Overview
MerchantKit: Store Tools is a Shopify merchant toolkit for checkout rules, storefront warnings, store-health checks, and clearly identified future operational modules.
This Privacy Policy explains what information MerchantKit processes when a merchant installs and uses the app.
Information we collect
Shop information: store domain, shop name, contact email, plan, currency, timezone, and primary domain provided by Shopify.
App configuration: warning rules, warning copy, selected products, selected variants, product tags, display settings, validation settings, and storefront styling settings created by the merchant.
Checkout rule configuration: payment-method actions and conditions created by the merchant and stored on Shopify payment customizations through the Admin GraphQL API.
Consent records: rule name, rule version, warning title and message snapshots, checkbox label, product IDs, variant IDs, cart token, checkout ID, order ID when available, source page, acceptance status, and acceptance time.
Authentication and session data: Shopify OAuth/session records needed to keep the app installed and connected to the merchant's Shopify store.
Analytics information: page views, referrers, browser and device details, and interaction events on public MerchantKit pages when analytics tags are enabled.
Information we do not intentionally collect
MerchantKit does not intentionally collect payment card data, billing addresses, customer passwords, or unnecessary customer profile data.
MerchantKit is designed to store consent context rather than full customer identity. Shopify may provide order or checkout identifiers so consent evidence can be connected to the relevant transaction.
MerchantKit does not request or store payment credentials. Customer, cart, delivery, product, and B2B context used by checkout rules is evaluated transiently inside Shopify Functions and is not sent to the MerchantKit web server.
How we use information
We use shop and configuration information to render warning blocks on the storefront, match rules to products or cart contents, and enforce required acknowledgments when checkout validation is enabled.
We use Shopify Admin GraphQL to let merchants create, update, activate, and delete payment customizations. Shopify Functions evaluate those rules during checkout.
We use consent records to help merchants review what warning was shown, when it was accepted, and which product or variant context was involved.
We use technical and session information to authenticate the app, maintain security, troubleshoot issues, and comply with Shopify platform requirements.
Sharing and subprocessors
MerchantKit does not sell personal information.
MerchantKit shares data with Shopify as needed to provide the app, including app proxy requests, OAuth, webhooks, cart attributes, metafields, and checkout validation.
MerchantKit may use hosting, database, logging, and infrastructure providers to operate the app. These providers process data only as needed to deliver and maintain the service.
MerchantKit may use Google Tag Manager and Google Analytics on public MerchantKit pages to understand traffic and improve the website experience.
Cookies and local storage
MerchantKit may use Shopify session cookies or related browser storage as part of the embedded app authentication flow.
On the storefront, MerchantKit may use local storage to remember that a shopper accepted a warning version, so the same warning does not need to be acknowledged repeatedly unless the rule or cart context requires it.
Analytics tags may set or read cookies or similar browser storage on public MerchantKit pages when they are enabled.
Data retention and deletion
MerchantKit keeps app configuration and consent records while the app is installed or as otherwise needed to provide the service, support audit history, resolve disputes, or comply with legal obligations.
When Shopify sends a shop redaction request, MerchantKit deletes local shop data associated with that store. When Shopify sends a customer redaction request with order IDs, MerchantKit removes matching cart, checkout, order, and user-agent identifiers from consent logs where possible.
Merchant responsibilities
Merchants are responsible for the warning text they configure, how they use consent records, and whether their use of MerchantKit complies with laws and policies that apply to their store, products, and customers.
Merchants should avoid entering sensitive personal information into warning rules, descriptions, custom CSS, or other app settings.
Changes to this policy
We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a new effective date.
Contact
Questions about these terms or policies can be sent to [email protected].
MerchantKit