agreement
A Data Processing Agreement (DPA) covering our processing of your customers' data as your processor is available on request — contact us below.
Changes to this policy
If we make a material change to how we handle data, we'll update the date at the top of this page and, where required, notify merchants directly.
Third parties
We use the following subprocessors: Shopify (platform, billing), Amazon SES (transactional email, US), Sentry (error monitoring, no customer PII sent), Hetzner (hosting, Germany).
Contact
Questions about this policy or a data request: support@getstorecred.com.