Merchant and staff account data

Givnori stores the merchant's myshopify.com domain, internal shop identifier, account status, currency, time zone, Shopify app installation identifier, installation dates, and subscription plan, status, billing period, trial, and pending-plan information.

Shopify session records contain a session identifier, OAuth state, whether the session is online or offline, granted scopes, expiry, and the access token. When Shopify issues or supplies them, Givnori also stores a refresh token and its expiry, plus the staff user's Shopify user identifier, first and last name, email address, locale, and account owner, collaborator, and email-verification flags. Tokens remain on the server and are never included in storefront configuration.

Campaign and test-case data

Campaign records contain the campaign identifier, name and status; threshold, currency, start and end dates; eligible product identifiers; gift product and variant identifiers; gift labels, variant labels, image URLs and availability; merchant-written storefront messages, translations and locales; version history; and publication or error state. Givnori also stores identifiers and verification records for app-owned Shopify discounts, published storefront configuration, subscriptions, and background jobs.

Saved test cases contain a merchant-provided case name; product and variant identifiers and titles from the shop's product catalog; simulated quantities, prices and availability; and the calculated threshold, eligibility and expected gift result. These cases are generated for campaign rehearsal and are not copied from a buyer, customer record, cart, or order.

Buyer data we do not collect

Givnori requests only Shopify product-read and discount-management access. It does not request customer or order access, and it does not read or store buyer customer profiles, customer identities, orders, payment details, or browsing histories. The storefront extension reads current Shopify cart contents in the buyer's browser to evaluate eligibility and update the selected gift. It does not transmit or save those cart contents in the Givnori database.

How and why data is used

Merchant and staff data is used to authenticate the shop, configure and preview gift-with-purchase campaigns, synchronize app-owned discounts and storefront configuration, administer subscriptions, recover interrupted jobs, prevent duplicate writes, and support the merchant.

Service providers and processing locations

Shopify provides installation, authentication, product and discount APIs, app billing, storefront cart services, and privacy webhooks. DigitalOcean provides Givnori's Web hosting and PostgreSQL database in its NYC region in the United States. The provider that operates our support email processes the sender's address, message, attachments, and shop domain only when someone contacts support.

If a merchant or staff user is outside the United States, use of Givnori transfers the data described above to the United States for DigitalOcean hosting. Shopify and the support email provider may process data in other countries under their own terms and privacy notices. Givnori does not send campaign data to advertising, analytics, AI, email-marketing, SMS, or data-broker services.

Uninstall, redaction, and retention

While Givnori is installed, records are retained for the service and its recovery and security needs. When Shopify sends an app-uninstalled event, Givnori immediately deletes the shop's stored access and refresh tokens and other session fields, hides its published storefront configuration, pauses campaigns, and marks linked discounts for verification. Campaign, subscription, and job records remain temporarily until Shopify sends the shop redaction event or the shop reinstalls the app.

Uninstall cleanup keeps a detached record containing the shop domain and installation generation and, when needed, app-owned discount identifiers, campaign or operation identifiers, and the minimum discount input required to verify or disable a remaining resource. If the shop reinstalls first, Givnori clears the previous installation's business records and keeps only unresolved cleanup evidence until reconciliation.

When Shopify sends the shop/redact (SHOP_REDACT) event, Givnori deletes the shop record and its campaign, version, test-case, published configuration, job, subscription, product-cache, discount-link, and session records, and clears detached resource evidence. Minimal processed webhook receipts and completed redaction tombstones may retain the shop identifier or domain, installation generation, event identifier, topic, payload hash, status, and timestamps for up to 30 days, after which they are deleted. Failed or pending webhook work and unresolved uninstall evidence remain only until processing or reconciliation is complete.

Shopify privacy events and security

Givnori authenticates and processes Shopify customer-data requests, customer-redaction events, shop-redaction events, and app-uninstalled events. Because Givnori does not read or store buyer customer or order data, customer requests and customer redaction do not return or delete buyer records. Logs redact tokens, authorization headers, webhook bodies, and customer content, and database access is scoped to the authenticated shop.

Questions and requests

To ask a privacy question or exercise privacy rights, [email protected]. We may verify the requester's authority before disclosing or deleting merchant data.