StoreCred

Privacy Policy

Last updated: July 20, 2026.

StoreCred ("we", "us") provides a Shopify app that automates store credit issuance for merchants. This policy explains what data we process, why, and what rights you have over it.

Controller and processor roles

If you're a merchant using StoreCred: you are the data controller for your customers' personal data. You decide to install the app and configure how it issues credit. We act as your data processor, handling that data only to provide the service, under your instructions (given by installing and configuring the app) and Shopify's platform terms.

If you're a customer of a store using StoreCred: your relationship is with that merchant, not with us directly. To exercise a data right (below), start with the merchant — we act on their instructions and Shopify's mandatory app webhooks route most such requests through them automatically. If you're unable to reach the merchant, contact us directly (see "Contact" below) and we'll assist.

If you gave us your email address on this website to be told when StoreCred launches: that one is different. There we are the controller, not a processor, because it's our own list rather than a merchant's data. See "Our launch waitlist" below.

Our launch waitlist

StoreCred isn't on the Shopify App Store yet, so this site offers a form to be notified when it goes live. If you use it:

Data we access

When a merchant installs StoreCred, we request the following Shopify access scopes:

Data we store

We keep a local record of each store credit transaction we issue (shop, customer reference, amount, trigger event, timestamp) so merchants can see why a customer's balance is what it is, and so we don't double-issue credit on a redelivered webhook. Shopify's own store credit ledger remains the source of truth for actual balances. We do not store payment card details — all payment and billing is handled by Shopify.

Data we send

If a merchant enables reminder emails, we send transactional email (via Cloudflare Email Sending) to the customer's email address on file, limited to: credit issued notifications and credit expiry reminders. We do not send marketing email to customers, and email content is not personalized beyond the credit amount and expiry date.

Legal basis for processing (GDPR)

We process customer data as a processor under the merchant's instructions, on the legal basis of the merchant's own basis for the underlying transaction — typically performance of a contract (fulfilling the store credit the customer was promised) or the merchant's legitimate interest in operating a loyalty/refund program. We don't independently determine a legal basis; that's the merchant's responsibility as controller, and this app is built to only process what's needed for the features the merchant turns on.

International data transfers

Our infrastructure is split across regions: application hosting and the database are in the EU (Hetzner, Germany). Transactional email sending (Cloudflare) and error monitoring (Sentry, when enabled) operate on global infrastructure and may process data outside the EU/UK, including in the United States. Where customer data is transferred outside the EU/UK we rely on the Standard Contractual Clauses incorporated into those providers' data processing agreements as the transfer mechanism.

Data retention

We retain transaction logs for as long as the app is installed, plus the redaction windows below after uninstall or a redaction request. Nightly database backups are encrypted and kept for 30 days, then deleted automatically — a redaction request removes the record from the live database immediately per the webhook below, and it ages out of backups within 30 days at the latest.

Your rights (GDPR / CCPA)

Depending on where you live, you may have the right to: access the data we hold about you, correct inaccurate data, request deletion, restrict or object to processing, receive your data in a portable format, and (California residents) opt out of the sale or sharing of personal information — we do not sell or share personal information with third parties for their own marketing purposes, so there is nothing to opt out of. To exercise any of these, contact the merchant whose store you interacted with, or us directly (below). EU/UK residents also have the right to lodge a complaint with your local data protection authority.

We implement Shopify's mandatory privacy webhooks to support these rights structurally:

Security

Data in transit is encrypted (HTTPS/TLS throughout, including to our subprocessors). Access to production systems is restricted to the app operator; database access requires server-level authentication. We don't store payment card data at all — that's handled entirely by Shopify.

Cookies

The embedded app runs inside Shopify admin and relies on Shopify's own session mechanism (App Bridge / session tokens) rather than setting its own tracking cookies.

The marketing site (this page and getstorecred.com) sets no advertising cookies and no cross-site tracking cookies. It does run Cloudflare Web Analytics, which measures page views without using cookies, without fingerprinting visitors, and without tracking people across sites. We mention it because "no cookies" and "no measurement at all" are different claims and only the first is true.

Children's privacy

StoreCred is a business tool for Shopify merchants and is not directed at children. We don't knowingly process data belonging to children.

Data Processing Agreement

A Data Processing Agreement (DPA) covering our processing of your customers' data as your processor is available on request — contact us below.

Changes to this policy

If we make a material change to how we handle data, we'll update the date at the top of this page and, where required, notify merchants directly.

Third parties

We use the following subprocessors:

Last verified against the application source on 2026-08-19. Amazon SES was listed here previously and is not a subprocessor — transactional email moved to Cloudflare on 2026-08-04 and this page had not been updated.

Who we are

StoreCred is operated by:

PROTFORGE SL
CIF B75512435
Avenida de Aragón 29, puerta 5
46010 Valencia, Spain
support@getstorecred.com

PROTFORGE SL is the data controller for the launch waitlist described above, and acts as a data processor on behalf of merchants for the customer data the app handles. Our lead supervisory authority is the Spanish Agencia Española de Protección de Datos (AEPD), aepd.es — and you may also complain to the data protection authority where you live.

Contact

Questions about this policy or a data request: support@getstorecred.com, or write to the postal address above.