1. Scope and roles
This Policy explains how Digitdeck handles personal information when a Shopify merchant installs or uses the Digitdeck app, a shopper interacts with an enabled Digitdeck storefront feature, or a person contacts Digitdeck.
For shopper and customer data processed to provide a merchant-selected module, the merchant is generally the controller or responsible party and Digitdeck acts as its processor or service provider. Digitdeck acts as an independent controller for merchant account contacts, support, security, legal compliance, service analytics, and its own business administration.
2. Information processed
Depending on enabled modules and Shopify permissions, Digitdeck may process:
| Category | Examples | Source |
|---|---|---|
| Merchant and store | Store domain, Shopify IDs, locale, plan, configuration, administrator contact | Shopify and Merchant |
| Catalog and inventory | Product, variant, collection, inventory, price, eligibility metadata | Shopify |
| Orders and customers | Order/customer identifiers, discount applications, financial status, email when required | Shopify |
| Back in Stock | Email, variant identifier, subscription and notification state | Shopper |
| Reviews | Author name, email, rating, title, body, media/fields, product reference, moderation state | Shopper and Merchant |
| Referrals | Email/customer identifier, referral code, attribution, order identifier, reward and void status | Shopper, Merchant, Shopify |
| Experiments | Pseudonymous visitor/assignment ID, exposure, page context, funnel and conversion events | Storefront/Shopify customer events |
| AI features | Merchant prompts, brand profile, selected store context, generated drafts, token and credit usage | Merchant and provider |
| Technical/security | IP-derived abuse controls, timestamps, device/request metadata, audit and error records | Use of Service |
| Billing | Shopify subscription ID, plan, status, approval and usage state | Shopify |
Digitdeck does not intentionally collect payment-card numbers through the app and asks users not to send passwords, access tokens, one-time codes, or sensitive personal data through support or free text.
3. Purposes and legal bases
Digitdeck processes information to authenticate installations; deliver enabled modules; create discounts, rewards, and storefront features; send requested transactional email; measure usage and enforce plan limits; secure and debug the Service; provide support; comply with Shopify and legal requirements; and improve product reliability.
Where applicable, processing relies on performance of a contract, the Merchant’s instructions and consents, legitimate interests in secure and reliable operations, compliance with legal obligations, or consent. Digitdeck does not use shopper transactional email addresses for its own marketing without a separate lawful basis.
4. AI processing
AI features are optional and merchant initiated. Digitdeck sends only the context required for the requested generation to the configured AI provider. Merchants must not submit sensitive personal data. Output is a draft and may be inaccurate; it must be reviewed before publication. AI usage is subject to the AI Features Policy and the provider’s enterprise/API data terms applicable to Digitdeck’s account.
5. Sharing and subprocessors
Digitdeck shares information only with Shopify, authorized personnel, and service providers needed for hosting, databases, queues, transactional email, AI, security, or support. Providers are bound by confidentiality and data-protection obligations and may not use Merchant Data for their own unrelated purposes. The current list is published in the Subprocessor List.
Digitdeck does not sell or share personal information for cross-context behavioral advertising. Digitdeck may disclose information when legally required, to protect rights and safety, or as part of a corporate transaction subject to appropriate safeguards.
6. International transfers
Digitdeck and its providers may process information in Colombia, the United States, or the configured cloud region. Where required, Digitdeck relies on contractual safeguards, including applicable Standard Contractual Clauses, supplementary security measures, or another lawful transfer mechanism.
7. Retention and deletion
Digitdeck retains information only while needed for the documented purpose:
| Data | Normal retention |
|---|---|
| Active store configuration and module records | While installed and needed to provide the Service |
| Customer-linked records after a valid redaction request | Deleted or anonymized when the authenticated Shopify webhook is processed |
| Shop data after uninstall | Disabled immediately; deleted through Shopify’s shop-redact lifecycle and no later than required by Shopify’s API terms |
| Privacy request export | Encrypted and retained only while needed to fulfill and evidence the request |
| Security/audit records | Limited period proportionate to investigation, fraud prevention, and legal needs |
| Billing and legal records | As required for accounting, dispute, tax, or legal obligations |
| Backups | Restricted and expired under the production backup schedule; not restored for ordinary business use after a valid deletion |
Shopify’s mandatory customers/data_request, customers/redact, and shop/redact webhooks are
verified and processed. Deletion may exclude data that must be retained by law, but such data is
restricted to that purpose.
8. Security
Controls include OAuth, encrypted access tokens, TLS, HMAC verification, signed app-proxy requests, tenant-scoped database access, least privilege, secrets management, rate limiting, idempotent jobs, audit records, and incident-response procedures. No method of transmission or storage is completely secure.
9. Individual rights
Depending on law, individuals may request access, correction, deletion, restriction, portability,
withdrawal of consent, or objection. Shopify customers should normally contact the relevant
merchant first. Requests may also be sent to the privacy contact with the related
myshopify.com domain. Digitdeck may verify identity and authority and will coordinate with the
merchant or Shopify where appropriate.
Individuals may complain to their local supervisory authority. In Colombia, the data-protection authority is the Superintendencia de Industria y Comercio.
10. Children
The Service is directed to merchants and is not intended for children. Merchants must not configure Digitdeck to collect children’s personal data without a lawful basis, required parental consent, and Digitdeck’s prior written agreement.
11. Changes and contact
Material changes will be posted with a new date and notified where required. Questions, privacy requests, or complaints may be sent to digitdeck.servicios@gmail.com. Legal notices should identify the store domain and must not include passwords, tokens, or payment-card data.